APIM 4.1应用自定义属性无法获取问题求助
问题描述
在APIM-4.1一体化部署环境中,我开发了自定义的CustomPasswordGrantHandler.java类(继承自PasswordGrantHandler),需要从应用中获取名为owner_user的自定义属性。
已完成的配置和操作:
- 在
deployment.toml中添加如下配置:
[[apim.devportal.application_attributes]] required = true hidden = false name = "owner_user" description = "Descrizione dell'attributo personalizzato 'owner_user'" [oauth.grant_type.password] grant_handler = "com.yourcompany.auth.CustomPasswordGrantHandler"
- 已在DevPortal中为目标应用设置了
owner_user自定义属性及对应值。
当前问题:自定义类已被正确调用,但获取到的应用属性是空Map{},相关代码片段如下:
public class CustomPasswordGrantHandler extends PasswordGrantHandler { @Override public boolean validateGrant(OAuthTokenReqMessageContext tokReqMsgCtx) throws IdentityOAuth2Exception { OAuth2AccessTokenReqDTO tokenReqDTO = tokReqMsgCtx.getOauth2AccessTokenReqDTO(); String clientId = tokenReqDTO.getClientId(); String username = tokenReqDTO.getResourceOwnerUsername(); log.info("clientId = " + clientId + " username = " + username); ApiMgtDAO apiMgtDAO = ApiMgtDAO.getInstance(); Application app = apiMgtDAO.getApplicationByClientId(clientId); log.info("app.getName(): " + app.getName()); Map<String, String> attributes = app.getApplicationAttributes(); log.info("attributes: " + attributes.toString()); String ownerUser = attributes.get("owner_user"); if (ownerUser == null || ownerUser.isEmpty()) { log.warn("Attributo 'owner_user' mancante per clientId=" + clientId); return false; }
日志输出:
INFO - clientId = O5duiwLVNfubc9mcYQ9nX040OJoa username = admin INFO - app.getName(): DefaultApplication INFO - attributes: {} WARN - Attributo 'owner_user' mancante per clientId=O5duiwLVNfubc9mcYQ9nX040OJoa
疑问:为何获取到的attributes是空Map?请帮忙分析并解决。
问题分析与解决
原因分析
ApiMgtDAO.getApplicationByClientId()方法默认仅返回应用的基础信息(如名称、ID等),不会自动加载存储在单独表中的自定义属性,因此调用app.getApplicationAttributes()会得到空Map。
解决方法
有两种可行方案可以获取到自定义属性:
方案一:直接通过应用ID获取属性
调用ApiMgtDAO.getApplicationAttributes()方法,传入应用ID直接查询属性:
public class CustomPasswordGrantHandler extends PasswordGrantHandler { @Override public boolean validateGrant(OAuthTokenReqMessageContext tokReqMsgCtx) throws IdentityOAuth2Exception { OAuth2AccessTokenReqDTO tokenReqDTO = tokReqMsgCtx.getOauth2AccessTokenReqDTO(); String clientId = tokenReqDTO.getClientId(); String username = tokenReqDTO.getResourceOwnerUsername(); log.info("clientId = " + clientId + " username = " + username); ApiMgtDAO apiMgtDAO = ApiMgtDAO.getInstance(); Application app = apiMgtDAO.getApplicationByClientId(clientId); log.info("app.getName(): " + app.getName()); // 直接通过应用ID获取自定义属性 Map<String, String> attributes = apiMgtDAO.getApplicationAttributes(app.getId()); log.info("attributes: " + attributes.toString()); String ownerUser = attributes.get("owner_user"); if (ownerUser == null || ownerUser.isEmpty()) { log.warn("Attributo 'owner_user' mancante per clientId=" + clientId); return false; } // 后续业务逻辑...
方案二:加载属性到Application对象
调用ApiMgtDAO.loadApplicationAttributes()方法,将属性数据填充到已获取的Application对象中:
public class CustomPasswordGrantHandler extends PasswordGrantHandler { @Override public boolean validateGrant(OAuthTokenReqMessageContext tokReqMsgCtx) throws IdentityOAuth2Exception { OAuth2AccessTokenReqDTO tokenReqDTO = tokReqMsgCtx.getOauth2AccessTokenReqDTO(); String clientId = tokenReqDTO.getClientId(); String username = tokenReqDTO.getResourceOwnerUsername(); log.info("clientId = " + clientId + " username = " + username); ApiMgtDAO apiMgtDAO = ApiMgtDAO.getInstance(); Application app = apiMgtDAO.getApplicationByClientId(clientId); // 显式加载应用属性到对象中 apiMgtDAO.loadApplicationAttributes(app); log.info("app.getName(): " + app.getName()); Map<String, String> attributes = app.getApplicationAttributes(); log.info("attributes: " + attributes.toString()); String ownerUser = attributes.get("owner_user"); if (ownerUser == null || ownerUser.isEmpty()) { log.warn("Attributo 'owner_user' mancante per clientId=" + clientId); return false; } // 后续业务逻辑...
额外验证点
- 登录APIM管理后台,查看目标应用的详情,确认
owner_user属性已正确保存。 - 如果是首次添加
deployment.toml中的属性配置,需重启APIM服务确保配置生效。
内容的提问来源于stack exchange,提问作者Daniele Gambino
相关产品推荐
相关产品推荐

