基于AuthZForce为FIWARE服务实现细粒度访问控制的问题求助
基于Keyrock/Wilma/AuthZForce实现FIWARE服务级细粒度访问控制
一、AuthZForce XACML策略实现
针对你的场景,可以通过分层策略集+规则组合实现用户角色与Fiware-Service的权限绑定,以下是可直接复用的XACML配置示例:
1. 顶层策略集(PolicySet)
该策略集包含三个子策略,分别对应三个用户的权限规则,采用deny-unless-permit组合算法(仅匹配到允许规则时授权):
<PolicySet xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" PolicySetId="fiware-service-access-policy-set" Version="1.0" PolicyCombiningAlgId="urn:oasis:names:tc:xacml:3.0:policy-combining-algorithm:deny-unless-permit"> <!-- User1 仅允许访问fiwareservice1 --> <Policy PolicyId="user1-fiware-service-policy" Version="1.0" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides"> <Target> <AnyOf> <AllOf> <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">User1</AttributeValue> <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id" DataType="http://www.w3.org/2001/XMLSchema#string" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" MustBePresent="true"/> </Match> </AllOf> </AnyOf> </Target> <Rule RuleId="allow-user1-fiwareservice1" Effect="Permit"> <Condition> <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">fiwareservice1</AttributeValue> <AttributeDesignator AttributeId="fiware-service-header" DataType="http://www.w3.org/2001/XMLSchema#string" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" MustBePresent="true"/> </Apply> </Condition> </Rule> <Rule RuleId="deny-user1-other-services" Effect="Deny"/> </Policy> <!-- User2 允许访问fiwareservice2和fiwareservice3 --> <Policy PolicyId="user2-fiware-service-policy" Version="1.0" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides"> <Target> <AnyOf> <AllOf> <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">User2</AttributeValue> <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id" DataType="http://www.w3.org/2001/XMLSchema#string" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" MustBePresent="true"/> </Match> </AllOf> </AnyOf> </Target> <Rule RuleId="allow-user2-fiwareservice2" Effect="Permit"> <Condition> <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">fiwareservice2</AttributeValue> <AttributeDesignator AttributeId="fiware-service-header" DataType="http://www.w3.org/2001/XMLSchema#string" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" MustBePresent="true"/> </Apply> </Condition> </Rule> <Rule RuleId="allow-user2-fiwareservice3" Effect="Permit"> <Condition> <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">fiwareservice3</AttributeValue> <AttributeDesignator AttributeId="fiware-service-header" DataType="http://www.w3.org/2001/XMLSchema#string" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" MustBePresent="true"/> </Apply> </Condition> </Rule> <Rule RuleId="deny-user2-other-services" Effect="Deny"/> </Policy> <!-- User3 允许访问所有服务 --> <Policy PolicyId="user3-fiware-service-policy" Version="1.0" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:permit-overrides"> <Target> <AnyOf> <AllOf> <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">User3</AttributeValue> <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id" DataType="http://www.w3.org/2001/XMLSchema#string" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" MustBePresent="true"/> </Match> </AllOf> </AnyOf> </Target> <Rule RuleId="allow-user3-all-services" Effect="Permit"/> </Policy> </PolicySet>
2. 关键配置要点
- 属性映射:在AuthZForce的PAP中配置,将请求头
Fiware-Service映射为XACML资源属性fiware-service-header,确保Wilma能将该头信息传递给AuthZForce做决策。 - 策略组合逻辑:单个用户策略采用
deny-overrides,确保未匹配允许规则时默认拒绝;User3的策略用permit-overrides直接授权所有请求。 - RBAC适配:如果需基于角色而非用户ID配置,可将
subject-id替换为角色属性urn:oasis:names:tc:xacml:2.0:subject:role,更符合标准RBAC模式。
二、简化替代方案
若XACML配置复杂度较高,可考虑以下两种轻量方案:
1. Keyrock角色+Wilma直接过滤
在Keyrock中为用户分配关联Fiware-Service的自定义角色(如service1-user、multi-service-user),然后在Wilma的拦截规则中:
- 从JWT令牌解析用户角色
- 直接匹配请求头
Fiware-Service,不符合则返回403状态码
该方案无需AuthZForce,适合规则简单的场景,配置成本更低。
2. OPA(Open Policy Agent)替代AuthZForce
OPA的Rego规则比XACML更简洁易读,示例规则如下:
package fiware.access default allow = false # User1 仅允许fiwareservice1 allow { input.user_id == "User1" input.headers["Fiware-Service"] == "fiwareservice1" } # User2 允许fiwareservice2和fiwareservice3 allow { input.user_id == "User2" input.headers["Fiware-Service"] in ["fiwareservice2", "fiwareservice3"] } # User3 允许所有服务 allow { input.user_id == "User3" }
可通过Wilma将请求转发到OPA做决策,规则修改和调试更高效。
内容的提问来源于stack exchange,提问作者Tony Rosset
相关产品推荐
相关产品推荐

