You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mule自定义策略修改:仅允许指定Client ID访问限定API端点

Mule自定义策略逻辑反转修改方案

当前你的策略作用是限制指定Client ID访问特定端点,要改为仅允许该Client ID访问目标端点(其他Client ID访问时返回403),需要对template.xml和YAML配置文件做以下修改:

一、修改template.xml的逻辑判断

原策略的逻辑是:当请求的Client ID不等于配置列表中的任意值时放行,否则拒绝。现在需要完全反转这个逻辑——仅当请求的Client ID匹配配置列表中的值时放行,其余情况直接拒绝。

修改后的template.xml核心部分:

<?xml version="1.0" encoding="UTF-8"?>
<mule
    xmlns="http://www.mulesoft.org/schema/mule/core"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:http-policy="http://www.mulesoft.org/schema/mule/http-policy"
    xmlns:http-transform="http://www.mulesoft.org/schema/mule/http-policy-transform"
    xsi:schemaLocation="http://www.mulesoft.org/schema/mule/core http://www.mulesoft.org/schema/mule/core/current/mule.xsd
    http://www.mulesoft.org/schema/mule/http-policy http://www.mulesoft.org/schema/mule/http-policy/current/mule-http-policy.xsd
    http://www.mulesoft.org/schema/mule/http-policy-transform http://www.mulesoft.org/schema/mule/http-policy-transform/current/mule-http-policy-transform.xsd">
    <http-policy:proxy name="{{{policyId}}}-custom-policy">
        <http-policy:source>
            <try>
                <choice>
                    <!-- 检查请求的Client ID是否在允许的列表中 -->
                    <when expression="#[{{{clientIdExpression}}} not in [{{#clientID}}'{{{.}}}'{{^last}},{{/last}}{{/clientID}}]]">
                        <raise-error type="CUSTOM:NOT_ALLOWED" 
                            description="#['Access Denied for this API resource']"/>
                    </when>
                    <otherwise>
                        <logger level="INFO" message="Allowed client access: #[{{{clientIdExpression}}}]"/>
                    </otherwise>
                </choice>
                <error-handler>
                    <on-error-propagate type="CUSTOM:NOT_ALLOWED">
                        <http-transform:set-response statusCode="403">
                            <http-transform:body>#[
                                output application/json
                                ---
                                {"error": "Access Forbidden", "message": "Only allowed clients can access this resource"}]
                            </http-transform:body>
                        </http-transform:set-response>
                    </on-error-propagate>
                </error-handler>
            </try>
            <http-policy:execute-next/>
        </http-policy:source>
    </http-policy:proxy>
</mule>

关键修改点:

  • 把原有的循环判断单个Client ID不等于的逻辑,改成一次性判断请求的Client ID是否不在允许的列表中(使用Mule的not in表达式),逻辑更简洁高效
  • 当Client ID不在列表时直接抛出拒绝错误;匹配时记录日志并放行
  • 优化403响应的错误信息,明确说明拒绝原因

二、修改YAML配置文件的描述与字段说明

YAML主要更新描述文字,让策略用途更准确,避免配置混淆:

修改后的YAML文件:

#YAML File
id: Test
name: Test
description: Custom Policy used to allow ONLY specified client access at API EndPoint level. This is designed to use with OpenId Connect access token enforcement policy.
category: Custom
type: custom
violationCategory: authentication
resourceLevelSupported: true
encryptionSupported: false
standalone: true
requiredCharacteristics: []
providedCharacteristics: []
configuration:  
  - propertyName: clientIdExpression
    name: Client ID Expression
    description: Mule Expression to be used to extract the Client ID from API requests
    type: string
    defaultValue: "authentication.properties.userProperties.client_id"
    optional: false
    sensitive: false
    allowMultiple: false
  - propertyName: clientName
    name: Client Name
    description: Name of the external client that is allowed to use this policy
    type: string
    defaultValue: []
    optional: false
    sensitive: false
    allowMultiple: false 
  - propertyName: clientID
    name: Allowed Client ID
    description: Client ID(s) that are allowed to access the API resource
    type: string
    optional: false
    sensitive: false
    allowMultiple: true
    defaultValue: []

关键修改点:

  • 更新主description:明确说明是仅允许指定Client ID访问
  • 修改clientName描述:从“使用该策略的外部客户端名称”改为“被允许使用该策略的外部客户端名称”
  • 修改clientID的name和description:从“需要被限制的Client ID”改为“允许访问的Client ID”,避免配置时误解

额外建议

  1. 测试验证:部署修改后的策略后,分别用允许的Client ID和其他Client ID访问目标端点,确认403响应和正常放行的逻辑是否符合预期
  2. 表达式排查:如果Client ID提取异常,可通过logger组件先打印提取到的Client ID,验证表达式是否正确
  3. 资源级配置:因为策略开启了resourceLevelSupported: true,在API Manager中配置策略时,需正确选择要应用的目标端点(/api/endpoint-1和/api/endpoint-2)

内容的提问来源于stack exchange,提问作者Triumph Spitfire

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 16:40:54