You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

APIM 4.1应用自定义属性无法获取问题求助

问题描述

在APIM-4.1一体化部署环境中,我开发了自定义的CustomPasswordGrantHandler.java类(继承自PasswordGrantHandler),需要从应用中获取名为owner_user的自定义属性。

已完成的配置和操作:

  1. 在deployment.toml中添加如下配置:
[[apim.devportal.application_attributes]]
required = true
hidden = false
name = "owner_user"
description = "Descrizione dell'attributo personalizzato 'owner_user'"

[oauth.grant_type.password]
grant_handler = "com.yourcompany.auth.CustomPasswordGrantHandler"
  1. 已在DevPortal中为目标应用设置了owner_user自定义属性及对应值。

当前问题:自定义类已被正确调用,但获取到的应用属性是空Map{},相关代码片段如下:

public class CustomPasswordGrantHandler extends PasswordGrantHandler {

@Override
public boolean validateGrant(OAuthTokenReqMessageContext tokReqMsgCtx) throws IdentityOAuth2Exception {

OAuth2AccessTokenReqDTO tokenReqDTO = tokReqMsgCtx.getOauth2AccessTokenReqDTO();
String clientId = tokenReqDTO.getClientId();
String username = tokenReqDTO.getResourceOwnerUsername();
log.info("clientId = " + clientId + " username = " + username);

ApiMgtDAO apiMgtDAO = ApiMgtDAO.getInstance();
Application app = apiMgtDAO.getApplicationByClientId(clientId);

log.info("app.getName(): " + app.getName());
Map<String, String> attributes = app.getApplicationAttributes();
log.info("attributes: " + attributes.toString());
String ownerUser = attributes.get("owner_user");

if (ownerUser == null || ownerUser.isEmpty()) {
    log.warn("Attributo 'owner_user' mancante per clientId=" + clientId);
    return false;
}

日志输出:

INFO - clientId = O5duiwLVNfubc9mcYQ9nX040OJoa username = admin
INFO - app.getName(): DefaultApplication
INFO - attributes: {}
WARN - Attributo 'owner_user' mancante per clientId=O5duiwLVNfubc9mcYQ9nX040OJoa

疑问:为何获取到的attributes是空Map?请帮忙分析并解决。

问题分析与解决

原因分析

ApiMgtDAO.getApplicationByClientId()方法默认仅返回应用的基础信息(如名称、ID等),不会自动加载存储在单独表中的自定义属性,因此调用app.getApplicationAttributes()会得到空Map。

解决方法

有两种可行方案可以获取到自定义属性:

方案一:直接通过应用ID获取属性

调用ApiMgtDAO.getApplicationAttributes()方法,传入应用ID直接查询属性:

public class CustomPasswordGrantHandler extends PasswordGrantHandler {

@Override
public boolean validateGrant(OAuthTokenReqMessageContext tokReqMsgCtx) throws IdentityOAuth2Exception {

OAuth2AccessTokenReqDTO tokenReqDTO = tokReqMsgCtx.getOauth2AccessTokenReqDTO();
String clientId = tokenReqDTO.getClientId();
String username = tokenReqDTO.getResourceOwnerUsername();
log.info("clientId = " + clientId + " username = " + username);

ApiMgtDAO apiMgtDAO = ApiMgtDAO.getInstance();
Application app = apiMgtDAO.getApplicationByClientId(clientId);

log.info("app.getName(): " + app.getName());
// 直接通过应用ID获取自定义属性
Map<String, String> attributes = apiMgtDAO.getApplicationAttributes(app.getId());
log.info("attributes: " + attributes.toString());
String ownerUser = attributes.get("owner_user");

if (ownerUser == null || ownerUser.isEmpty()) {
    log.warn("Attributo 'owner_user' mancante per clientId=" + clientId);
    return false;
}
// 后续业务逻辑...

方案二:加载属性到Application对象

调用ApiMgtDAO.loadApplicationAttributes()方法,将属性数据填充到已获取的Application对象中:

public class CustomPasswordGrantHandler extends PasswordGrantHandler {

@Override
public boolean validateGrant(OAuthTokenReqMessageContext tokReqMsgCtx) throws IdentityOAuth2Exception {

OAuth2AccessTokenReqDTO tokenReqDTO = tokReqMsgCtx.getOauth2AccessTokenReqDTO();
String clientId = tokenReqDTO.getClientId();
String username = tokenReqDTO.getResourceOwnerUsername();
log.info("clientId = " + clientId + " username = " + username);

ApiMgtDAO apiMgtDAO = ApiMgtDAO.getInstance();
Application app = apiMgtDAO.getApplicationByClientId(clientId);

// 显式加载应用属性到对象中
apiMgtDAO.loadApplicationAttributes(app);
log.info("app.getName(): " + app.getName());
Map<String, String> attributes = app.getApplicationAttributes();
log.info("attributes: " + attributes.toString());
String ownerUser = attributes.get("owner_user");

if (ownerUser == null || ownerUser.isEmpty()) {
    log.warn("Attributo 'owner_user' mancante per clientId=" + clientId);
    return false;
}
// 后续业务逻辑...

额外验证点

  1. 登录APIM管理后台,查看目标应用的详情,确认owner_user属性已正确保存。
  2. 如果是首次添加deployment.toml中的属性配置,需重启APIM服务确保配置生效。

内容的提问来源于stack exchange,提问作者Daniele Gambino

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 08:28:12