This Confluence has been LDAP enabled, if you are an ASF Committer, please use your LDAP Credentials to login. Any problems file an INFRA jira ticket please.

Child pages
  • KnoxSSO and Custom Application Development
Skip to end of metadata
Go to start of metadata

The usecase here is described as an application that is:

  1. Proxied via KnoxGateway (service def for webapp required)
  2. Leveraging KnoxSSO (either natively or via SSOCookieProvider in Knox topology)
  3. Web App backend makes hadoop API calls through Knox using KnoxSSO cookie (will require topology with SSOCookieProvider)

As long as the KnoxSSO cookie is valid it can be replayed by the backend for API calls.

There may be a window where the cookie is valid for the request to the webapp but not by the time it gets to the API call in the backend.

We will need to be able to react to a redirect in that case.

Alternatively, you could leverage KnoxToken service to exchange the KnoxSSO cookie for a JWT token with associated metadata and manage that token in the application session.

Requesting a new token prior to expiration.

This would require another topology that was protected by the JWTProvider rather than the SSOCookieProvider and that you send the token as a bearer token to the API calls rather than a cookie.