Scitokens/Xrootd-Scitokens: Flexible Authorization Handling
Scitokens/Xrootd-Scitokens: Flexible Authorization Handling
复制标题
Scitokens/Xrootd-Scitokens:灵活的授权处理
DOI:
10.5281/zenodo.1206217
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
D. Weitzel
中科院分区:
文献类型:
--
作者:
B. Bockelman;D. Weitzel
In this release, we significantly improve the authorization handling with the following three features:
base_path can now take a comma-separated list of paths, allowing a single issuer to cover multiple parts of the filesystem namespace.
restricted_path was introduced. This option restricts the paths the issuer is allowed to issue authorizations for within its base area(s). It is intended to ease the migrations to a SciTokens-based setup for existing storages where multiple groups share a same base area.
default_user was introduced. This provides the ability to set the username in the credential for requests that pass the scitokens authorization. It allows the sysadmin to map the filesystem access of an issuer to a specific Unix username.