<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Talend Studio: Authorization for REST service-based Routes with HTTP basic authentication in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Talend-Studio-Authorization-for-REST-service-based-Routes-with/ta-p/2150608</link>
    <description>&lt;DIV class="talend-tkb-migrated-content"&gt;
&lt;P&gt;When implementing a REST service in a Mediation route using the &lt;STRONG&gt;cREST&lt;/STRONG&gt;&amp;nbsp;component as route consumer, Studio provides three ways to authenticate the service: HTTP Basic, SAML token, and OpenID Connect. Only the SAML token provides an option to enable authorization. Unfortunately, the SAML token is not an adequate solution in many use cases because third-party service clients cannot be expected to acquire a SAML token and integrate it into the request. Often HTTP basic authentication, together with HTTPS, is the only way to integrate third-party clients.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Cause&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Studio does not support authorization when selecting HTTP basic authentication as an authentication type.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Resolution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Overview of best practice&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;In Routes, you can enhance the &lt;STRONG&gt;cRest&lt;/STRONG&gt; component to implement role-based authorization with the help of an authorizing filter.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Detailed explanation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;BLOCKQUOTE class="quote"&gt;Sources for the project are available in the attached &lt;STRONG&gt;Authorization.zip&lt;/STRONG&gt;&lt;SPAN&gt; file.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The &lt;STRONG&gt;cREST&lt;/STRONG&gt;&amp;nbsp;component is based on the Camel CXFRS component and the JAX-RS implementation of CXF. In JAX-RS, the runtime is extended and customized through providers. CXF JAX-RS provides a &lt;A title="SimpleAuthorizingFilter" href="https://cxf.apache.org/javadoc/latest/org/apache/cxf/jaxrs/security/SimpleAuthorizingFilter.html" target="_blank" rel="noopener"&gt;SimpleAuthorizingFilter&lt;/A&gt;, extending a REST endpoint with role-based authorization.&lt;/P&gt;
&lt;P&gt;One way to add providers in CXFRS is to add the &lt;STRONG&gt;providers&lt;/STRONG&gt; option to the endpoint URL of the CXFRS component. The providers are registered as beans in the Camel registry and referenced by name in the &lt;STRONG&gt;providers&lt;/STRONG&gt; option. For more information on the exact syntax in the &lt;STRONG&gt;providers&lt;/STRONG&gt; option and a complete list of all other options, see the Apache Camel, &lt;A href="http://camel.apache.org/cxfrs.html" target="_blank" rel="noopener"&gt;CXF-RS Component&lt;/A&gt; page.&lt;/P&gt;
&lt;P&gt;Figure 1 shows a Mediation route in Studio that implements a web service with authentication and authorization.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VF.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/121640iAAA61EBFAD58F6F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VF.jpg" alt="0EM5b000003h7VF.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 1. REST service with authentication and authorization&lt;/P&gt;
&lt;P&gt;In the &lt;STRONG&gt;cREST&lt;/STRONG&gt; component, you can enforce authentication on the &lt;STRONG&gt;Basic settings&lt;/STRONG&gt; tab by enabling the &lt;STRONG&gt;Use Authentication&lt;/STRONG&gt; check box and selecting &lt;STRONG&gt;HTTP Basic&lt;/STRONG&gt; as the authentication protocol.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VP.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/123949iF71F65356ED4C219/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VP.jpg" alt="0EM5b000003h7VP.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 2. Basic settings of the REST endpoint&lt;/P&gt;
&lt;P&gt;Enforcing authorization in the &lt;STRONG&gt;cREST&lt;/STRONG&gt;&amp;nbsp;component is slightly more involved. It requires setting the additional &lt;STRONG&gt;"providers"&lt;/STRONG&gt; option, which is implemented by the bean registered under the name of &lt;STRONG&gt;"authFilter"&lt;/STRONG&gt;&amp;nbsp;in the &lt;STRONG&gt;Advanced settings&lt;/STRONG&gt; tab, as shown in Figure 3.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VU.jpg" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/121472i5AAB17B93934FA05/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VU.jpg" alt="0EM5b000003h7VU.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 3. Advanced settings of the REST endpoint&lt;/P&gt;
