Skip to content

[improve][broker] Support OpenID multi-role authorization and improve proxy authentication defaults - #26549

Merged
merlimat merged 5 commits into
apache:masterfrom
lhotari:lh-improve-openid-proxy-auth
Sep 11, 2026
Merged

merlimat merged 5 commits into
apache:masterfrom
lhotari:lh-improve-openid-proxy-auth

Conversation

@lhotari

@lhotari lhotari commented Sep 11, 2026 •

Copy link
Copy Markdown
Member

Motivation

Enable MultiRolesTokenAuthorizationProvider to work with AuthenticationProviderOpenID by reusing the configured authentication providers to validate tokens and extract role claims. This lets multi-role authorization use the same token handling and OpenID configuration as authentication.

Align proxy and broker defaults so that forwarding client credentials and authenticating the original client are enabled together, reducing the configuration needed for token authentication through a proxy and helping avoid misconfiguration.

Modifications

  • Add a shared token-role interface implemented by the Token and OpenID authentication providers, including support for configurations that use both providers. Multi-role authorization reuses their initialized instances, token parsers, and caches.
  • Add an AuthorizationProvider.InitialContext record containing ServiceConfiguration, PulsarResources, and AuthenticationService. Deprecate the previous initializer while preserving compatibility for existing authorization providers.
  • Allow multi-role authorization with any authentication provider implementing TokenAuthenticationProvider, with clear initialization errors when the shared token provider does not implement it.
  • Default forwardAuthorizationCredentials and authenticateOriginalAuthData to true in Java configuration, shipped configuration files, and deployment templates.
  • Document the explicit authenticateOriginalAuthData=false setting for TLS client-certificate and SASL authentication through a proxy and update the corresponding test fixtures.

Verifying this change

  • Add coverage for OpenID multi-role authorization, Token/OpenID provider combinations, role-claim formats, asynchronous role extraction, shared-provider lifecycle, and initializer compatibility.

  • Extend proxy JWT tests to cover the default subject claim, a custom role claim, and multi-role authorization, verifying client topic permissions with the default proxy/broker configuration.

  • Run scoped broker-common, OpenID, broker, proxy, and websocket tests with retries disabled, plus ./gradlew quickCheck.

  • Make sure that the change passes the CI checks.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API — add the authorization initialization context and token-role interface; retain the deprecated initializer for existing providers.
  • The schema
  • The default values of configurations — enable forwarding client credentials and authenticating the original client.
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics — token validation during authorization uses the shared authentication provider's existing metrics.
  • Anything that affects deployment — multi-role authorization requires a token provider implementing TokenAuthenticationProvider; TLS client-certificate and SASL proxy deployments need the explicit setting described above.

… proxy authentication defaults

Assisted-by: Codex
@lhotari lhotari added this to the 5.0.0-M2 milestone Sep 11, 2026
@merlimat
merlimat merged commit 891cf2e into apache:master Sep 11, 2026
43 checks passed
lhotari added a commit that referenced this pull request Sep 12, 2026
… proxy authentication defaults (#26549)

(cherry picked from commit 891cf2e)
lhotari added a commit that referenced this pull request Sep 12, 2026
… proxy authentication defaults (#26549)

(cherry picked from commit 891cf2e)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants