mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-08-22 07:32:30 +02:00
1.7 KiB
1.7 KiB
Multi-User: Overview
New or changed functionality
The feature adds several related but distinct capabilities to Krill:
-
Pluggable authentication:
- Changes the interface with Lagosta
- Three "plugins" so far:
- Admin API Token
- Config File Users
- OpenID Connect (powered by openidconnect-rs), including:
- A mock OpenID Connect server for testing
- JMESPath based claim selection (powered by jmespatch)
- Custom JMESPath regular expression functions
-
Authorization, including:
- Identity
- Permissions
- Roles
- Policy (powered on Oso)
-
Stateless login sessions via support for rich bearer tokens, including:
- Caching
- (De)Serialization
- (En/De)cryption (powered by rust-openssl)
-
Password hashing support in
krillc -
Propagation of the current identity all the way down to the event history
It also required changes in Lagosta to:
- Support the modified interface with Krill
- Display user attributes (e.g. ID, role, etc)
- Check for and handle errors in many more situations
- Actively logout with Krill, don't just forget the token
Impacted source components
The feature only lightly touches the core RPKI related code in Krill in order to propagate the current actor details. The main source code components impacted by this feature are:
src/daemon/auth/src/daemon/http/src/daemon/config.rssrc/daemon/krillserver.rssrc/daemon/scheduler.rssrc/lagosta/src/test-resources/ui/src/tests/multi_user_*.rssrc/tests/ui/