You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于AuthZForce为FIWARE服务实现细粒度访问控制的问题求助

基于Keyrock/Wilma/AuthZForce实现FIWARE服务级细粒度访问控制

一、AuthZForce XACML策略实现

针对你的场景,可以通过分层策略集+规则组合实现用户角色与Fiware-Service的权限绑定,以下是可直接复用的XACML配置示例:

1. 顶层策略集(PolicySet)

该策略集包含三个子策略,分别对应三个用户的权限规则,采用deny-unless-permit组合算法(仅匹配到允许规则时授权):

<PolicySet xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17"
           PolicySetId="fiware-service-access-policy-set"
           Version="1.0"
           PolicyCombiningAlgId="urn:oasis:names:tc:xacml:3.0:policy-combining-algorithm:deny-unless-permit">
  <!-- User1 仅允许访问fiwareservice1 -->
  <Policy PolicyId="user1-fiware-service-policy" Version="1.0"
          RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides">
    <Target>
      <AnyOf>
        <AllOf>
          <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">User1</AttributeValue>
            <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"
                                 DataType="http://www.w3.org/2001/XMLSchema#string"
                                 Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"
                                 MustBePresent="true"/>
          </Match>
        </AllOf>
      </AnyOf>
    </Target>
    <Rule RuleId="allow-user1-fiwareservice1" Effect="Permit">
      <Condition>
        <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">fiwareservice1</AttributeValue>
          <AttributeDesignator AttributeId="fiware-service-header"
                               DataType="http://www.w3.org/2001/XMLSchema#string"
                               Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource"
                               MustBePresent="true"/>
        </Apply>
      </Condition>
    </Rule>
    <Rule RuleId="deny-user1-other-services" Effect="Deny"/>
  </Policy>

  <!-- User2 允许访问fiwareservice2和fiwareservice3 -->
  <Policy PolicyId="user2-fiware-service-policy" Version="1.0"
          RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides">
    <Target>
      <AnyOf>
        <AllOf>
          <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">User2</AttributeValue>
            <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"
                                 DataType="http://www.w3.org/2001/XMLSchema#string"
                                 Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"
                                 MustBePresent="true"/>
          </Match>
        </AllOf>
      </AnyOf>
    </Target>
    <Rule RuleId="allow-user2-fiwareservice2" Effect="Permit">
      <Condition>
        <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">fiwareservice2</AttributeValue>
          <AttributeDesignator AttributeId="fiware-service-header"
                               DataType="http://www.w3.org/2001/XMLSchema#string"
                               Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource"
                               MustBePresent="true"/>
        </Apply>
      </Condition>
    </Rule>
    <Rule RuleId="allow-user2-fiwareservice3" Effect="Permit">
      <Condition>
        <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">fiwareservice3</AttributeValue>
          <AttributeDesignator AttributeId="fiware-service-header"
                               DataType="http://www.w3.org/2001/XMLSchema#string"
                               Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource"
                               MustBePresent="true"/>
        </Apply>
      </Condition>
    </Rule>
    <Rule RuleId="deny-user2-other-services" Effect="Deny"/>
  </Policy>

  <!-- User3 允许访问所有服务 -->
  <Policy PolicyId="user3-fiware-service-policy" Version="1.0"
          RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:permit-overrides">
    <Target>
      <AnyOf>
        <AllOf>
          <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">User3</AttributeValue>
            <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"
                                 DataType="http://www.w3.org/2001/XMLSchema#string"
                                 Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"
                                 MustBePresent="true"/>
          </Match>
        </AllOf>
      </AnyOf>
    </Target>
    <Rule RuleId="allow-user3-all-services" Effect="Permit"/>
  </Policy>
</PolicySet>

2. 关键配置要点

  • 属性映射:在AuthZForce的PAP中配置,将请求头Fiware-Service映射为XACML资源属性fiware-service-header,确保Wilma能将该头信息传递给AuthZForce做决策。
  • 策略组合逻辑:单个用户策略采用deny-overrides,确保未匹配允许规则时默认拒绝;User3的策略用permit-overrides直接授权所有请求。
  • RBAC适配:如果需基于角色而非用户ID配置,可将subject-id替换为角色属性urn:oasis:names:tc:xacml:2.0:subject:role,更符合标准RBAC模式。

二、简化替代方案

若XACML配置复杂度较高,可考虑以下两种轻量方案:

1. Keyrock角色+Wilma直接过滤

在Keyrock中为用户分配关联Fiware-Service的自定义角色(如service1-user、multi-service-user),然后在Wilma的拦截规则中:

  • 从JWT令牌解析用户角色
  • 直接匹配请求头Fiware-Service,不符合则返回403状态码
    该方案无需AuthZForce,适合规则简单的场景,配置成本更低。

2. OPA(Open Policy Agent)替代AuthZForce

OPA的Rego规则比XACML更简洁易读,示例规则如下:

package fiware.access

default allow = false

# User1 仅允许fiwareservice1
allow {
    input.user_id == "User1"
    input.headers["Fiware-Service"] == "fiwareservice1"
}

# User2 允许fiwareservice2和fiwareservice3
allow {
    input.user_id == "User2"
    input.headers["Fiware-Service"] in ["fiwareservice2", "fiwareservice3"]
}

# User3 允许所有服务
allow {
    input.user_id == "User3"
}

可通过Wilma将请求转发到OPA做决策,规则修改和调试更高效。

内容的提问来源于stack exchange,提问作者Tony Rosset

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 08:04:55