

我在KONG上阅读了本教程 https://getkong.org/plugins/jwt/

I went through this tutorial on KONGhttps://getkong.org/plugins/jwt/

我对JWT和授权概念有所了解.我已经用Spring Boot原型化了JWT,可以在其中放置自己的键值,例如{{authorizations:"role_admin,role_user"}.

I have an understanding of JWT and authorization concepts. I have prototyped JWT with Spring Boot where I could put my own key value like this {"authorizations":"role_admin, role_user"}.

在Spring Boot中很容易做到这一点,但是我找不到有关如何使用KONG进行此操作的信息.有人有任何信息吗?

It is easy to do that in Spring Boot but I am not able to find information on how to do this with KONG. Anyone has any info about it?



Kong community edition can handle only the authentication process, (give or deny access to a customer).

授权过程(给定客户可以在您的应用程序中执行的操作)由您的应用程序或 https://getkong.org/plugins/ee-oauth2-introspection/仅限企业版的oauth2自省插件

Authorization process (what a given customer can do in your application) is handled by your application or by https://getkong.org/plugins/ee-oauth2-introspection/ oauth2 introspection plugin which is enterprise edition only


you can write your own authorization server based on X-Consumer-Username request header if user passed authentication or original token header proxied by kong



07-15 09:57