hivefans icon

zeppelin-shiro.ini

hivefans | PRO | 05/18/21 07:56:58 AM UTC | 0 โญ | 13906 ๐Ÿ‘๏ธ | Never โฐ | []
INI file |

0 B

|

None

|

0 ๐Ÿ‘

/

0 ๐Ÿ‘Ž

[main]
ldapRealm=org.apache.zeppelin.realm.LdapRealm
ldapRealm.contextFactory.authenticationMechanism=simple
ldapRealm.contextFactory.url=ldap://10.252.143.193:389
ldapRealm.userDnTemplate=uid={0},ou=people,dc=gwmedc,dc=com
ldapRealm.pagingSize = 200
ldapRealm.authorizationEnabled=true
ldapRealm.searchBase=dc=gwmedc,dc=com
ldapRealm.userSearchBase = ou=people,dc=gwmedc,dc=com
ldapRealm.groupSearchBase = ou=group,dc=gwmedc,dc=com
ldapRealm.groupObjectClass=posixGroup
ldapRealm.userLowerCase = true
ldapRealm.memberAttribute = memberuid
ldapRealm.groupSearchFilter=(&(objectClass=posixGroup)(memberuid={0}))
ldapRealm.userSearchScope = subtree
ldapRealm.groupSearchScope = subtree
ldapRealm.contextFactory.systemUsername= cn=admin,dc=gwmedc,dc=com
### ๆˆ‘็š„cn=admin,dc=domain,dc=comๅฏ†็ ่ฎพ็ฝฎ็š„ๆ˜ฏadmin๏ผŒ่ฟ™้‡Œ้œ€่ฆๆ›ฟๆขๆˆ็”จๆˆท่‡ชๅทฑ่ฎพ็ฝฎ็š„ๅฏ†็ 
ldapRealm.contextFactory.systemPassword = admin
ldapRealm.groupSearchEnableMatchingRuleInChain = false
### ๅฐ†LdapไธŠ็š„admin groupๆ˜ ๅฐ„ๆˆzeppelin็š„admin่ง’่‰ฒ, user groupๆ˜ ๅฐ„ๆˆzeppelin็š„user_role่ง’่‰ฒ
ldapRealm.rolesByGroup = admin:admin,user:user_role
securityManager.realms = $ldapRealm
ย 
sessionManager = org.apache.shiro.web.session.mgt.DefaultWebSessionManager
cookie = org.apache.shiro.web.servlet.SimpleCookie
cookie.name = JSESSIONID
cookie.httpOnly = true
sessionManager.sessionIdCookie = $cookie
securityManager.sessionManager = $sessionManager
securityManager.sessionManager.globalSessionTimeout = 86400000
shiro.loginUrl = /api/login
securityManager.sessionManager = $sessionManager
securityManager.realms = $ldapRealm
ย 
sessionManager = org.apache.shiro.web.session.mgt.DefaultWebSessionManager
### Enables 'HttpOnly' flag in Zeppelin cookies
cookie = org.apache.shiro.web.servlet.SimpleCookie
cookie.name = JSESSIONID
cookie.httpOnly = true
### Uncomment the below line only when Zeppelin is running over HTTPS
#cookie.secure = true
sessionManager.sessionIdCookie = $cookie
securityManager.sessionManager = $sessionManager
# 86,400,000 milliseconds = 24 hour
securityManager.sessionManager.globalSessionTimeout = 86400000
shiro.loginUrl = /api/login
ย 
[roles]
#devops = *
#admin = *
ย 
[urls]
/api/version = anon
/api/interpreter/setting/restart/** = authc
/api/interpreter/** = authc, roles[admin]
/api/configurations/** = authc, roles[admin]
/api/credential/** = authc, roles[admin]
#/** = anon
/** = authc

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    ๐Ÿ‘

    /

    ๐Ÿ‘Ž