Parameters
See plugin common configurations for configuration options available to all plugins.
external_user_label_field
Field containing the external user's labels. Use a field name for a top-level value or a JSONPath expression for nested values.
The selected value can be a list, a serialized JSON array, a delimited string, or a scalar string. Configure
external_user_label_field_parserwhen the value requires explicit parsing.external_user_label_field_key
Key used to match values selected by a JSONPath expression against
allow_labelsordeny_labels. For example, set this field toteamwhenexternal_user_label_fieldis$.orgs..teamand the access control list uses theteamkey.external_user_label_field_parser
vaild vaule:
segmented_text,json, ortableParser for the selected external-user label value.
Use
jsonfor a serialized JSON array,segmented_textfor a delimited string, ortablefor a list. When omitted, the plugin handles lists, JSON-array strings, comma-separated strings, and scalar strings automatically.external_user_label_field_separator
Regular expression used to split labels when
external_user_label_field_parserissegmented_text.allow_labels
Labels that allow a request. At least one matching value is required when this field is configured and no value matches
deny_labels.Configure at least one of
allow_labelsanddeny_labels.deny_labels
Labels that deny a request. Any matching value rejects the request before
allow_labelsis evaluated.Configure at least one of
allow_labelsanddeny_labels.rejected_code
vaild vaule:
greater than or equal to 200
HTTP status code to return when the request is rejected.
rejected_msg
Error message to return when the request is rejected. When omitted, the plugin returns
The consumer is forbidden.