Mule自定义策略修改:仅允许指定Client ID访问限定API端点
Mule自定义策略逻辑反转修改方案
当前你的策略作用是限制指定Client ID访问特定端点,要改为仅允许该Client ID访问目标端点(其他Client ID访问时返回403),需要对template.xml和YAML配置文件做以下修改:
一、修改template.xml的逻辑判断
原策略的逻辑是:当请求的Client ID不等于配置列表中的任意值时放行,否则拒绝。现在需要完全反转这个逻辑——仅当请求的Client ID匹配配置列表中的值时放行,其余情况直接拒绝。
修改后的template.xml核心部分:
<?xml version="1.0" encoding="UTF-8"?> <mule xmlns="http://www.mulesoft.org/schema/mule/core" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:http-policy="http://www.mulesoft.org/schema/mule/http-policy" xmlns:http-transform="http://www.mulesoft.org/schema/mule/http-policy-transform" xsi:schemaLocation="http://www.mulesoft.org/schema/mule/core http://www.mulesoft.org/schema/mule/core/current/mule.xsd http://www.mulesoft.org/schema/mule/http-policy http://www.mulesoft.org/schema/mule/http-policy/current/mule-http-policy.xsd http://www.mulesoft.org/schema/mule/http-policy-transform http://www.mulesoft.org/schema/mule/http-policy-transform/current/mule-http-policy-transform.xsd"> <http-policy:proxy name="{{{policyId}}}-custom-policy"> <http-policy:source> <try> <choice> <!-- 检查请求的Client ID是否在允许的列表中 --> <when expression="#[{{{clientIdExpression}}} not in [{{#clientID}}'{{{.}}}'{{^last}},{{/last}}{{/clientID}}]]"> <raise-error type="CUSTOM:NOT_ALLOWED" description="#['Access Denied for this API resource']"/> </when> <otherwise> <logger level="INFO" message="Allowed client access: #[{{{clientIdExpression}}}]"/> </otherwise> </choice> <error-handler> <on-error-propagate type="CUSTOM:NOT_ALLOWED"> <http-transform:set-response statusCode="403"> <http-transform:body>#[ output application/json --- {"error": "Access Forbidden", "message": "Only allowed clients can access this resource"}] </http-transform:body> </http-transform:set-response> </on-error-propagate> </error-handler> </try> <http-policy:execute-next/> </http-policy:source> </http-policy:proxy> </mule>
关键修改点:
- 把原有的循环判断单个Client ID不等于的逻辑,改成一次性判断请求的Client ID是否不在允许的列表中(使用Mule的
not in表达式),逻辑更简洁高效 - 当Client ID不在列表时直接抛出拒绝错误;匹配时记录日志并放行
- 优化403响应的错误信息,明确说明拒绝原因
二、修改YAML配置文件的描述与字段说明
YAML主要更新描述文字,让策略用途更准确,避免配置混淆:
修改后的YAML文件:
#YAML File id: Test name: Test description: Custom Policy used to allow ONLY specified client access at API EndPoint level. This is designed to use with OpenId Connect access token enforcement policy. category: Custom type: custom violationCategory: authentication resourceLevelSupported: true encryptionSupported: false standalone: true requiredCharacteristics: [] providedCharacteristics: [] configuration: - propertyName: clientIdExpression name: Client ID Expression description: Mule Expression to be used to extract the Client ID from API requests type: string defaultValue: "authentication.properties.userProperties.client_id" optional: false sensitive: false allowMultiple: false - propertyName: clientName name: Client Name description: Name of the external client that is allowed to use this policy type: string defaultValue: [] optional: false sensitive: false allowMultiple: false - propertyName: clientID name: Allowed Client ID description: Client ID(s) that are allowed to access the API resource type: string optional: false sensitive: false allowMultiple: true defaultValue: []
关键修改点:
- 更新主
description:明确说明是仅允许指定Client ID访问 - 修改
clientName描述:从“使用该策略的外部客户端名称”改为“被允许使用该策略的外部客户端名称” - 修改
clientID的name和description:从“需要被限制的Client ID”改为“允许访问的Client ID”,避免配置时误解
额外建议
- 测试验证:部署修改后的策略后,分别用允许的Client ID和其他Client ID访问目标端点,确认403响应和正常放行的逻辑是否符合预期
- 表达式排查:如果Client ID提取异常,可通过
logger组件先打印提取到的Client ID,验证表达式是否正确 - 资源级配置:因为策略开启了
resourceLevelSupported: true,在API Manager中配置策略时,需正确选择要应用的目标端点(/api/endpoint-1和/api/endpoint-2)
内容的提问来源于stack exchange,提问作者Triumph Spitfire
相关产品推荐
相关产品推荐

