136 Commits

Author SHA1 Message Date
david-leifker
10ea10ce85
fix(security): require signed/encrypted jwt tokens (#6565)
* fix(security): require unsigned/encrypted jwt tokens

* Add import

Co-authored-by: Pedro Silva <pedro@acryl.io>
2022-12-26 19:45:32 +00:00
david-leifker
ecc01b9a46
refactor(restli-mce-consumer) (#6744)
* fix(security): commons-text in frontend

* refactor(restli): set threads based on cpu cores
feat(mce-consumers): hit local restli endpoint

* testing docker build

* Add retry configuration options for entity client

* Kafka debugging

* fix(kafka-setup): parallelize topic creation

* Adjust docker build

* Docker build updates

* WIP

* fix(lint): metadata-ingestion lint

* fix(gradle-docker): fix docker frontend dep

* fix(elastic): fix race condition between gms and mae for index creation

* Revert "fix(elastic): fix race condition between gms and mae for index creation"

This reverts commit 9629d12c3bdb3c0dab87604d409ca4c642c9c6d3.

* fix(test): fix datahub frontend test for clean/test cycle

* fix(test): datahub-frontend missing assets in test

* fix(security): set protobuf lib datahub-upgrade & mce/mae-consumer

* gitingore update

* fix(docker): remove platform on docker base image, set by buildx

* refactor(kafka-producer): update kafka producer tracking/logging

* updates per PR feedback

* Add documentation around mce standalone consumer
Kafka consumer concurrency to follow thread count for restli & sql connection pool

