NATS-How to set the subscribe and publish permission when using request-reply in python?

Viewed 79

I want to set auth permission, but it seems different when using request-reply mode. Here is my setting:

values.yaml

users:
  -user: test
   password: testtest
   permissions:
     subcribe: ["test"]
     pulbish: ["test"]

python code

nc = await nats.connect("nats://test:testtest@jetstream-nats:4222")
js = nc.jetstream()
await js.add_stream(name="test", subjects=["test"]

Error message:

nats.errors.Error: nats: permissions violation for subscription to "_inbox.xxxxxxxxxxxx.*"
nats.errors.Error: nats: permissions violation for publish to "$js.api.stream.create.test"

If I change value.yaml to this, it would not show any error and still can't publish to stream "test".

users:
  -user: test
   password: testtest
   permissions:
     subcribe: ["_INBOX.>"]
     pulbish: ["$JS.API.STREAM.CREATE.>"]

But if I change value.yaml to this, it would occur the same error message

users:
  -user: test
   password: testtest
   permissions:
     subcribe: ["_INBOX.>"]
     pulbish: ["$JS.API.STREAM.CREATE.test.>"]
========================================================================================
nats.errors.Error: nats: permissions violation for subscription to "_inbox.xxxxxxxxxxxx.*"
nats.errors.Error: nats: permissions violation for publish to "$js.api.stream.create.test"

My question is HOW TO set the subscribe and publish permission when using request-reply?

If i want to set user "testuser" only can publish to stream "test" and subscribe "test", how to set my yaml file?

1 Answers

A publish to a stream only requires permission to the actual subject of the message, in this case test. What appears to be happening is that you are also trying to create the stream with that user which requires different permissions (that you added in the second snippet). In both snippets, you have typos in your YAML, pulbish instead of publish and subcribe instead of subscribe.

If you want the same user to be able to create the stream and publish to it, try this:

users:
  - user: test
    password: testtest
    permissions:
      subscribe: ["_INBOX.>"]
      publish: ["$JS.API.STREAM.CREATE.test", "test"]
Related