-
Notifications
You must be signed in to change notification settings - Fork 379
Reverse proxy header authentication
CloudBeaver offers a feature for authorization and authentication using reverse proxy headers. This method allows to authenticate users via specific HTTP header fields.
-
As an administrator, navigate to the Settings -> Server configuration.
-
Locate the Reverse proxy option and activate this setting to allow reverse proxy authentication.
-
Save changes.
To configure reverse proxy authentication, follow these steps:
- Open your
.cloudbeaver.runtime.conf
configuration file. - Locate the
app
section within the file. - Add a new entry to the
authConfigurations
array with the following structure:
"app": {
...
"authConfigurations": [
{
"id": "your_proxy_id",
"provider": "reverseProxy",
"displayName": "your_proxy_username",
"disabled": true,
"iconURL": "",
"description": "",
"parameters": {
"logout-url": "https://link_if_needed",
"user-header": "",
"team-header": "",
"team-delimiter": "",
"first-name-header": "",
"last-name-header": ""
}
}
]
}
Important: Ensure you include the mandatory fields id, provider, and displayName. The
provider
name must be set toreverseProxy
.
To configure reverse proxy authentication in the Enterprise and Team Editions of CloudBeaver using the graphical user interface (GUI), follow these steps:
- Log in as an administrator.
- Navigate to Settings -> Server configuration in the CloudBeaver interface.
- Click on the + Add button to create a new authentication provider.
- In the Provider dropdown menu, select Reverse Proxy.
- Enter a unique identifier in the ID field and a name for the configuration in the Configuration name field.
- Click on Save to apply the changes.
Configure the standard HTTP header fields as follows:
-
Header User Name: Set as
X-User
. -
Header Team Name: Use
X-Role
. -
Header User First Name: Designate as
X-First-name
. -
Header User Last Name: Set as
X-Last-name
.
Consider a user named newuser
, belonging to both user
and admin
teams. To access an application with reverse proxy
header authentication enabled, the following HTTP headers should be set in the request to the CloudBeaver application:
X-User: newuser
X-Role: user|admin
X-First-name: [Your First Name]
X-Last-name: [Your Last Name]
Tip: CloudBeaver categorizes users into two default teams:
user
andadmin
. Default delimiter used to separate teams in the header is|
.
- Application overview
- Demo Server
- Administration
- Supported databases
- Accessibility
- Keyboard shortcuts
- Features
- Server configuration
- CloudBeaver and Nginx
- Domain manager
- Configuring HTTPS for Jetty server
- Product configuration parameters
- Command line parameters
- Local Preferences
- Team Edition Overview
- Getting started with Team Edition
- Team Edition Server Configuration
- Projects in Team Edition
- Teams in Team Edition
- Team Edition Deployment
- Roles in Team Edition
- Git integration in Team Edition
- Datasets in Team Edition
-
CloudBeaver Community
-
CloudBeaver AWS
-
CloudBeaver Enterprise
-
Deployment options
-
Development