Skip to content

Conversation

@pavel-jares-bcm
Copy link
Contributor

Description

This PR allows cutting SMF record during the processing OIDC token. It a token is mapped to an identity the SMF record could be cut. It contains the mapped user and the source user. Because there is a possibility mapping OIDC token by other than sub properties the use can define a different properties to be logged. So the SMF records contains mapped user an a source user.

The feature is as default disabled to mitigate a performance impact.

The new configuration properties:

apiml.security.rauditx.onOidcUserIsMapped

  • Enable cutting SMF record on mapping distributed user from OIDC token to mainframe one.

apiml.security.rauditx.oidcSourceUserPaths

  • Comma separated JSON paths to find source user in the OIDC token to be cut in the SMF record.

Linked to # (issue)
Part of the # (epic)

Type of change

Please delete options that are not relevant.

  • fix: Bug fix (non-breaking change which fixes an issue)
  • feat: New feature (non-breaking change which adds functionality)
  • docs: Change in a documentation
  • refactor: Refactor the code
  • chore: Chore, repository cleanup, updates the dependencies.
  • BREAKING CHANGE or !: Breaking change (fix or feature that would cause existing functionality to not work as expected)

Checklist:

  • My code follows the style guidelines of this project
  • PR title conforms to commit message guideline ## Commit Message Structure Guideline
  • I have commented my code, particularly in hard-to-understand areas. In JS I did provide JSDoc
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • The java tests in the area I was working on leverage @nested annotations
  • Any dependent changes have been merged and published in downstream modules

For more details about how should the code look like read the Contributing guideline

Signed-off-by: Pavel Jareš <[email protected]>
Signed-off-by: Pavel Jareš <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Sensitive Sensitive change that requires peer review size/L

Projects

Development

Successfully merging this pull request may close these issues.

1 participant