&lt;P&gt;In this example, the &lt;STRONG&gt;cBeanRegister&lt;/STRONG&gt; component initializes the &lt;STRONG&gt;SimpleAuthorizingFilter&lt;/STRONG&gt;, and registers it under the name &lt;STRONG&gt;"authFilter"&lt;/STRONG&gt;, as shown in Figure 4.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VZ.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/124897i58848B4A8988EA6D/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VZ.jpg" alt="0EM5b000003h7VZ.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 4. Definition and registration of the authorizing filter&lt;/P&gt;
&lt;P&gt;The filter is mainly a wrapper around the &lt;A title="SimpleAuthorizingInterceptor" href="https://cxf.apache.org/javadoc/latest/org/apache/cxf/interceptor/security/SimpleAuthorizingInterceptor.html" target="_blank" rel="noopener"&gt;SimpleAuthorizingInterceptor&lt;/A&gt;, which does the actual work. It is also the interceptor where the roles are specified that authorize the service to execute. In this article, the &lt;STRONG&gt;setGlobalRoles&lt;/STRONG&gt; method specifies the roles &lt;STRONG&gt;manager&lt;/STRONG&gt; and &lt;STRONG&gt;admin&lt;/STRONG&gt; in the beans definition code, which allows them to execute the service. In a real-world use case, you would specify them through a context variable.&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;Authorization.zip&lt;/STRONG&gt; file, attached to this article, contains an executable sample project (v6.5.1). You can experiment with the project by deploying it in a Talend Runtime and trying different outcomes. For example, you could add a few users to the &lt;STRONG&gt;etc/users.properties&lt;/STRONG&gt; file with corresponding roles.&lt;/P&gt;
&lt;P&gt;Figure 5 shows a &lt;STRONG&gt;users.properties&lt;/STRONG&gt; file where the user &lt;STRONG&gt;alice&lt;/STRONG&gt; has the &lt;STRONG&gt;manager&lt;/STRONG&gt; and &lt;STRONG&gt;employee&lt;/STRONG&gt; role, and user &lt;STRONG&gt;bob&lt;/STRONG&gt; only has the &lt;STRONG&gt;employee&lt;/STRONG&gt; role. Call the deployed service using the URL (&lt;STRONG&gt;&lt;A href="http://localhost:8040/services/test" target="_blank" rel="noopener"&gt;http://localhost:8040/services/test&lt;/A&gt;&lt;/STRONG&gt;). If authenticating with user &lt;STRONG&gt;alice&lt;/STRONG&gt; the call is successful. If authenticating with user &lt;STRONG&gt;bob&lt;/STRONG&gt; you should get HTTP return code &lt;STRONG&gt;403&lt;/STRONG&gt;. The sample not only works with the JAAS PropertiesLoginModule but also with the other login modules supported by the Talend Runtime, such as LDAPLoginModule or SyncopeLoginModule.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7Vj.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/124019iAF516B109B9C56A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7Vj.jpg" alt="0EM5b000003h7Vj.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 5. Sample users file&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 19 Aug 2024 01:57:17 GMT</pubDate>
    <dc:creator>TalendSolutionExpert</dc:creator>
    <dc:date>2024-08-19T01:57:17Z</dc:date>
    <item>
      <title>Talend Studio: Authorization for REST service-based Routes with HTTP basic authentication</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Talend-Studio-Authorization-for-REST-service-based-Routes-with/ta-p/2150608</link>
      <description>&lt;DIV class="talend-tkb-migrated-content"&gt;
&lt;P&gt;When implementing a REST service in a Mediation route using the &lt;STRONG&gt;cREST&lt;/STRONG&gt;&amp;nbsp;component as route consumer, Studio provides three ways to authenticate the service: HTTP Basic, SAML token, and OpenID Connect. Only the SAML token provides an option to enable authorization. Unfortunately, the SAML token is not an adequate solution in many use cases because third-party service clients cannot be expected to acquire a SAML token and integrate it into the request. Often HTTP basic authentication, together with HTTPS, is the only way to integrate third-party clients.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Cause&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Studio does not support authorization when selecting HTTP basic authentication as an authentication type.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Resolution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Overview of best practice&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;In Routes, you can enhance the &lt;STRONG&gt;cRest&lt;/STRONG&gt; component to implement role-based authorization with the help of an authorizing filter.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Detailed explanation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;BLOCKQUOTE class="quote"&gt;Sources for the project are available in the attached &lt;STRONG&gt;Authorization.zip&lt;/STRONG&gt;&lt;SPAN&gt; file.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The &lt;STRONG&gt;cREST&lt;/STRONG&gt;&amp;nbsp;component is based on the Camel CXFRS component and the JAX-RS implementation of CXF. In JAX-RS, the runtime is extended and customized through providers. CXF JAX-RS provides a &lt;A title="SimpleAuthorizingFilter" href="https://cxf.apache.org/javadoc/latest/org/apache/cxf/jaxrs/security/SimpleAuthorizingFilter.html" target="_blank" rel="noopener"&gt;SimpleAuthorizingFilter&lt;/A&gt;, extending a REST endpoint with role-based authorization.&lt;/P&gt;
&lt;P&gt;One way to add providers in CXFRS is to add the &lt;STRONG&gt;providers&lt;/STRONG&gt; option to the endpoint URL of the CXFRS component. The providers are registered as beans in the Camel registry and referenced by name in the &lt;STRONG&gt;providers&lt;/STRONG&gt; option. For more information on the exact syntax in the &lt;STRONG&gt;providers&lt;/STRONG&gt; option and a complete list of all other options, see the Apache Camel, &lt;A href="http://camel.apache.org/cxfrs.html" target="_blank" rel="noopener"&gt;CXF-RS Component&lt;/A&gt; page.&lt;/P&gt;
&lt;P&gt;Figure 1 shows a Mediation route in Studio that implements a web service with authentication and authorization.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VF.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/121640iAAA61EBFAD58F6F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VF.jpg" alt="0EM5b000003h7VF.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 1. REST service with authentication and authorization&lt;/P&gt;
&lt;P&gt;In the &lt;STRONG&gt;cREST&lt;/STRONG&gt; component, you can enforce authentication on the &lt;STRONG&gt;Basic settings&lt;/STRONG&gt; tab by enabling the &lt;STRONG&gt;Use Authentication&lt;/STRONG&gt; check box and selecting &lt;STRONG&gt;HTTP Basic&lt;/STRONG&gt; as the authentication protocol.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VP.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/123949iF71F65356ED4C219/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VP.jpg" alt="0EM5b000003h7VP.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 2. Basic settings of the REST endpoint&lt;/P&gt;
&lt;P&gt;Enforcing authorization in the &lt;STRONG&gt;cREST&lt;/STRONG&gt;&amp;nbsp;component is slightly more involved. It requires setting the additional &lt;STRONG&gt;"providers"&lt;/STRONG&gt; option, which is implemented by the bean registered under the name of &lt;STRONG&gt;"authFilter"&lt;/STRONG&gt;&amp;nbsp;in the &lt;STRONG&gt;Advanced settings&lt;/STRONG&gt; tab, as shown in Figure 3.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VU.jpg" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/121472i5AAB17B93934FA05/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VU.jpg" alt="0EM5b000003h7VU.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 3. Advanced settings of the REST endpoint&lt;/P&gt;
&lt;P&gt;In this example, the &lt;STRONG&gt;cBeanRegister&lt;/STRONG&gt; component initializes the &lt;STRONG&gt;SimpleAuthorizingFilter&lt;/STRONG&gt;, and registers it under the name &lt;STRONG&gt;"authFilter"&lt;/STRONG&gt;, as shown in Figure 4.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7VZ.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/124897i58848B4A8988EA6D/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7VZ.jpg" alt="0EM5b000003h7VZ.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 4. Definition and registration of the authorizing filter&lt;/P&gt;
&lt;P&gt;The filter is mainly a wrapper around the &lt;A title="SimpleAuthorizingInterceptor" href="https://cxf.apache.org/javadoc/latest/org/apache/cxf/interceptor/security/SimpleAuthorizingInterceptor.html" target="_blank" rel="noopener"&gt;SimpleAuthorizingInterceptor&lt;/A&gt;, which does the actual work. It is also the interceptor where the roles are specified that authorize the service to execute. In this article, the &lt;STRONG&gt;setGlobalRoles&lt;/STRONG&gt; method specifies the roles &lt;STRONG&gt;manager&lt;/STRONG&gt; and &lt;STRONG&gt;admin&lt;/STRONG&gt; in the beans definition code, which allows them to execute the service. In a real-world use case, you would specify them through a context variable.&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;Authorization.zip&lt;/STRONG&gt; file, attached to this article, contains an executable sample project (v6.5.1). You can experiment with the project by deploying it in a Talend Runtime and trying different outcomes. For example, you could add a few users to the &lt;STRONG&gt;etc/users.properties&lt;/STRONG&gt; file with corresponding roles.&lt;/P&gt;
&lt;P&gt;Figure 5 shows a &lt;STRONG&gt;users.properties&lt;/STRONG&gt; file where the user &lt;STRONG&gt;alice&lt;/STRONG&gt; has the &lt;STRONG&gt;manager&lt;/STRONG&gt; and &lt;STRONG&gt;employee&lt;/STRONG&gt; role, and user &lt;STRONG&gt;bob&lt;/STRONG&gt; only has the &lt;STRONG&gt;employee&lt;/STRONG&gt; role. Call the deployed service using the URL (&lt;STRONG&gt;&lt;A href="http://localhost:8040/services/test" target="_blank" rel="noopener"&gt;http://localhost:8040/services/test&lt;/A&gt;&lt;/STRONG&gt;). If authenticating with user &lt;STRONG&gt;alice&lt;/STRONG&gt; the call is successful. If authenticating with user &lt;STRONG&gt;bob&lt;/STRONG&gt; you should get HTTP return code &lt;STRONG&gt;403&lt;/STRONG&gt;. The sample not only works with the JAAS PropertiesLoginModule but also with the other login modules supported by the Talend Runtime, such as LDAPLoginModule or SyncopeLoginModule.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0EM5b000003h7Vj.jpg"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/124019iAF516B109B9C56A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="0EM5b000003h7Vj.jpg" alt="0EM5b000003h7Vj.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 5. Sample users file&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 19 Aug 2024 01:57:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Talend-Studio-Authorization-for-REST-service-based-Routes-with/ta-p/2150608</guid>
      <dc:creator>TalendSolutionExpert</dc:creator>
      <dc:date>2024-08-19T01:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Talend Studio: Authorization for REST service-based Routes with HTTP basic authentication</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Talend-Studio-Authorization-for-REST-service-based-Routes-with/tac-p/2476694#M14423</link>
      <description>&lt;P&gt;&lt;SPAN class="Y2IQFc"&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Thank you for this nice article but I cannot find the &lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authorization&lt;/STRONG&gt;.zip file attached to the article in order to test your example on a service or a Route. Could you add it as an attachment please&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 17:00:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Talend-Studio-Authorization-for-REST-service-based-Routes-with/tac-p/2476694#M14423</guid>
      <dc:creator>Dave_Simo</dc:creator>
      <dc:date>2024-08-18T17:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Talend Studio: Authorization for REST service-based Routes with HTTP basic authentication</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Talend-Studio-Authorization-for-REST-service-based-Routes-with/tac-p/2476711#M14425</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/274551"&gt;@Dave_Simo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for letting us know the missing and the attached &lt;STRONG&gt;Authorization.zip&lt;/STRONG&gt;&lt;SPAN&gt; file&lt;/SPAN&gt; is available now.&lt;/P&gt;
&lt;P&gt;Feel free to let us if it works for you.&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Sabrina&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 01:59:48 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Talend-Studio-Authorization-for-REST-service-based-Routes-with/tac-p/2476711#M14425</guid>
      <dc:creator>Xiaodi_Shi</dc:creator>
      <dc:date>2024-08-19T01:59:48Z</dc:date>
    </item>
  </channel>
</rss>

