Home
Home
German Version
Support
Impressum
25.2 Release ►

Start Chat with Collection

    Main Navigation

    • Preparation
      • Connectors
      • Create an InSpire VM on Hyper-V
      • Initial Startup for G7 appliances
      • Setup InSpire G7 primary and Standby Appliances
    • Datasources
      • Configuration - Atlassian Confluence Connector
      • Configuration - Best Bets Connector
      • Configuration - Box Connector
      • Configuration - COYO Connector
      • Configuration - Data Integration Connector
      • Configuration - Documentum Connector
      • Configuration - Dropbox Connector
      • Configuration - Egnyte Connector
      • Configuration - GitHub Connector
      • Configuration - Google Drive Connector
      • Configuration - GSA Adapter Service
      • Configuration - HL7 Connector
      • Configuration - IBM Connections Connector
      • Configuration - IBM Lotus Connector
      • Configuration - Jira Connector
      • Configuration - JVM Launcher Service
      • Configuration - LDAP Connector
      • Configuration - Microsoft Azure Principal Resolution Service
      • Configuration - Microsoft Dynamics CRM Connector
      • Configuration - Microsoft Exchange Connector
      • Configuration - Microsoft File Connector (Legacy)
      • Configuration - Microsoft File Connector
      • Configuration - Microsoft Graph Connector
      • Configuration - Microsoft Loop Connector
      • Configuration - Microsoft Project Connector
      • Configuration - Microsoft SharePoint Connector
      • Configuration - Microsoft SharePoint Online Connector
      • Configuration - Microsoft Stream Connector
      • Configuration - Microsoft Teams Connector
      • Configuration - Salesforce Connector
      • Configuration - SCIM Principal Resolution Service
      • Configuration - SemanticWeb Connector
      • Configuration - ServiceNow Connector
      • Configuration - Web Connector
      • Configuration - Yammer Connector
      • Data Integration Guide with SQL Database by Example
      • Indexing user-specific properties (Documentum)
      • Installation & Configuration - Atlassian Confluence Sitemap Generator Add-On
      • Installation & Configuration - Caching Principal Resolution Service
      • Installation & Configuration - Mindbreeze InSpire Insight Apps in Microsoft SharePoint On-Prem
      • Mindbreeze InSpire Insight Apps in Microsoft SharePoint Online
      • Mindbreeze Web Parts for Microsoft SharePoint
      • User Defined Properties (SharePoint 2013 Connector)
      • Whitepaper - Mindbreeze InSpire Insight Apps in Salesforce
      • Whitepaper - Web Connector - Setting Up Advanced Javascript Usecases
    • Configuration
      • CAS_Authentication
      • Configuration - Alerts
      • Configuration - Alternative Search Suggestions and Automatic Search Expansion
      • Configuration - Back-End Credentials
      • Configuration - Chinese Tokenization Plugin (Jieba)
      • Configuration - CJK Tokenizer Plugin
      • Configuration - Collected Results
      • Configuration - CSV Metadata Mapping Item Transformation Service
      • Configuration - Entity Recognition
      • Configuration - Exporting Results
      • Configuration - External Query Service
      • Configuration - Filter Plugins
      • Configuration - GSA Late Binding Authentication
      • Configuration - Identity Conversion Service - Replacement Conversion
      • Configuration - InceptionImageFilter
      • Configuration - Index-Servlets
      • Configuration - InSpire AI Chat and Insight Services for Retrieval Augmented Generation
      • Configuration - Item Property Generator
      • Configuration - Japanese Language Tokenizer
      • Configuration - Kerberos Authentication
      • Configuration - Management Center Menu
      • Configuration - Metadata Enrichment
      • Configuration - Metadata Reference Builder Plugin
      • Configuration - Mindbreeze Proxy Environment (Remote Connector)
      • Configuration - Personalized Relevance
      • Configuration - Plugin Installation
      • Configuration - Principal Validation Plugin
      • Configuration - Profile
      • Configuration - Reporting Query Logs
      • Configuration - Reporting Query Performance Tests
      • Configuration - Request Header Session Authentication
      • Configuration - Shared Configuration (Windows)
      • Configuration - Vocabularies for Synonyms and Suggest
      • Configuration of Thumbnail Images
      • Cookie-Authentication
      • Documentation - Mindbreeze InSpire
      • I18n Item Transformation
      • Installation & Configuration - Outlook Add-In
      • Installation - GSA Base Configuration Package
      • JWT Authentication
      • Language detection - LanguageDetector Plugin
      • Mindbreeze Personalization
      • Mindbreeze Property Expression Language
      • Mindbreeze Query Expression Transformation
      • SAML-based Authentication
      • Trusted Peer Authentication for Mindbreeze InSpire
      • Using the InSpire Snapshot for Development in a CI_CD Scenario
      • Whitepaper - AI Chat
      • Whitepaper - Create a Google Compute Cloud Virtual Machine InSpire Appliance
      • Whitepaper - Create a Microsoft Azure Virtual Machine InSpire Appliance
      • Whitepaper - Create AWS 10M InSpire Appliance
      • Whitepaper - Create AWS 1M InSpire Appliance
      • Whitepaper - Create AWS 2M InSpire Appliance
      • Whitepaper - Create Oracle Cloud 10M InSpire Application
      • Whitepaper - Create Oracle Cloud 1M InSpire Application
      • Whitepaper - MMC_ Services
      • Whitepaper - Natural Language Question Answering (NLQA)
      • Whitepaper - SSO with Microsoft AAD or AD FS
      • Whitepaper - Text Classification Insight Services
    • Operations
      • Adjusting the InSpire Host OpenSSH Settings - Set LoginGraceTime to 0 (Mitigation for CVE-2024-6387)
      • app.telemetry Statistics Regarding Search Queries
      • CIS Level 2 Hardening - Setting SELinux to Enforcing mode
      • Configuration - app.telemetry dashboards for usage analysis
      • Configuration - Usage Analysis
      • Deletion of Hard Disks
      • Handbook - Backup & Restore
      • Handbook - Command Line Tools
      • Handbook - Distributed Operation (G7)
      • Handbook - Filemanager
      • Handbook - Indexing and Search Logs
      • Handbook - Updates and Downgrades
      • Index Operating Concepts
      • Inspire Diagnostics and Resource Monitoring
      • Provision of app.telemetry Information on G7 Appliances via SNMPv3
      • Restoring to As-Delivered Condition
      • Whitepaper - Administration of Insight Services for Retrieval Augmented Generation
    • User Manual
      • Browser Extension
      • Cheat Sheet
      • iOS App
      • Keyboard Operation
    • SDK
      • api.chat.v1beta.generate Interface Description
      • api.v2.alertstrigger Interface Description
      • api.v2.export Interface Description
      • api.v2.personalization Interface Description
      • api.v2.search Interface Description
      • api.v2.suggest Interface Description
      • api.v3.admin.SnapshotService Interface Description
      • Debugging (Eclipse)
      • Developing an API V2 search request response transformer
      • Developing Item Transformation and Post Filter Plugins with the Mindbreeze SDK
      • Development of a Query Expression Transformer
      • Development of Insight Apps
      • Embedding the Insight App Designer
      • Java API Interface Description
      • OpenAPI Interface Description
    • Release Notes
      • Release Notes 20.1 Release - Mindbreeze InSpire
      • Release Notes 20.2 Release - Mindbreeze InSpire
      • Release Notes 20.3 Release - Mindbreeze InSpire
      • Release Notes 20.4 Release - Mindbreeze InSpire
      • Release Notes 20.5 Release - Mindbreeze InSpire
      • Release Notes 21.1 Release - Mindbreeze InSpire
      • Release Notes 21.2 Release - Mindbreeze InSpire
      • Release Notes 21.3 Release - Mindbreeze InSpire
      • Release Notes 22.1 Release - Mindbreeze InSpire
      • Release Notes 22.2 Release - Mindbreeze InSpire
      • Release Notes 22.3 Release - Mindbreeze InSpire
      • Release Notes 23.1 Release - Mindbreeze InSpire
      • Release Notes 23.2 Release - Mindbreeze InSpire
      • Release Notes 23.3 Release - Mindbreeze InSpire
      • Release Notes 23.4 Release - Mindbreeze InSpire
      • Release Notes 23.5 Release - Mindbreeze InSpire
      • Release Notes 23.6 Release - Mindbreeze InSpire
      • Release Notes 23.7 Release - Mindbreeze InSpire
      • Release Notes 24.1 Release - Mindbreeze InSpire
      • Release Notes 24.2 Release - Mindbreeze InSpire
      • Release Notes 24.3 Release - Mindbreeze InSpire
      • Release Notes 24.4 Release - Mindbreeze InSpire
      • Release Notes 24.5 Release - Mindbreeze InSpire
      • Release Notes 24.6 Release - Mindbreeze InSpire
      • Release Notes 24.7 Release - Mindbreeze InSpire
      • Release Notes 24.8 Release - Mindbreeze InSpire
      • Release Notes 25.1 Release - Mindbreeze InSpire
      • Release Notes 25.2 Release - Mindbreeze InSpire
    • Security
      • Known Vulnerablities
    • Product Information
      • Product Information - Mindbreeze InSpire - Standby
      • Product Information - Mindbreeze InSpire
    Home

    Path

    Sure, you can handle it. But should you?
    Let our experts manage the tech maintenance while you focus on your business.
    See Consulting Packages

    Configuration
    GSA Late Binding Authentication

    IntroductionPermanent link for this heading

    The GSA Late Binding Authentication service can be used in web indexing use cases where authorization can’t rely on access control lists or a search-time access check of the results is required. Additional requirement is that the access checking requests (head or get requests) should be authenticated with session cookies.

