본문 바로가기
WIKI 기술 지식 베이스

Identity 서비스

원문 보기 위키 갱신

참고

출처: 문서

본문

참고

이 서비스는 더 이상 사용되지 않아요(deprecated). 아마 Auth 서비스 문서를 찾고 계실 거예요. 백엔드 플러그인에서 사용자의 엔티티 ref와 소유권(ownership) 주장을 얻는 방법이 궁금하다면 User Info 서비스 문서를 확인하세요.

백엔드 플러그인을 다룰 때 auth-backend 플러그인과 상호작용해 Backstage 토큰을 인증하고, 그 토큰을 분해해 사용자의 엔티티 ref나 소유권 주장을 꺼내야 하는 경우가 있을 수 있어요.

서비스 사용하기

다음 예시는 example 백엔드 플러그인에서 identity 서비스를 가져와 들어오는 요청에 대한 사용자의 엔티티 ref와 소유권 주장을 검색하는 방법을 보여줘요.

import {
  coreServices,
  createBackendPlugin,
} from '@backstage/backend-plugin-api';
import { Router } from 'express';

createBackendPlugin({
  pluginId: 'example',
  register(env) {
    env.registerInit({
      deps: {
        identity: coreServices.identity,
        http: coreServices.httpRouter,
      },
      async init({ http, identity }) {
        const router = Router();
        router.get('/test-me', (request, response) => {
          // use the identity service to pull out the header from the request and get the user
          const {
            identity: { userEntityRef, ownershipEntityRefs },
          } = await identity.getIdentity({
            request,
          });
          // send the decoded and validated things back to the user
          response.json({
            userEntityRef,
            ownershipEntityRefs,
          });
        });
        http.use(router);
      },
    });
  },
});

서비스 구성하기

identity 핵심 서비스를 설정하기 위해 선택적으로 전달할 수 있는 추가 구성이 있어요.

  • issuer - JWT 토큰 검증을 위한 선택적 발급자(issuer)를 설정해요
  • algorithms - JWT 토큰 검증을 위한 alg 헤더로, 기본값은 ES256이에요. 지원되는 알고리즘에 대한 자세한 내용은 jose 라이브러리 문서에서 확인할 수 있어요

createBackend를 호출할 때 핵심 서비스에 대한 오버라이드를 추가해 이 추가 옵션들을 구성할 수 있어요.

import { identityServiceFactory } from '@backstage/backend-app-api';

const backend = createBackend();
backend.add(
  identityServiceFactory({
    issuer: 'backstage',
    algorithms: ['ES256', 'RS256'],
  }),
);

더 알아보기 (Learn more)