project_state_owner_headers

Projects a normalized [StateOwner] into destination-specific HTTP headers.
On this page

Projects a normalized [StateOwner] into destination-specific HTTP headers.

Configuration Notes

Place this filter only in a chain whose destination is authorized to receive identity. The ingress state_owner filter removes its assertion headers; this filter recreates configured headers from the validated, immutable context, so client-supplied values cannot shadow the trusted projection. In an IRR step it also strips the raw ingress names carried as bounded transport metadata before the child request is dispatched.

Configuration

FieldTypeRequiredDescription
tenant_headerstringyesHeader receiving the stable tenant namespace.
subject_headerstringyesHeader receiving the stable subject identifier.
issuer_headerstringnoOptional header receiving the identity-provider or trust-domain identifier.

Examples

Example 1

filter: project_state_owner_headers
tenant_header: x-tenant-id
subject_header: x-user-id

Example 2

filter: project_state_owner_headers
tenant_header: x-service-tenant
subject_header: x-service-user
issuer_header: x-service-issuer