Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 17 additions & 2 deletions obp-api/src/main/resources/props/sample.props.template
Original file line number Diff line number Diff line change
Expand Up @@ -257,6 +257,21 @@ write_connector_metrics=false
## Enable writing connector traces (full outbound/inbound message payloads per call) to RDBMS table `connector_trace`. Verbose — keep off in prod unless debugging.
write_connector_trace=false

## Client addresses behind a proxy. By default OBP-API takes the client address from the TCP peer,
## which behind a reverse proxy, load balancer or server-side application is the proxy's address: every
## per-IP limit, IP penalty and the busiest-callers view would then see one address. When a proxy sits
## in front, let it set a header with the client's address (it MUST overwrite any value the client sent,
## e.g. NGINX `proxy_set_header X-Real-IP $remote_addr;`) and trust that header here.
## X-Forwarded-For is also accepted (its leftmost address is used) when the proxy sanitises the chain.
## trust.proxy.peers limits whose header is believed: the addresses or CIDR ranges of the proxies (and
## of server-side applications that pass on their users' addresses). A header from any other peer is
## ignored. Unset, the header is believed from anyone, so a caller that reaches OBP-API directly can
## name any address it likes. Deployment Checks (GET /obp/v7.0.0/management/system/diagnostics/deployment,
## or Observe > Deployment Checks in API Manager) shows whether these are right for the traffic seen.
# trust.proxy.enabled=false
# trust.proxy.header=X-Real-IP
# trust.proxy.peers=10.0.0.0/8, 2001:db8::/32

## Telemetry: aggregated numbers about this instance (request rates and durations per endpoint,
## Connector calls, caches, the database pool, memory, garbage collection, threads) for Prometheus.
## Not API Metrics: see docs/telemetry_conventions.md. Telemetry is always recorded; these props
Expand Down Expand Up @@ -879,7 +894,7 @@ super_admin_user_ids=USER_ID1,USER_ID2,

##################################################################################
# List of Users that should automatically have roles needed to call endpoints used by OBP-OIDC or OBP Keycloak Provider.
# The following users will automatically have: CanGetAnyUser, CanVerifyUserCredentials, CanVerifyOidcClient, CanGetOidcClient
# The following users will automatically have: CanGetAnyUser, CanVerifyUserCredentials, CanVerifyOidcClient, CanGetOidcClient, CanGetConsumers, CanCreateConsumer
# oidc_operator_user_ids=USER_ID1,USER_ID2,
####################################################################################

Expand Down Expand Up @@ -1965,7 +1980,7 @@ regulated_entities = []

# Bootstrap OIDC Operator User
# Given the following credentials, OBP will create a user if they do not already exist.
# This user will be granted: CanGetAnyUser, CanVerifyUserCredentials, CanVerifyOidcClient, CanGetOidcClient, CanGetConsumers
# This user will be granted: CanGetAnyUser, CanVerifyUserCredentials, CanVerifyOidcClient, CanGetOidcClient, CanGetConsumers, CanCreateConsumer
# If you want to use this feature, please set up all three values properly at the same time.
# oidc_operator_username=...
# oidc_operator_initial_password=...
Expand Down
8 changes: 6 additions & 2 deletions obp-api/src/main/scala/bootstrap/liftweb/Boot.scala
Original file line number Diff line number Diff line change
Expand Up @@ -865,7 +865,7 @@ class Boot extends MdcLoggable {
/**
* Bootstrap OIDC Operator User
* Given the following credentials, OBP will create a user *if it does not exist already*.
* This user will be granted: CanGetAnyUser, CanVerifyUserCredentials, CanVerifyOidcClient, CanGetOidcClient, CanGetConsumers
* This user will be granted: CanGetAnyUser, CanVerifyUserCredentials, CanVerifyOidcClient, CanGetOidcClient, CanGetConsumers, CanCreateConsumer
*/
private def createBootstrapOidcOperatorUser() = {

Expand Down Expand Up @@ -905,7 +905,8 @@ class Boot extends MdcLoggable {
CanVerifyUserCredentials,
CanVerifyOidcClient,
CanGetOidcClient,
CanGetConsumers
CanGetConsumers,
CanCreateConsumer
)

userBox match {
Expand Down Expand Up @@ -1133,10 +1134,13 @@ object ToSchemify extends MdcLoggable {
CounterpartyAttributeMapper,
BankAccountBalance,
Group,
code.group.GroupMembership,
Organisation,
RoutingScheme,
BankSupportedRoutingScheme,
code.glossaryitem.DynamicGlossaryItem,
code.platformapp.PlatformApp,
code.platformapp.PlatformAppRequiredScope,
PayeeLookup,
UtilityPaymentCallback,
BulkPayment,
Expand Down
2 changes: 1 addition & 1 deletion obp-api/src/main/scala/code/api/util/APIUtil.scala
Original file line number Diff line number Diff line change
Expand Up @@ -2256,7 +2256,7 @@ object APIUtil extends MdcLoggable with CustomJsonFormats{
// Virtual roles granted by super_admin_user_ids prop
val superAdminVirtualRoles: List[String] = List("CanCreateEntitlementAtOneBank", "CanCreateEntitlementAtAnyBank", "CanGetAnyUser")
// Virtual roles granted by oidc_operator_user_ids prop
val oidcOperatorVirtualRoles: List[String] = List("CanGetAnyUser", "CanVerifyUserCredentials", "CanVerifyOidcClient", "CanGetOidcClient")
val oidcOperatorVirtualRoles: List[String] = List("CanGetAnyUser", "CanVerifyUserCredentials", "CanVerifyOidcClient", "CanGetOidcClient", "CanGetConsumers", "CanCreateConsumer")

def hasScope(bankId: String, consumerId: String, role: ApiRole): Boolean = {
!Scope.scope.vend.getScope(bankId, consumerId, role.toString).isEmpty
Expand Down
10 changes: 10 additions & 0 deletions obp-api/src/main/scala/code/api/util/ApiRole.scala
Original file line number Diff line number Diff line change
Expand Up @@ -580,6 +580,16 @@ object ApiRole extends MdcLoggable{
case class CanDeleteIpPenalty(requiresBankId: Boolean = false) extends ApiRole
lazy val canDeleteIpPenalty = CanDeleteIpPenalty()

// Platform Apps: the Consumers an installation runs as part of its own deployment (Portal, API Manager...).
case class CanCreatePlatformApp(requiresBankId: Boolean = false) extends ApiRole
lazy val canCreatePlatformApp = CanCreatePlatformApp()

case class CanGetPlatformApps(requiresBankId: Boolean = false) extends ApiRole
lazy val canGetPlatformApps = CanGetPlatformApps()

case class CanDeletePlatformApp(requiresBankId: Boolean = false) extends ApiRole
lazy val canDeletePlatformApp = CanDeletePlatformApp()

// Shows which Consumers and client IP addresses are sending the most traffic to the instance
// (TrafficSources). About the instance, so held at the empty bank id. It names Consumers and IP
// addresses, which is why it is a Role of its own and not part of CanGetTelemetry.
Expand Down
Loading
Loading