Securing Solr Admin Dashboard with KeyCloak as IDP

Viewed 78

We're trying to secure the Solr 8.11 Dashboard. KeyCloak serves as an IDP in this case. All Querys (SELECT, UPDATE, etc.) should be accessible without any Login screen.

The Solr Security.xml looks like this:

{
  "authentication":{
    "class": "solr.JWTAuthPlugin",
    "blockUnknown": false,
    "scope": "openid",
    "wellKnownUrl": "http://keycloak.fqdn.com:8080/auth/realms/My-Realm/.well-known/openid-configuration",
    "clientId": "Solr-auth",
    "rolesClaim": "roles"
  },
  "authorization":{
    "class":"solr.ExternalRoleRuleBasedAuthorizationPlugin", 
    "permissions":[{"name":"core-admin-read",
      "role":"profile"}] 
  }
}

This works so far but does not seem quite right. Notice how I had to specify "profile" as a Role. If I put "solr-admin" as a Role I get the following Error Message from Solr when logging in:

The principal JWTPrincipalWithUserRoles{username='******************************', token='*****', claims={exp=1651702368, iat=1651680768, auth_time=1651680768, jti=************************************, iss=http://keycloak.fqdn.com:8080/auth/realms/My-Realm, aud=account, sub=********************************, typ=Bearer, azp=Solr-auth, nonce==************************************,, session_state==************************************,, acr=1, allowed-origins=[http://solr.fqdn.com:9991], realm_access={roles=[MyCustomRole1,MyCustomRole2, MyCustomRole3, solr-admin, MyCustomRole4]}, resource_access={account={roles=[manage-account, manage-account-links, view-profile]}}, scope=openid profile email, email_verified=false, preferred_username=testuser, email=myemail@fqdn.com}, roles=[profile, email]} does not have the right role 

My User (testuser) has been assigned to a few different Roles. (Like MyCustomRole1) I've also created the Role "solr-admin" and assigned my User to this role. But somehow the JWT Token has "roles=[profile, email]" in it. So I have to put profile or email into the Solr security.xml. Every KeyCloak User is a Member of both Roles.

Is there a way so that Solr allows a Login if the Security.xml has solr-admin instead of profile as the Role name?

0 Answers
Related