Trino配置Azure Entra ID OAuth2认证:显示陌生ID而非用户名
Azure Entra ID与Trino认证集成问题:UI显示陌生ID而非Azure ID
我正在配置Azure Entra ID(原Azure AD)与Trino的认证集成,配置流程看似成功,但Trino UI中显示的是一个陌生ID,而非我的Azure ID(附截图:
)。
我确认这个陌生ID并非AAD用户的对象ID,现在需要明确它的来源,才能完成与对应Azure ID的映射——因为我在基于文件的访问控制中需要使用Azure ID。
以下是我的config.properties配置:
coordinator=true node-scheduler.include-coordinator=false http-server.http.port=80 discovery.uri=http://localhost:80 http-server.https.enabled=true http-server.https.port=443 http-server.https.keystore.path=/etc/trino/healthrxcert.pem http-server.authentication.type=oauth2,PASSWORD password-authenticator.config-files=/etc/trino/password-authenticator.properties http-server.authentication.oauth2.issuer=https://login.microsoftonline.com/<tenent ID>/v2.0 http-server.authentication.oauth2.client-id=<ID> http-server.authentication.oauth2.client-secret=<SECRET> http-server.authentication.oauth2.auth-url=https://login.microsoftonline.com/<tenent ID>/oauth2/v2.0/authorize http-server.authentication.oauth2.token-url=https://login.microsoftonline.com/<tenent ID>/oauth2/v2.0/token http-server.authentication.oauth2.jwks-url=https://login.microsoftonline.com/<tenent ID>/discovery/v2.0/keys http-server.authentication.oauth2.userinfo-url=https://graph.microsoft.com/oidc/userinfo http-server.authentication.oauth2.scopes=openid web-ui.authentication.type=oauth2
问题分析与解决方法
1. 陌生ID的来源
Trino OAuth2认证默认从JWT令牌的sub(Subject)字段提取用户标识。而Azure AD v2.0令牌的sub是应用专属的用户唯一标识符,和用户的Azure对象ID(oid字段)不是同一个值,这就是你看到陌生ID的原因。
2. 修改配置,指定使用Azure ID
在config.properties中添加以下配置,强制Trino从JWT的oid字段读取用户ID:
http-server.authentication.oauth2.principal-field=oid
3. 生效与验证
- 修改配置后重启Trino Coordinator服务
- 重新登录Trino UI,此时显示的应该是用户的Azure对象ID(
oid),可直接用于基于文件的访问控制映射
额外排查点
- 确认Azure AD应用注册已勾选
openid范围(当前配置已设置scopes=openid,满足要求),oid字段会包含在ID令牌中 - 可使用离线JWT解析工具解码ID令牌,检查是否存在
oid字段,确保令牌内容符合预期
内容的提问来源于stack exchange,提问作者alakmar Shafin
相关产品推荐
相关产品推荐

