backend-defaults: Added deprecation warning for the dangerouslyDisableDefaultAuthPolicy config option

Co-authored-by: Camila Belo <camilaibs@gmail.com>
Signed-off-by: Johan Haals <johan.haals@gmail.com>
This commit is contained in:
Johan Haals
2024-08-14 13:41:17 +02:00
parent f24ba909bf
commit 87cd3d0b9e
3 changed files with 8 additions and 0 deletions
+2
View File
@@ -24,6 +24,8 @@ backend:
dangerouslyDisableDefaultAuthPolicy: true
```
Please note that this functionality will be removed in a future release, and you should migrate to using the new auth services as soon as possible or you would have to support your own service for issuing tokens.
In short, this will allow requests through to plugins in your backend, even if they do not include any credentials. The requests will still be treated as unauthenticated however, which not all plugin endpoints may accept. For more information on the impact of this configuration, see the [auth service documentation](../backend-system/core-services/auth.md).
### Migrating the backend
@@ -22,6 +22,7 @@ import {
BackstagePrincipalTypes,
BackstageServicePrincipal,
BackstageUserPrincipal,
LoggerService,
} from '@backstage/backend-plugin-api';
import { AuthenticationError, ForwardedError } from '@backstage/errors';
import { JsonObject } from '@backstage/types';
@@ -47,6 +48,7 @@ export class DefaultAuthService implements AuthService {
private readonly pluginId: string,
private readonly disableDefaultAuthPolicy: boolean,
private readonly pluginKeySource: PluginKeySource,
private readonly logger: LoggerService,
) {}
async authenticate(
@@ -166,6 +168,9 @@ export class DefaultAuthService implements AuthService {
});
}
// If the target plugin does not support the new auth service, fall back to using old token format
this.logger.warn(
'tokenManager is DEPRECATED, please migrate to the new auth service, see https://backstage.io/docs/tutorials/auth-service-migration for more information',
);
return this.tokenManager.getToken().catch(error => {
throw new ForwardedError(
`Unable to generate legacy token for communication with the '${targetPluginId}' plugin. ` +
@@ -88,6 +88,7 @@ export const authServiceFactory = createServiceFactory({
plugin.getId(),
disableDefaultAuthPolicy,
keySource,
logger,
);
},
});