IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  IAG rule based on body content

    Posted 02/21/22 10:59 PM
    Edited by Timothy Dilbert 02/21/22 10:59 PM
    We're using the IBM Application Gateway to protect some internal web services. We would like to create an Authorization Rule based on the content of the request.

    Meaning, if the HTTP request has <Category>Super Secret</Category> in the body, and the `access_token` does not have `Scope` AllowSuperSecret we want to deny the request.

    I know it is possible to create authorisation rules based on scope, groupIds, or custom attributes. But, it is possible to create a rule like what's above? Meaning, based on the content of the HTTP request body?

    Reference: Rules
    IBM Application Gateway remove preview
    Rules
    The IBM Application Gateway (IAG) provides a containerized secure Web Reverse proxy which is designed to sit in front of your application, seamlessly adding authentication and authorization protection to your application.
    View this on IBM Application Gateway >



    ------------------------------
    Timothy
    ------------------------------


  • 2.  RE: IAG rule based on body content
    Best Answer

    Posted 02/21/22 11:44 PM

    Timothy,

     

    Unfortunately, it is not possible to create an authorization rule which uses the body of the request.

     

    Thanks.

     

    Scott A. Exton
    Senior Software Engineer
    Chief Programmer - IBM Security Verify Access

    IBM Master Inventor