WSO2 IS 6.0.0无法获取含internal_login scope的令牌问题排查
根据WSO2 Identity Server文档,调用/t/{tenant-domain}/api/users/v1/me/sessions API需携带包含internal_login scope的令牌,但当前无法获取该scope。
使用隐式授权模式调用以下URL获取令牌:
https://localhost/oauth2/authorize?response_type=id_token+token&nonce=abc&scope=openid%20profile%20internal_login&redirect_uri=https://xxxx.com/&client_id=xxxxx
返回的令牌仅包含"scope": "openid profile",导致API调用返回403错误。
调试日志补充:开启身份类调试日志后,发现关键片段:
TID: [-1234] [oauth2] [2024-07-10 21:28:55,895] [8a103ad6-8239-4ea3-b57b-c73856da4b49] DEBUG {org.wso2.carbon.identity.oauth.callback.OAuthCallbackHandlerRegistry} - OAuthCallbackHandler was found for the callback. Class Name : org.wso2.carbon.identity.oauth.callback.DefaultCallbackHandler Resource Owner : u@u.uu@carbon.super Client Id : xxxx Scope : internal_login openid profile ...then TID: [-1234] [oauth2] [2024-07-10 21:28:55,896] [8a103ad6-8239-4ea3-b57b-c73856da4b49] DEBUG {org.wso2.carbon.identity.oauth2.authz.AuthorizationHandlerManager} - Skipping the internal scope validation as the application is not configured as Management App ... and later TID: [-1234] [oauth2] [2024-07-10 21:28:55,896] [8a103ad6-8239-4ea3-b57b-c73856da4b49] DEBUG {org.wso2.carbon.identity.oauth.callback.OAuthCallbackHandlerRegistry} - OAuthCallbackHandler was found for the callback. Class Name : org.wso2.carbon.identity.oauth.callback.DefaultCallbackHandler Resource Owner : u@u.uu@carbon.super Client Id : xxxx Scope : openid profile
当前使用WSO2 Identity Server 6.0.0版本,另一台同版本但从5.10.0迁移而来的实例可正常获取该scope令牌,未发现配置差异。需明确哪些配置或权限负责颁发internal_login scope。
从日志中Skipping the internal scope validation as the application is not configured as Management App这条关键信息可直接定位问题:internal_login是WSO2 IS的内部scope,仅允许标记为**管理应用(Management App)**的OAuth客户端请求。
以下是具体配置步骤和检查点:
将OAuth客户端标记为Management App
- 登录WSO2 IS管理控制台,进入
Main > Identity > Applications > OAuth/OpenID Connect Configurations - 找到目标客户端应用,点击Edit
- 切换到Advanced Configuration标签页,勾选Management Application选项
- 保存配置后重新发起令牌请求
- 登录WSO2 IS管理控制台,进入
验证客户端授权scope
在客户端编辑页面的Scopes标签下,确认internal_login已添加到允许的scope列表中。注意:内部scope默认不会显示在可选列表,需手动输入并添加。排查迁移实例的配置差异
从5.10.0迁移的实例可能在迁移过程中自动保留了客户端的Management App标记。可对比两个实例数据库中SP_METADATA表的IS_MANAGEMENT_APP字段,迁移实例该字段值为TRUE,而新部署实例可能为FALSE。可选:关闭内部scope校验(不推荐生产环境)
若无需严格限制,可修改deployment.toml配置关闭校验:[oauth.internal_scope_validation] enable = false
内容的提问来源于stack exchange,提问作者Alexey Dolgopolov

