Hello leaf-team,
When creating a new Service Registry, the leaf documentation says this
// At the beginning of the WebServer setup, add the ServiceRegistryRestResource setup
/*
* ATTENTION: Carefully select the value for this boolean. See ServiceRegistryRestResource JavaDoc for details.
*/
boolean requireUserHeaders = <TRUE_OR_FALSE>;
IRestContextProvider contextProvider = RestContextProvider.newBuilder().build();
ServiceRegistryRestResource registryResource = new ServiceRegistryRestResource(registry, contextProvider,
requireUserHeaders);
And the documentation for the ServiceRegistryRestResource says
/**
* When set to true, requests will be expected to provide a {@link User}. When set to false, requests without a
* User will be promoted to use {@link User#SYSTEM}.
*/
private final boolean requireUserHeaders;
We are extending the metadata for services to include a classification field, to prevent users from seeing a service that they do not have high enough clearance for.
So with that, I would think we want this boolean as true, so any calls to the service registry from the front end to load in services will be authenticated, that way a user with classification: 1 cant see a class 4 service.
The part I’m confused on, is that the websocket and dashboard service are showing as unauthorized in the logs of the service registry
19:05:15.920 [qtp2066950947-49] [1;31mERROR[m c.l.l.p.s.ServiceRegistry - message: Registration failed, serviceId: WebsocketService
com.leidos.leaf.beans.exception.authorization.UnauthorizedException: No User was provided, and is therefore unauthorized.
at com.leidos.leaf.internal.dataobject.service.authorization.policy.DataObjectAuthorizationHelper.lambda$evaluateAuthorization$13(DataObjectAuthorizationHelper.java:225) ~[framework-services-core-3.6.1.jar:?]
at java.util.Optional.ifPresentOrElse(Optional.java:203) ~[?:?]
at com.leidos.leaf.internal.dataobject.service.authorization.policy.DataObjectAuthorizationHelper.evaluateAuthorization(DataObjectAuthorizationHelper.java:223) ~[framework-services-core-3.6.1.jar:?]
But, other services are registering with the system user, and that boolean is set to true. This property is attached to all the service data objects in mongodb
createdByUsername: "AnonymousSystemUser"
So then, if I set that boolean to false, the websocket and dashboard service can register, but also using
createdByUsername: "AnonymousSystemUser"
So any ideas why some services can register with the system user but these two cant?