You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Envoy验证JWT中的aud、iss及roles声明?

Envoy中JWT角色声明验证方案

问题背景

我有如下JWT声明:

{
  "aud": "123123-1232-123123-2323-123",
  "iss": "https://url",
  "iat": 2112,
  "nbf": 1212,
  "exp": 1212,
  "aio": "ewq32ee23e2e=",
  "azp": "123123-1232-123123-2323-123",
  "azpacr": "1",
  "oid": "123123-1232-123123-2323-123",
  "rh": "1.qqfn4wanflwf3aldAAA.",
  "roles": [
    "default"
  ],
  "sub": "123123-1232-123123-2323-123"
}

需要完成三项验证:

  • 受众(aud)
  • 签发者(iss)
  • 确保JWT中存在roles声明,且其数组值包含“default”

已实现前两项的Envoy配置:

http_filters:
  - name: envoy.filters.http.jwt_authn
    typed_config: 
      "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication
      providers:
        "auth-iam":
          issuer: https://url
          forward: true,
          audiences:
          - 123123-1232-123123-2323-123  # [audience]
          remote_jwks:
            http_uri:
              uri: https://url/keys
              cluster: auth-iam
              timeout: 5s
            cache_duration:
              seconds: 900                        
      rules:  
        - match:
            prefix: /actuator/health
        - match:
            prefix: /
          requires:
            provider_name: auth-iam

解决方案:添加角色声明验证

要完成第三项验证,只需在现有JWT认证配置的providers.auth-iam节点下添加claim_to_validate规则,指定对roles数组的包含性检查。

修改后的完整配置:

http_filters:
  - name: envoy.filters.http.jwt_authn
    typed_config: 
      "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication
      providers:
        "auth-iam":
          issuer: https://url
          forward: true,
          audiences:
          - 123123-1232-123123-2323-123  # [audience]
          remote_jwks:
            http_uri:
              uri: https://url/keys
              cluster: auth-iam
              timeout: 5s
            cache_duration:
              seconds: 900
          # 新增角色声明验证规则
          claim_to_validate:
            - claim: "roles"
              list_match:
                contains:
                  string_match:
                    exact: "default"
      rules:  
        - match:
            prefix: /actuator/health
        - match:
            prefix: /
          requires:
            provider_name: auth-iam

关键说明

  • claim_to_validate用于定义JWT声明的自定义验证规则
  • 针对数组类型的roles声明,使用list_match.contains检查是否存在指定字符串"default"
  • 若roles声明不存在,或数组中不包含"default",Envoy会自动拒绝请求,返回401或403状态码

内容的提问来源于stack exchange,提问作者Rahul verma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 17:31:57