如何解决WSO2 IS作为Key Manager时控制台持续缓冲问题
问题:WSO2 Identity Server 6.1.0作为Key Manager时门户持续缓冲的修复方案?
我已分布式部署WSO2 API Manager,并使用WSO2 Identity Server 6.1.0作为Key Manager。此前已通过官方文档步骤解决了/console和/myaccount的"Registered callback does not match"问题,但尝试登录https://km.wso2.com:9443/console和https://km.wso2.com:9443/myaccount时,WSO2 Identity Server门户持续缓冲,长时间后日志中出现如下错误,缓冲状态仍未解除:
{org.wso2.carbon.identity.auth.valve.AuthenticationValve} - Error while normalizing the request URI to process the authentication: java.net.URISyntaxException: Illegal character in path at index 8: /console wso2 identity burring continously at java.base/java.net.URI$Parser.fail(URI.java:2974) at java.base/java.net.URI$Parser.checkChars(URI.java:3145) at java.base/java.net.URI$Parser.parseHierarchical(URI.java:3227) at java.base/java.net.URI$Parser.parse(URI.java:3186) at java.base/java.net.URI.<init>(URI.java:623)
我的deployment.toml配置如下:
[database.shared_db] type = "mysql" url = "jdbc:mysql://cp.wso2.com:3306/shared_db?useSSL=false&allowPublicKeyRetrieval=true" username = "sharedadmin" password = "sharedadmin" driver = "com.mysql.cj.jdbc.Driver" #Traffic Manager Endpoints Configuration #Use Same Configuration #Use default-encryption [keystore.primary] file_name = "wso2carbon.jks" password = "wso2carbon" [truststore] file_name="client-truststore.jks" password="wso2carbon" type="JKS" #Event listener endpoint to publish controller events to the Control Plane [event_listener.properties] notification_endpoint = "https:/cp.wso2.com:9443/internal/data/v1/notify" username = "${admin.username}" password = "${admin.password}" 'header.X-WSO2-KEY-MANAGER' = "WSO2-IS" #Disable group and role separation [authorization_manager.properties] GroupAndRoleSeparationEnabled = false
修复方案及修改建议
1. 修正事件监听端点URL错误
配置中notification_endpoint的URL少了一个斜杠,正确的地址应为:
notification_endpoint = "https://cp.wso2.com:9443/internal/data/v1/notify"
这个错误会导致KM与APIM控制平面的事件同步异常,进而引发门户加载时的请求处理失败。
2. 清理OAuth2应用回调URL配置
- 登录APIM管理控制台,找到对应IS作为KM的
WSO2 Console和WSO2 My AccountOAuth2应用 - 检查回调URL,确保无多余空格或非法字符,严格匹配:
https://km.wso2.com:9443/console/loginhttps://km.wso2.com:9443/myaccount/login
- 若之前手动修改过回调URL,重新同步KM与APIM的客户端配置,确保两边信息一致
3. 配置URI编码规则
在IS的deployment.toml中添加HTTPS连接器的编码配置,避免URI非法字符解析错误:
[transport.https.properties] URIEncoding = "UTF-8"
4. 清除浏览器缓存与Cookie
门户持续缓冲可能是浏览器缓存了错误的会话数据,彻底清除km.wso2.com域名的Cookie和缓存后重新登录。
5. 重启服务节点
修改配置后,重启Identity Server和APIM控制平面节点,确保所有配置生效。
内容的提问来源于stack exchange,提问作者Chathura Dilshan
相关产品推荐
相关产品推荐

