You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决WSO2 IS作为Key Manager时控制台持续缓冲问题

问题:WSO2 Identity Server 6.1.0作为Key Manager时门户持续缓冲的修复方案?

我已分布式部署WSO2 API Manager,并使用WSO2 Identity Server 6.1.0作为Key Manager。此前已通过官方文档步骤解决了/console和/myaccount的"Registered callback does not match"问题,但尝试登录https://km.wso2.com:9443/console和https://km.wso2.com:9443/myaccount时,WSO2 Identity Server门户持续缓冲,长时间后日志中出现如下错误,缓冲状态仍未解除:

{org.wso2.carbon.identity.auth.valve.AuthenticationValve} - Error while normalizing the request URI to process the authentication: java.net.URISyntaxException: Illegal character in path at index 8: /console wso2 identity burring continously
        at java.base/java.net.URI$Parser.fail(URI.java:2974)
        at java.base/java.net.URI$Parser.checkChars(URI.java:3145)
        at java.base/java.net.URI$Parser.parseHierarchical(URI.java:3227)
        at java.base/java.net.URI$Parser.parse(URI.java:3186)
        at java.base/java.net.URI.<init>(URI.java:623)

我的deployment.toml配置如下:

[database.shared_db]
type = "mysql"
url = "jdbc:mysql://cp.wso2.com:3306/shared_db?useSSL=false&allowPublicKeyRetrieval=true"
username = "sharedadmin"
password = "sharedadmin"
driver = "com.mysql.cj.jdbc.Driver"

#Traffic Manager Endpoints Configuration
#Use Same Configuration

#Use default-encryption
[keystore.primary]
file_name = "wso2carbon.jks"
password = "wso2carbon"

[truststore]
file_name="client-truststore.jks"
password="wso2carbon"
type="JKS"

#Event listener endpoint to publish controller events to the Control Plane
[event_listener.properties]
notification_endpoint = "https:/cp.wso2.com:9443/internal/data/v1/notify"
username = "${admin.username}"
password = "${admin.password}"
'header.X-WSO2-KEY-MANAGER' = "WSO2-IS"

#Disable group and role separation
[authorization_manager.properties]
GroupAndRoleSeparationEnabled = false
修复方案及修改建议

1. 修正事件监听端点URL错误

配置中notification_endpoint的URL少了一个斜杠,正确的地址应为:

notification_endpoint = "https://cp.wso2.com:9443/internal/data/v1/notify"

这个错误会导致KM与APIM控制平面的事件同步异常,进而引发门户加载时的请求处理失败。

2. 清理OAuth2应用回调URL配置

  • 登录APIM管理控制台,找到对应IS作为KM的WSO2 Console和WSO2 My Account OAuth2应用
  • 检查回调URL,确保无多余空格或非法字符,严格匹配:
    • https://km.wso2.com:9443/console/login
    • https://km.wso2.com:9443/myaccount/login
  • 若之前手动修改过回调URL,重新同步KM与APIM的客户端配置,确保两边信息一致

3. 配置URI编码规则

在IS的deployment.toml中添加HTTPS连接器的编码配置,避免URI非法字符解析错误:

[transport.https.properties]
URIEncoding = "UTF-8"

4. 清除浏览器缓存与Cookie

门户持续缓冲可能是浏览器缓存了错误的会话数据,彻底清除km.wso2.com域名的Cookie和缓存后重新登录。

5. 重启服务节点

修改配置后,重启Identity Server和APIM控制平面节点,确保所有配置生效。

内容的提问来源于stack exchange,提问作者Chathura Dilshan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 13:44:52