Allow a user to access an API with roles, no more possible in wso2 7.1?

Viewed 81

In WSO2 Enterprise Integrator 6.6.0 we could manage lists of roles by users, and with the following custom module we could allow a user to access an API if he had the right role.

https://github.com/SavithriNandadasa/wso2-esb-RoleBasedAuthorizationHandler

<handlers>
    <handler class="org.wso2.api.authorization.RoleBasedAuthorizationHandler">
        <property name="roles" value="Role/Test"/>
        </handler>
</handlers>

In WSO2 Enterprise Integrator 7.1 the role management seems to have disappeared. You can add roles manually to the database. But the custom module does not work anymore because the required library would not be part of EI.7 anymore. ( WSO2 EI 7 - RoleBasedAuthorizationHandler java class )

Does anyone have a solution to allow only certain users to access an API?

2 Answers

Some of the MI components get changed relative to the previous EI versions. For example, Multi-tenancy gets removed, DB-based registry changed to file-based registry, org.wso2.carbon.user.api renamed to org.wso2.micro.integrator.security.user.api , org.wso2.carbon.user.core renamed to org.wso2.micro.integrator.security.user.core. Therefore this sample is no longer valid and it should be modify to comply with MI components.

I implemented a new authorization handler for MI. You can find it here. If you find any bugs please report them back to the Github project.

Once you add the Jar you can engage the Handler as shown below.

<handlers>
    <handler class="com.ycr.auth.handlers.AuthorizationHandler">
      <property name="roles" value="admin,test" />
      <property name="authorize" value="true" />
    </handler>
</handlers>
Related