Docs

Parameters

See plugin common configurations (opens in Apache APISIX docs) for configuration options available to all plugins.

  • external_user_label_field

    string

    default: groups


    Field containing the external user's labels. Use a field name for a top-level value or a JSONPath expression for nested values.

    The selected value can be a list, a serialized JSON array, a delimited string, or a scalar string. Configure external_user_label_field_parser when the value requires explicit parsing.

  • external_user_label_field_key

    string


    Key used to match values selected by a JSONPath expression against allow_labels or deny_labels. For example, set this field to team when external_user_label_field is $.orgs..team and the access control list uses the team key.

  • external_user_label_field_parser

    string

    vaild vaule:

    segmented_text, json, or table


    Parser for the selected external-user label value.

    Use json for a serialized JSON array, segmented_text for a delimited string, or table for a list. When omitted, the plugin handles lists, JSON-array strings, comma-separated strings, and scalar strings automatically.

  • external_user_label_field_separator

    string


    Regular expression used to split labels when external_user_label_field_parser is segmented_text.

  • allow_labels

    object


    Labels that allow a request. At least one matching value is required when this field is configured and no value matches deny_labels.

    Configure at least one of allow_labels and deny_labels.

  • deny_labels

    object


    Labels that deny a request. Any matching value rejects the request before allow_labels is evaluated.

    Configure at least one of allow_labels and deny_labels.

  • rejected_code

    integer

    default: 403

    vaild vaule:

    greater than or equal to 200


    HTTP status code to return when the request is rejected.

  • rejected_msg

    string

    default: The consumer is forbidden.


    Error message to return when the request is rejected. When omitted, the plugin returns The consumer is forbidden.