Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-22991

[fiware-stackoverflow] Implementing Fine-Grained Access Control with AuthZForce for FIWARE Services

    Details

      Description

      Created question in FIWARE Q/A platform on 30-07-2024 at 13:07
      Please, ANSWER this question AT https://stackoverflow.com/questions/78811548/implementing-fine-grained-access-control-with-authzforce-for-fiware-services

      Question:
      Implementing Fine-Grained Access Control with AuthZForce for FIWARE Services

      Description:
      I'm working on securing a FIWARE system (Orion, Quantum Leap) using Keyrock, Wilma, and AuthZForce. My goal is to implement fine-grained access control based on FIWARE services.
      Each entity in our system belongs to a service, identified by the Fiware-Service header. I want to restrict access to these services based on user roles:
      *User1: Can only access *fiwareservice1
      *User2: Can access *fiwareservice2 and fiwareservice3
      *User3: Can access all *services

      I'm struggling to create appropriate XACML policies in AuthZForce to enforce these rules. Has anyone successfully implemented a similar setup?
      I'm open to suggestions if this approach is not ideal or if there are alternative methods for managing service-based access control in FIWARE.

        Activity

        Hide
        newbacklogmanager Backlog Manager added a comment -

        2025-02-04 17:52|CREATED monitor | # answers= 1, accepted answer= False

        Show
        newbacklogmanager Backlog Manager added a comment - 2025-02-04 17:52|CREATED monitor | # answers= 1, accepted answer= False
        Hide
        newbacklogmanager Backlog Manager added a comment -

        2025-02-05 01:00|UPDATED status: transition Answer| # answers= 1, accepted answer= False

        Show
        newbacklogmanager Backlog Manager added a comment - 2025-02-05 01:00|UPDATED status: transition Answer| # answers= 1, accepted answer= False

          People

          • Assignee:
            Unassigned
            Reporter:
            newbacklogmanager Backlog Manager
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated: