Details

    • Type: extRequest
    • Status: Closed
    • Priority: Major
    • Resolution: Done
    • Fix Version/s: 2021
    • Component/s: FIWARE-TECH-HELP
    • Labels:
      None

      Description

      Hi.

      I can access the entity named 'TestRoom' in Orion using request like 'http://localhost:1026/v2/entities/TestRoom' without any access restrictions.
      So, I just want to make constraint to access Test_Room using OAuth2.0 token.

      But now I don't know how to make access token scope to entity in Orion.
      For example, I want to make the user or the app that has access token(scope:read temperature from TestRoom) can read temperature information from TestRoom.

      If I know above thing, I will make the request access token(scope:read info. from Test_Room) and use that token with X-Auth-Token header.

      So Could you get me any information, URL, document or instruction?
      I already read RFC 6749 and some documents of FIWARE Security GE, and installed orion, keyrock and authzforce.
      And I was not install the Willma(PEP) because Tour-Guide App provided FIWARE doesn't use this GE. (I don't know why, as you know, PEP is entry point of all FIWARE security right?)

      __________________________________________________________________________________________

      You can get more information about our cookies and privacy policies on the following links:

      Fiware-tech-help mailing list
      Fiware-tech-help@lists.fiware.org
      https://lists.fiware.org/listinfo/fiware-tech-help

      [Created via e-mail received from: =?ks_c_5601-1987?B?v8C8vLbz?= <terious551@sju.ac.kr>]

        Activity

        Hide
        fermin Fermín Galán added a comment -

        Assigning back to backlog manager in order to avoid reminder emails. Once the system gets adapted to avoid them (see https://github.com/flopezag/fiware-management-scripts/pull/17) you can assign me it back if you want

        Show
        fermin Fermín Galán added a comment - Assigning back to backlog manager in order to avoid reminder emails. Once the system gets adapted to avoid them (see https://github.com/flopezag/fiware-management-scripts/pull/17 ) you can assign me it back if you want
        Hide
        aalonsog Alvaro Alonso added a comment -

        You have to create an assign roles in Keyrock. Then Wilma PEP Proxy will check the roles before redirecting the request to the CB. I recommend you to see Wilma tutorials and documentation

        Show
        aalonsog Alvaro Alonso added a comment - You have to create an assign roles in Keyrock. Then Wilma PEP Proxy will check the roles before redirecting the request to the CB. I recommend you to see Wilma tutorials and documentation

          People

          • Assignee:
            aalonsog Alvaro Alonso
            Reporter:
            fw.ext.user FW External User
          • Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: