Header-based Authentication¶
In this method, the authenticated user name and roles are read from HTTP header variables in the request.
This is especially useful when the WebGIS Portal is operated behind a reverse proxy. In that case, the reverse proxy handles the authentication and authorization of requests. When forwarding requests, it adds specific HTTP headers that contain information about the authenticated user. The WebGIS Portal reads these header variables and uses them for access control for maps and map services.
Danger
When this method is used, the WebGIS Portal must be reachable only through the reverse proxy. If the portal is directly accessible, attackers could abuse this method. The WebGIS Portal does not verify whether the header variables were actually set by the reverse proxy.
Header-based authentication is enabled through the header-authentication section in portal.config:
<section name="header-authentication">
<add key="use" value="true" /> <!-- default false -->
<add key="username-variable" value="X-username" />
<add key="roles-variable" value="X-roles" />
<add key="extract-role-parameters" value="none" /> <!-- none, insideBrackets -->
<add key="role-separator" value=";" /> <!-- default: , -->
<add key="role-parameters-separator" value="," /> <!-- default: , -->
<add key="user-prefix" value="header-user" />
<add key="role-prefix" value="header-role" />
<!-- Optional: -->
<add key="extended-role-parameters-from-headers-prefix" value="X-AUTH-" />
<add key="extended-role-parameters-from-headers" value="roleparam1,roleparam2" />
</section>
Configuration values¶
Attribute |
Description |
|---|---|
|
Enables header-based authentication. |
|
Defines the header name that contains the user name. |
|
Defines the header name that carries the user roles. |
|
Role parameters allow an additional restriction of roles.
For example, if a user group is assigned the role Example for |
|
Separator between multiple roles in the |
|
Separator for individual role parameters during parsing.
Example: |
|
Defines namespaces for users and roles to avoid ambiguity when multiple authentication methods are used.
The prefix is separated from the user name by Example:
In CMS permission management, the full name including the prefix is used
( |
|
These two parameters allow the definition of additional role parameters that are extracted from HTTP headers. The prefix is added before the parameter name to make it unique. -> The headers |