WSO2 IS 7.0.0中已有角色触发UserNotFound错误的XACML问题排查
WSO2 Identity Server 7.0.0 PDP调用报UserNotFound错误排查
我正在使用WSO2 Identity Server 7.0.0,已将授权策略发布为PDP。调用/api/identity/entitlement/decision/pdp端点时,尽管目标角色Internal/AdminRole确实存在,仍收到UserNotFound错误。
策略说明
策略配置逻辑为:允许角色Internal/AdminRole对资源/admin执行read操作。
Postman请求详情
- 端点:
https://<your-is-host>:9444/api/identity/entitlement/decision/pdp - 授权方式:Basic Auth(账号
admin,密码admin) - 请求头:
Content-Type: application/xml - 请求体(XML格式):
<Request xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" ReturnPolicyIdList="false" CombinedDecision="false"> <Attributes Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource"> <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:resource:resource-id" IncludeInResult="false"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">/admin</AttributeValue> </Attribute> </Attributes> <Attributes Category="urn:oasis:names:tc:xacml:3.0:attribute-category:action"> <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" IncludeInResult="false"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">read</AttributeValue> </Attribute> </Attributes> <Attributes Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"> <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id" IncludeInResult="false"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Internal/AdminRole</AttributeValue> </Attribute> </Attributes> </Request>
错误响应
<Response xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17"> <Result> <Decision>Indeterminate</Decision> <Status> <StatusCode Value="urn:oasis:names:tc:xacml:1.0:status:processing-error"/> <StatusMessage>UserNotFound: User Internal/AdminRole does not exist in: PRIMARY</StatusMessage> </Status> </Result> </Response>
请问是我遗漏了某些配置,还是WSO2 Identity Server 7.0.0存在bug?
内容的提问来源于stack exchange,提问作者Turing
相关产品推荐
相关产品推荐

