Skip to content

Configure BaSyx Go ReBAC in the access control step - #42

Merged
aaronzi merged 2 commits into
eclipse-basyx:mainfrom
aaronzi:feat/rebac-configuration
Sep 28, 2026
Merged

aaronzi merged 2 commits into
eclipse-basyx:mainfrom
aaronzi:feat/rebac-configuration

Conversation

@aaronzi

@aaronzi aaronzi commented Sep 28, 2026

Copy link
Copy Markdown
Member

Allow generated BaSyx setups to enable the experimental relationship-based access control (ReBAC) of BaSyx Go 1.1.0.

The Access Control step gets a Resource sharing (ReBAC) section, available when access control is enabled. It writes REBAC_ENABLED, REBAC_SUBJECT_CLAIM, REBAC_GROUP_CLAIM and REBAC_ADMINISTRATORS to the AAS Environment. Administrators are validated as issuer|subject or issuer|group:<name>. Disabling ReBAC or access control removes all four variables, because BaSyx Go refuses to start ReBAC without ABAC. The security summary shows the ReBAC state.

ReBAC works with the local Keycloak without further setup:

  • The generated realm adds a groups claim mapper (full path off) and a basyx-admins group that contains basyx-admin.
  • Administrators default to <issuer>|group:basyx-admins, and the generated README explains the group.

The starting access policy now allows GET /description for everyone. The BaSyx Web UI uses the service description to detect ReBAC. The endpoint only exposes the service profiles.

Eventing, the Event Feed and GENERAL_DELEGATEDOPERATIONRESPONSEMAXSIZEBYTES are already configurable, so ReBAC was the only missing BaSyx Go 1.1.0 setting.

Related:

Validation:

  • pnpm format:check
  • pnpm lint:check (0 errors; 11 existing warnings in untouched files)
  • pnpm typecheck
  • pnpm test (23 files, 116 tests)
  • pnpm build
  • git diff --check

Tests cover the ReBAC environment, removing it when ReBAC or access control is turned off, administrator validation, the public description rule, and the realm group and mapper.

🤖 Generated with Claude Code

- Add an optional ReBAC section that writes REBAC_ENABLED,
  REBAC_SUBJECT_CLAIM, REBAC_GROUP_CLAIM and REBAC_ADMINISTRATORS, and
  removes them when ReBAC or access control is disabled.
- Validate administrator entries (issuer|subject or issuer|group:<name>).
- Add a groups claim mapper and a basyx-admins group containing
  basyx-admin to the local Keycloak realm; default the administrators to
  that group.
- Allow /description publicly in the starting policy so clients can
  detect ReBAC.
- Show ReBAC in the security summary and the generated README.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@aaronzi aaronzi left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Found two configuration issues, detailed inline. Validation: all 116 tests and type checking passed; both findings were reproduced with focused checks. Full Docker startup was not tested.

Comment thread utils/securitySetup.ts Outdated
Comment thread pages/get-started/deployment/access-control.vue
- Split administrator entries only at the first "|", like BaSyx Go, so
  subjects such as auth0|123 are accepted.
- Move an untouched generated administrator default to the new issuer
  when the issuer or identity provider changes; keep edited lists.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@aaronzi
aaronzi merged commit 4124229 into eclipse-basyx:main Sep 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant