You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

迁移Jenkins到Jetty12 EE9时HashLoginService配置异常求助

Jetty 12(EE9)中Jenkins HashLoginService的正确配置方案

Jetty 12升级后,HashLoginService的API和WebAppContext的结构发生了两处关键变化,导致旧配置失效:

  1. HashLoginService.setConfig()不再接受字符串路径,必须传入org.eclipse.jetty.util.resource.Resource类型对象
  2. org.eclipse.jetty.ee9.webapp.WebAppContext不再暴露securityHandler字段,需通过方法调用获取

以下是经过验证的正确配置步骤:

1. 在Jetty Server级别配置HashLoginService

修改jetty.base/etc/jetty.xml,添加HashLoginService并通过ResourceFactory正确构造Resource:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE Configure PUBLIC "-//Jetty//Configure//EN" "https://www.eclipse.org/jetty/configure_12_0.dtd">

<Configure id="Server" class="org.eclipse.jetty.server.Server">
  <!-- 定义Jenkins专属的HashLoginService -->
  <New id="JenkinsRealm" class="org.eclipse.jetty.security.HashLoginService">
    <Set name="name">Jenkins Realm</Set>
    <Set name="config">
      <!-- 使用Jetty官方推荐的ResourceFactory创建资源对象 -->
      <Call class="org.eclipse.jetty.util.resource.ResourceFactory" name="of">
        <Arg><Ref refid="Server"/></Arg>
        <Call name="newResource">
          <Arg><Property name="jetty.base" default="."/>/resources/realm.properties</Arg>
        </Call>
      </Call>
    </Set>
  </New>
  <!-- 将LoginService添加为Server的Bean,确保全局可见 -->
  <Call name="addBean">
    <Arg><Ref refid="JenkinsRealm"/></Arg>
  </Call>
</Configure>

2. 关联LoginService到Jenkins的WebAppContext

修改jetty.base/webapps/jenkins.xml,调整WebAppContext配置并关联已定义的LoginService:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE Configure PUBLIC "-//Jetty//Configure//EN" "https://www.eclipse.org/jetty/configure_12_0.dtd">

<Configure class="org.eclipse.jetty.ee9.webapp.WebAppContext">
  <Set name="contextPath">/jenkins</Set>
  <Set name="war"><Property name="jetty.webapps" default="."/>/jenkins.war</Set>
  
  <!-- 通过方法调用获取SecurityHandler并关联LoginService -->
  <Call name="getSecurityHandler">
    <Set name="loginService">
      <Ref refid="JenkinsRealm"/>
    </Set>
  </Call>
</Configure>

关键配置说明

  • Resource构造方式:必须通过ResourceFactory创建Resource对象,这是Jetty 12统一资源加载的标准方式,避免直接实例化PathResource等具体实现类
  • SecurityHandler获取:使用<Call name="getSecurityHandler">替代旧的<Get name="securityHandler">,因为EE9的WebAppContext中securityHandler是通过方法暴露而非字段
  • 全局Bean注册:HashLoginService需要在Server级别注册为Bean,才能在WebAppContext中通过Ref引用

验证与排查

  • 确认realm.properties文件路径正确,可通过启动日志查看资源加载情况
  • 确保Jetty环境包含jetty-security模块,HashLoginService属于该模块,缺失时需通过jetty-home/bin/jetty.sh module add security添加
  • 启动Jetty时添加--debug参数,可查看配置加载的详细过程,定位资源或配置错误

内容的提问来源于stack exchange,提问作者Andrew Norman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 09:02:06