Co-authored-by: leifker <dleifker@gmail.com>
Co-authored-by: Pedro Silva <pedro@acryl.io>
2022-12-26 16:09:08 +00:00
david-leifker
bacc2f957b
fix(oidc): fix oidc authentication loop (#6848)
* fix(oidc): fix oidc authentication loop
2022-12-22 16:12:51 -06:00
david-leifker
2a182f4846
fix(pac4j-oidc): add verifier parameter (#6835)
* fix(pac4j-oidc): add verifier parameter
2022-12-21 20:11:11 -06:00
david-leifker
27ea3bf125
fix(security): play framework upgrade (#6626)
* fix(security): play framework upgrade
2022-12-08 20:27:51 -06:00
david-leifker
a2dc229c62
fix(tests): Misc updates for tests, auth log level, and quickstart (#6491) 2022-11-29 08:44:55 -08:00
Aditya Radhakrishnan
4b3120478d
feat(auth): add sso frontend endpoint (#6273) 2022-10-31 16:39:26 -07:00
Aditya Radhakrishnan
d905cdffc1
fix(oidc): change default oidc username claim to be email (#6220) 2022-10-23 21:09:46 -07:00
John Joyce
1bcc9df853
fix(oidc): Avoid storing Pac4j profile in cookie (#6260) 2022-10-21 10:58:27 -07:00
Aditya Radhakrishnan
73a3aa3a3d
fix(auth): fix login endpoint to respect session expiration env var (#6151) 2022-10-07 14:08:43 -07:00
Aditya Radhakrishnan
e8259788a3
feat(tracking): add telemetry for frontend events (#6129) 2022-10-06 18:56:32 -07:00
Aditya Radhakrishnan
325b959ea6
feat(roles): add ability to invite users into a role (#6015) 2022-09-23 16:48:23 -07:00
Aditya Radhakrishnan
011421dfaa
fix(frontend): fix authenticate endpoint to create new session on redirect (#6036) 2022-09-23 12:05:53 -07:00
Aditya Radhakrishnan
d13145e32d
fix(frontend): refactoring AuthServiceClient (#6029) 2022-09-22 18:26:42 -07:00
John Joyce
2d29d0b121
refactor(frontend): Addressing minor issues (#6012) 2022-09-21 14:21:55 -07:00
Patrick Marx
de547a9af9
fix(frontend): forward Host header as X-Forwarded-Host (#5816) 2022-09-09 14:13:30 -07:00
John Joyce
5974721697
fix(ui): Long overdue - Fix red error screens during OIDC login, logout exception scenarios (#5708) 2022-08-23 09:54:34 -07:00
neojunjie
8d4b7cf8a1
fix(PlayCookie) PLAY_TOKEN cookie rejected because userprofile exceeds 4096 chars (#5114) 2022-07-14 09:52:51 -07:00
Alexey Kravtsov
8dd7dfceab
fix(jaas): fix auth.jaas.enabled option parsing (#5179) 2022-06-16 12:07:49 -07:00
chen4119
7bf27336ef
feat(frontend): Parse JWT access token claims (#5138) 2022-06-13 07:12:06 -07:00
Aditya Radhakrishnan
fdf4e48495
feat(users): add ability to add native users from the UI (#5097)
Co-authored-by: John Joyce <john@acryl.io>
2022-06-08 18:13:22 -07:00
RyanHolstien
21715957c8
feat(oidc): add configurable read timeout (#5088) 2022-06-06 13:39:44 -07:00
piyushn-stripe
007af1bcf6
feat(frontend): Allow overriding frontend with a custom akka http server (#5031) 2022-05-31 17:35:23 -07:00
RyanHolstien
72eff249ad
chore(deps): play - upgrade for CVEs (#4891) 2022-05-10 16:15:53 -07:00
RyanHolstien
9422578e41
Revert "chore(deps): upgrade play to remove CVEs (#4864)" (#4868)
This reverts commit 84a026b1263ab91cd4010d905129a279523f413e.
2022-05-06 15:08:35 -07:00
RyanHolstien
d70df06c21
chore(jetty): upgrade jetty to 9.4.46 for CVE (#4857) 2022-05-06 14:18:20 -07:00
RyanHolstien
84a026b126
chore(deps): upgrade play to remove CVEs (#4864) 2022-05-06 13:42:03 -07:00
RyanHolstien
ad7a92a098
Revert "chore(deps): upgrade play dependencies to remove CVE vulnerabilities (#4820)" (#4861)
This reverts commit fa4abeade750c487504976e13c7aad2789b9e49e.
2022-05-06 10:18:30 -07:00
RyanHolstien
fa4abeade7
chore(deps): upgrade play dependencies to remove CVE vulnerabilities (#4820) 2022-05-06 08:05:19 -07:00
chen4119
fc32e78ac1
fix(datahub-frontend): OIDC discovery URL will not have NONE as auth_methods_supported (#4710) 2022-04-26 14:01:18 -07:00
John Joyce
c69310522b
feat(metadata service): Introducing Platform Events (#4477) 2022-03-29 18:32:04 -07:00
Pedro Silva
db35aca869
feat(frontend) Adds multiple group claim support (#4450) 2022-03-21 13:33:53 -07:00
John Joyce
11f809abd2
feat(oidc): Adding support for extracting single string groups claim (#4419) 2022-03-15 17:41:19 -07:00
John Joyce
86f240769f
Fixing OIDC encryption bug from v0.8.29 (#4418) 2022-03-15 17:41:08 -07:00
John Joyce
c713b60810
fix(oidc): Update group membership each login (and make group extraction disabled by default) (#4380) 2022-03-11 08:49:31 -08:00
John Joyce
ef31b0ee6a
fix(frontend): Fix common OIDC issues (#4351) 2022-03-08 14:27:19 -08:00
Dexter Lee
18dd5b6c13
feat(Impact Analysis): Support impact analysis to check all downstreams of given entity (#4322) 2022-03-04 16:10:25 -08:00
Aseem Bansal
4aa14214d9
feat(ingest): rest-emitter: make test_connection more robust (#3919)
Co-authored-by: Shirshanka Das <shirshanka@apache.org>
2022-01-19 18:51:47 -08:00
John Joyce
f49666a230
feat(auth): Metadata Service Authentication! (#3598) 2021-11-22 16:33:14 -08:00
John Joyce
1062c3ebc5
fix(frontend): Hush noisy datahub-frontend warnings (#3559) 2021-11-12 16:33:06 -08:00
John Joyce
c7d3f8b930
Proxy GMS API requests (#3509) 2021-11-08 13:37:31 -08:00
John Joyce
710dc3db1c
fix(oidc): Fix the oidc lastModifiedAt bug (#3429) 2021-10-20 17:09:02 -07:00
John Joyce
a25434c81e
fix(oidc): add name claim extraction (#3384) 2021-10-13 18:56:20 -07:00
John Joyce
ed01b59a00
feat(users & groups): User & Groups Management GraphQL APIs + UI (#3318) 2021-10-07 16:14:35 -07:00
John Joyce
fe589a58b3
fix(oidc): Tolerate null emails (#3330) 2021-10-05 19:30:51 -07:00
John Joyce
c742cbd62d
Attach Client ID to token request in Authentication Mode none (#3308) 2021-09-29 10:28:28 -07:00
John Joyce
33f4d2ede0
fix(upgrade): Improving NoCodeUpgrade logic to account for Bootstrap logic (#3301) 2021-09-28 16:30:49 -07:00
John Joyce
add778c04a
feat(oidc): Support NONE client auth method in OIDC (stopgap) (#3305) 2021-09-28 16:30:17 -07:00
John Joyce
dfcfc6984d
Fixing response type bug (#3251) 2021-09-16 16:54:38 -07:00
Dexter Lee
9172700585
fix(frontend): Add additional sasl config for kafka producer in datahub-frontend (#3220) 2021-09-15 18:08:54 -07:00