Update AAA shiro configuration for CAS AAF 06/71506/1
authorAaron Hay <aaron.hay@att.com>
Tue, 30 Oct 2018 22:40:07 +0000 (18:40 -0400)
committerAaron Hay <aaron.hay@att.com>
Tue, 30 Oct 2018 22:40:25 +0000 (18:40 -0400)
Update configuration file based on AAF bootstrap data in the AAF role.dat file.

Change-Id: Iafbb1f37383fb97a00441539e14ace8e9282a330
Issue-ID: OOM-1488
Signed-off-by: Aaron Hay <aaron.hay@att.com>
kubernetes/appc/resources/config/appc/opt/onap/appc/data/properties/aaa-app-config.xml

index 3dd78d3..81834ea 100644 (file)
     <urls>
         <pair-key>/auth/**</pair-key>
 <!--        <pair-value>authcBasic, roles[admin], dynamicAuthorization</pair-value> -->
-        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-admin|*]</pair-value>
+        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-api|*]</pair-value>
     </urls>
     <urls>
         <pair-key>/restconf/config/aaa-cert-mdsal**</pair-key>
 <!--        <pair-value>authcBasic, roles[admin]</pair-value> -->
-        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-admin|*]</pair-value>
+        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-api|*]</pair-value>
     </urls>
     <urls>
         <pair-key>/restconf/operational/aaa-cert-mdsal**</pair-key>
 <!--        <pair-value>authcBasic, roles[admin]</pair-value> -->
-        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-admin|*]</pair-value>
+        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-api|*]</pair-value>
     </urls>
     <urls>
         <pair-key>/restconf/operations/aaa-cert-rpc**</pair-key>
 <!--        <pair-value>authcBasic, roles[admin]</pair-value> -->
-        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-admin|*]</pair-value>
+        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-api|*]</pair-value>
     </urls>
     <urls>
         <pair-key>/restconf/config/aaa-authn-model**</pair-key>
 <!--        <pair-value>authcBasic, roles[admin]</pair-value> -->
-        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-admin|*]</pair-value>
+        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-api|*]</pair-value>
     </urls>
     <urls>
         <pair-key>/restconf/operational/aaa-authn-model**</pair-key>
 <!--        <pair-value>authcBasic, roles[admin]</pair-value> -->
-        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-admin|*]</pair-value>
+        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-api|*]</pair-value>
     </urls>
     <urls>
         <pair-key>/restconf/operations/cluster-admin**</pair-key>
 <!--        <pair-value>authcBasic, roles[admin]</pair-value> -->
-        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-admin|*]</pair-value>
+        <pair-value>authcBasic, roles[org.onap.appc.odl|odl-api|*]</pair-value>
     </urls>
     <urls>
         <pair-key>/**</pair-key>