如何使用Envoy验证JWT中的aud、iss及roles声明?
Envoy中JWT角色声明验证方案
问题背景
我有如下JWT声明:
{ "aud": "123123-1232-123123-2323-123", "iss": "https://url", "iat": 2112, "nbf": 1212, "exp": 1212, "aio": "ewq32ee23e2e=", "azp": "123123-1232-123123-2323-123", "azpacr": "1", "oid": "123123-1232-123123-2323-123", "rh": "1.qqfn4wanflwf3aldAAA.", "roles": [ "default" ], "sub": "123123-1232-123123-2323-123" }
需要完成三项验证:
- 受众(aud)
- 签发者(iss)
- 确保JWT中存在
roles声明,且其数组值包含“default”
已实现前两项的Envoy配置:
http_filters: - name: envoy.filters.http.jwt_authn typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication providers: "auth-iam": issuer: https://url forward: true, audiences: - 123123-1232-123123-2323-123 # [audience] remote_jwks: http_uri: uri: https://url/keys cluster: auth-iam timeout: 5s cache_duration: seconds: 900 rules: - match: prefix: /actuator/health - match: prefix: / requires: provider_name: auth-iam
解决方案:添加角色声明验证
要完成第三项验证,只需在现有JWT认证配置的providers.auth-iam节点下添加claim_to_validate规则,指定对roles数组的包含性检查。
修改后的完整配置:
http_filters: - name: envoy.filters.http.jwt_authn typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication providers: "auth-iam": issuer: https://url forward: true, audiences: - 123123-1232-123123-2323-123 # [audience] remote_jwks: http_uri: uri: https://url/keys cluster: auth-iam timeout: 5s cache_duration: seconds: 900 # 新增角色声明验证规则 claim_to_validate: - claim: "roles" list_match: contains: string_match: exact: "default" rules: - match: prefix: /actuator/health - match: prefix: / requires: provider_name: auth-iam
关键说明
claim_to_validate用于定义JWT声明的自定义验证规则- 针对数组类型的
roles声明,使用list_match.contains检查是否存在指定字符串"default" - 若
roles声明不存在,或数组中不包含"default",Envoy会自动拒绝请求,返回401或403状态码
内容的提问来源于stack exchange,提问作者Rahul verma
相关产品推荐
相关产品推荐

