Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-20004

FIWARE.Question.Tech.Fiware context broker access control rules by entity type.

    Details

      Description

      Created question in FIWARE Q/A platform on 29-08-2022 at 22:08
      Please, ANSWER this question AT https://stackoverflow.com/questions/73535332/fiware-context-broker-access-control-rules-by-entity-type

      Question:
      Fiware context broker access control rules by entity type

      Description:
      Is it possible to configure access-control rules for Orion-LD/the FIWARE context broker based on the entity type? Or, alternatively, on the presence of some attributes in the entities?
      A similar question was asked here:
      Get a list of all resources accessible to users in FIWARE. The answer seems to imply that in the so-called Advanced Authorization scenario it is possible to achieve something like this by means of XACML filters for broker endpoints, allowing for instance GET access to the endpoint /entities?type=SomeEntityType for certain users. However, this appears like a very brittle solution, since the type query parameter may be preceded by other params in a real-world request. Furthermore, there are other ways to filter resources returned by the /entities endpoint, e.g. by means of parameters q or attrs (according to the NGSI-LD spec, https://www.etsi.org/deliver/etsi_gs/CIM/001_099/009/01.06.01_60/gs_CIM009v010601p.pdf, see 6.4.3.2), hence separate rules would be needed for all of these and it seems impossible to keep them consistent. Ideally, I would also like GET requests to /entites/

      {entityId}

      to be evaluated against the type of the entity, without configuring this individually for every entity.
      Am I missing a simple solution to this problem?

        Activity

        backlogmanager Backlog Manager created issue -
        Hide
        backlogmanager Backlog Manager added a comment -

        2022-08-30 05:31|CREATED monitor | # answers= 0, accepted answer= False

        Show
        backlogmanager Backlog Manager added a comment - 2022-08-30 05:31|CREATED monitor | # answers= 0, accepted answer= False
        backlogmanager Backlog Manager made changes -
        Field Original Value New Value
        Component/s FIWARE-TECH-HELP [ 10278 ]
        backlogmanager Backlog Manager made changes -
        HD-Enabler Unknown [ 10910 ]
        HD-Chapter Unknown [ 10845 ]
        HD-Node Unknown [ 10852 ]
        fla Fernando Lopez made changes -
        Assignee Jason Fox [ jason.fox ]
        fla Fernando Lopez made changes -
        Status Open [ 1 ] In Progress [ 3 ]
        fla Fernando Lopez made changes -
        Status In Progress [ 3 ] Answered [ 10104 ]
        fla Fernando Lopez made changes -
        Resolution Done [ 10000 ]
        Status Answered [ 10104 ] Closed [ 6 ]
        backlogmanager Backlog Manager made changes -
        Summary [fiware-stackoverflow] Fiware context broker access control rules by entity type FIWARE.Question.Tech.Fiware context broker access control rules by entity type.
        HD-Enabler Unknown [ 10910 ]
        HD-Chapter Unknown [ 10845 ]
        HD-Node Unknown [ 10852 ]
        Transition Time In Source Status Execution Times Last Executer Last Execution Date
        Open Open In Progress In Progress
        3d 1h 4m 1 Fernando Lopez 02/Sep/22 8:36 AM
        In Progress In Progress Answered Answered
        2s 1 Fernando Lopez 02/Sep/22 8:36 AM
        Answered Answered Closed Closed
        1s 1 Fernando Lopez 02/Sep/22 8:36 AM

          People

          • Assignee:
            jason.fox Jason Fox
            Reporter:
            backlogmanager Backlog Manager
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: