kafbat/kafka-ui

BE: AUth: Implement JWT auth w/ JWKS

开放

#206 创建于 2024年3月13日

 (2 条评论) (0 个反应) (0 位负责人)TypeScript (363 个派生)auto 404
area/authgood first issuehacktoberfestscope/backendstatus/triage/completedtype/feature

仓库指标

星标
 (2,554 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

https://docs.spring.io/spring-security/reference/servlet/oauth2/resource-server/jwt.html


via: https://github.com/provectus/kafka-ui/issues/4145

In our case we have a central place where authentication already happens using Azure AD as IDP, and we would like to just forward the JWT resultant from the oauth provider authentication to kafka-ui, and then kafka-ui could just validate the jwt using JWKS (https://auth0.com/docs/secure/tokens/json-web-tokens/json-web-key-sets).

A similar feature is present in Grafana (https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/jwt/#verify-token-using-a-json-web-key-set-loaded-from-https-endpoint), which we are using fine.

As it is now, our only solution is to authenticate using Azure AD in our central place to get access to the internal network to reach kafka-ui, and then authenticate again into kafka-ui using the same method.

贡献者指南