fix(auth): add missing test coverage

This commit is contained in:
Łukasz Mierzwa
2021-10-23 14:38:54 +01:00
committed by Łukasz Mierzwa
parent 9b89b4ee2a
commit 4ccc0a35ab
19 changed files with 299 additions and 30 deletions
+20 -2
View File
@@ -45,6 +45,9 @@ authentication:
header:
name: string
value_re: regex
group_name: string
group_value_re: regex
group_value_separator: string
basicAuth:
users:
- username: string
@@ -66,9 +69,9 @@ authentication:
- `authentication:users:header:group_value_re` - Similar to
`authentication:users:header:value_re`, but for groups instead of usernames.
Must be set when `authentication:users:header:group_name` is set.
- `authentication:users:header:group_value_separator` - If set, this will be
- `authentication:users:header:group_value_separator` - This will be
used to split the group header to multiple group names. The split is done
before evaluating the value regex. Optional.
after evaluating the value regex. Default value is `" "`.
- `authentication:users` - list of users (username & password) allowed to login.
Passwords are stored plain without any encryption.
When set HTTP basic authentication will be used.
@@ -107,6 +110,21 @@ authentication:
value_re: ^(.+)$
```
Example where the `X-Auth-User` and `X-Auth-Groups` headers will be used to
set username and list of groups. This assume that `X-Auth-Groups` value has
`Groups: foo,bar` syntax, where `foo` and `bar` are two groups user belongs to.
```YAML
authentication:
header:
name: X-Auth-User
value_re: ^(.+)$
group_name: X-Auth-Groups
group_value_re: 'Groups: (.+)'
group_value_separator: ','
```
### Authorization
`authorization` section allows to configure authorization groups used in