PageSourceSearch

https://www.rabbitmq.com/assets/js/2bf5baa4.7c1da2c6.js

js rabbitmq.com collected 2026-09-24 06:07:02 UTC 4,667 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkrabbitmq_website=self.webpackChunkrabbitmq_website||[]).push([["20125"],{86926(e,t,i){i.r(t),i.d(t,{metadata:()=>s,default:()=>h,frontMatter:()=>a,contentTitle:()=>o,toc:()=>l,assets:()=>d});var s=JSON.parse('{"id":"validated-user-id","title":"Validated User-ID","description":"\x3c!--","source":"@site/versioned_docs/version-4.2/validated-user-id.md","sourceDirName":".","slug":"/validated-user-id","permalink":"/docs/4.2/validated-user-id","draft":false,"unlisted":false,"editUrl":"https://github.com/rabbitmq/rabbitmq-website/tree/main/versioned_docs/version-4.2/validated-user-id.md","tags":[],"version":"4.2","frontMatter":{"title":"Validated User-ID"},"sidebar":"docsSidebar","previous":{"title":"Sender-selected Distribution","permalink":"/docs/4.2/sender-selected"},"next":{"title":"Exchanges","permalink":"/docs/4.2/exchanges"}}'),n=i(74848),r=i(28453);let a={title:"Validated User-ID"},o="Validated User-ID",d={},l=[{value:"Example (in Java)",id:"example-in-java",level:2},{value:"Additional Layer of Authentication",id:"additional-layer-of-authentication",level:2},{value:"Special Cases: the Impersonator Tag",id:"special-cases-the-impersonator-tag",level:2},{value:"Federation Interactions",id:"federation-interactions",level:2}];function c(e){let t={a:"a",code:"code",h1:"h1",h2:"h2",header:"header",p:"p",pre:"pre",...(0,r.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsx)(t.header,{children:(0,n.jsx)(t.h1,{id:"validated-user-id",children:"Validated User-ID"})}),"\n",(0,n.jsx)(t.p,{children:"In some scenarios it is useful for consumers to be able\nto know the identity of the user who published a\nmessage."}),"\n",(0,n.jsxs)(t.p,{children:["To make this possible, RabbitMQ will validate the ",(0,n.jsx)("code",{children:"user-id"})," message property if it is set.\nIn other words, if this property is set by a publisher, its value must be equal\nto the name of the connection's user."]}),"\n",(0,n.jsxs)(t.p,{children:["If the ",(0,n.jsx)("code",{children:"user-id"})," property is not set, the\npublisher's identity remains private and no validation will be performed."]}),"\n",(0,n.jsx)(t.h2,{id:"example-in-java",children:"Example (in Java)"}),"\n",(0,n.jsx)(t.pre,{children:(0,n.jsx)(t.code,{className:"language-java",children:'AMQP.BasicProperties properties = new AMQP.BasicProperties();\nproperties.setUserId("guest");\nchannel.basicPublish("amq.fanout", "", properties, "test".getBytes());\n'})}),"\n",(0,n.jsx)(t.p,{children:'This message will only be published successfully if the user\nis "guest".'}),"\n",(0,n.jsx)(t.h2,{id:"additional-layer-of-authentication",children:"Additional Layer of Authentication"}),"\n",(0,n.jsxs)(t.p,{children:["If security is a serious concern, you should probably\ncombine the use of this feature\nwith ",(0,n.jsx)(t.a,{href:"./ssl",children:"TLS-enabled"})," connections, possibly with peer certificate chain verification\nof clients performed by the server."]}),"\n",(0,n.jsx)(t.h2,{id:"special-cases-the-impersonator-tag",children:"Special Cases: the Impersonator Tag"}),"\n",(0,n.jsxs)(t.p,{children:["Occasionally it may be useful to allow an application to forge a\n",(0,n.jsx)(t.code,{children:"user-id"}),". In order to permit this, the publishing user can have\nits ",(0,n.jsx)("code",{children:"impersonator"})," tag set. By default, no users have\nthis tag set. In particular, the ",(0,n.jsx)("code",{children:"administrator"})," tag\ndoes not allow this."]}),"\n",(0,n.jsx)(t.h2,{id:"federation-interactions",children:"Federation Interactions"}),"\n",(0,n.jsxs)(t.p,{children:["The ",(0,n.jsx)(t.a,{href:"./federation",children:"federation plugin"})," can deliver\nmessages from an upstream on which the ",(0,n.jsx)("code",{children:"user-id"}),"\nproperty is set. By default it will clear this property (since\nit has no way to know whether the upstream broker is\ntrustworthy). If the ",(0,n.jsx)("code",{children:"trust-user-id"})," property on an\nupstream is set, then it will pass the ",(0,n.jsx)("code",{children:"user-id"}),"\nproperty through from the upstream broker, assuming it to have\nbeen validated there."]})]})}function h(e={}){let{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(c,{...e})}):c(e)}},28453(e,t,i){i.d(t,{R:()=>a,x:()=>o});var s=i(96540);let n={},r=s.createContext(n);function a(e){let t=s.useContext(r);return s.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:a(e.components),s.createElement(r.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.