    It is not recommended to use this method if authorization based on ACLs exclusively is sufficient. If  possible, one should use it in conjunction with ACL check (only if the ACLs allow access) as an additional authorization method. The reason is, that the search-time access check can significantly impact search performance.

    ConfigurationPermanent link for this heading

    Late Binding Authorization ServicePermanent link for this heading

    The Late Binding Authorization Service can be configured as a Mindbreeze InSpire Launched Service using the Mindbreeze InSpire Management Center. Navigate to the “Indices” Tab and add a launched service of type “GSALateBindingAuthorization”.

    You can configure the following settings for the server:

    Bind port

    Port that is used for receiving authorization requests.

    Cookie header property

    The authorization service receives a user identity data structure within the authorization request. This property is the name of the identity property that contains the original session cookie header of the search request.

    The access check rules for given URL patterns can be defined in form of “Authorizers”.

    IMPORTANT: the authorization result for a given documents is delivered by the first authorizer with a matching URL pattern.

    An authorizer can have the following attributes:

    URL Pattern

    Regular expression matching the URL (key) of the authorizable document. If matches, this authorizer will be used for access check. The pattern has to fully match the URL input.

    Denied Status Code Pattern

    If set, a HTTP request is performed on the URL of the authorizable document with the search user’s original session cookies.

    The configured regular expression (f. ex. “401|403” or “301|40.*”) is checked against the status code of the HTTP response. If matches, the user is denied access on the document. The pattern has to fully match the status code.

    Denied Content Pattern

    If set, a HTTP Get request is performed on the URL of the authorizable document with the search user’s original session cookies.

    Note: if only “Denied Status Code Pattern” is set in an authorizer without a “Denied Content Pattern”, only HTTP HEAD requests are used for authorization check.

    The configured regular expression is checked against the content of the HTTP response. If the regular expression matches a substring of the content, the user is denied access on the document.

    Check Content Pattern for Matching Media Type

    This regular expression pattern is set per default to “text/.*”. The role of this setting is to restrict matching the configured “Denied Content Pattern” to responses with certain Content-Type header. In this way one can prevent text matching on content for responses in binary or non-textual formats. If not set, the “Denied Content Pattern” is applied on all responses.

    Data Source ConfigurationPermanent link for this heading

    For using the configured GSA Late Binding Authorization Service for access check in a given Data Source (for example Web) the service should be selected as “Authorization Service” in the configuration of the given data source.

    If ACLs are used on the index a “Caching Principal Resolution Service” has to be selected as well:

    Index ConfigurationPermanent link for this heading

    To improve the performance, it is advised to set the following index configuration options:

    • Approved Hits Reauthorize: Token Cache
    • Initial Precheck Bulk Size: 1
    • Maximum Precheck Bulk Size: 1

    Cookie Header Preserver Session Authentication PluginPermanent link for this heading

    The role of this plugin is to allow sending the original user session cookies with the authorization requests to the GSA Late Binding Authorization service.

    The plugin should be configured as a SessionAuthenticationService on the Client Service that will be used for searching.

    For the configuration navigate to the “Client Services” Tab of the Mindbreeze InSpire Management Center and in the configuration of the selected Client Service, add a Session Authentication Plugin of type “CookieHeaderPreserverSessionAuthenticationService”.

    The following settings can be configured for the plugin:

    Cookie header property

    The name of the property in the generated identity data. Default is “cookieheader”. This must be configured on the same value as the “Cookie header property” of the GSA Late Binding Authorization service.

    Username Source

    Can be set to “Username”, “Header” or “Anonymous”.

    Username: a user identity is created having the name set to the value configured in the “Username” setting.

    Header: the name of the created user identity is set to the value of the “X-Auth-User” HTTP request header.

    Username

    If “Username Source” is configured as “Username”, the name of the generated identity is set to this value.

    Has Group Principals

    If active, the comma separated list of groups set in the “X-Auth-Groups” HTTP request header is parsed and the group names are added as additional principal names to the generated identity.

    Download PDF

    • Configuration - GSA Late Binding Authentication

    Content

    • Introduction
    • Configuration

    Download PDF

    • Configuration - GSA Late Binding Authentication