NIFI-8363 Added Single User Login Identity Provider and Authorizer#4968
Merged
bbende merged 3 commits intoapache:mainfrom Apr 12, 2021
Merged
NIFI-8363 Added Single User Login Identity Provider and Authorizer#4968bbende merged 3 commits intoapache:mainfrom
bbende merged 3 commits intoapache:mainfrom
Conversation
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of PR
NIFI-8363 Implements a Single User
LoginIdentityProviderandAuthorizeras an incremental step toward a default secure standalone installation of NiFi. TheLoginIdentityProviderclass includes the following features:login-identity-providers.xmljava.util.UUID.randomUUID()java.security.SecureRandomwith Base64 encodingThe implementation is not intended for production use, but provides a basic level of security for standalone installations. Future changes will incorporate updates to default configuration files so that this implementation can be reviewed independently. Verifying runtime behavior requires the following steps:
login-identity-providers.xmlfrom the test resources directory to the NiFiconfdirectoryauthorizerdefinition inconf/authorizers.xmlwith the following elements:nifi.security.user.login.identity.provider=single-user-providerinnifi.propertiesnifi.security.user.authorizer=single-user-authorizerinnifi.propertiesnifi.web.https.portandnifi.securitykeystore and truststore properties to enable HTTPSnifi-app.logforGenerated UsernameandGenerated PasswordIn order to streamline the review of the contribution we ask you
to ensure the following steps have been taken:
For all changes:
Is there a JIRA ticket associated with this PR? Is it referenced
in the commit message?
Does your PR title start with NIFI-XXXX where XXXX is the JIRA number you are trying to resolve? Pay particular attention to the hyphen "-" character.
Has your PR been rebased against the latest commit within the target branch (typically
main)?Is your initial contribution a single, squashed commit? Additional commits in response to PR reviewer feedback should be made on this branch and pushed to allow change tracking. Do not
squashor use--forcewhen pushing to allow for clean monitoring of changes.For code changes:
mvn -Pcontrib-check clean installat the rootnififolder?LICENSEfile, including the mainLICENSEfile undernifi-assembly?NOTICEfile, including the mainNOTICEfile found undernifi-assembly?.displayNamein addition to .name (programmatic access) for each of the new properties?For documentation related changes:
Note:
Please ensure that once the PR is submitted, you check GitHub Actions CI for build issues and submit an update to your PR as soon as possible.