You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fiware Keyrock GE跨域问题:登录请求正常,其他请求触发CORS错误

FIWARE Keyrock CORS配置异常问题

问题现象

已在FIWARE中配置Keyrock通用使能器(GE)启用跨域资源共享(CORS),用户登录的POST请求可正常执行且无CORS问题,但发起创建用户等其他请求时出现CORS错误。预期配置允许所有源、方法、请求头,支持凭证与预检请求,但问题仍存在。

Keyrock Docker-Compose配置

version: "3.8"
services:
  orion-v2:
    image: quay.io/fiware/orion:${ORION_VERSION}
    hostname: orion
    container_name: fiware-orion
    depends_on:
      - mongo-db
    networks:
      default:
        ipv4_address: 172.18.1.9
    expose:
      - "${ORION_PORT}"
    ports:
      - "${ORION_PORT}:${ORION_PORT}" # localhost:1026
    command: -logLevel DEBUG -noCache -dbhost mongo-db -corsOrigin __ALL
    healthcheck:
      test: curl --fail -s http://orion:${ORION_PORT}/version || exit 1
      interval: 5s
    deploy:
      restart_policy:
        condition: on-failure
        delay: 60s
        max_attempts: 10

  iot-agent:
    image: fiware/iotagent-json
    hostname: iot-agent
    container_name: fiware-iot-agent
    depends_on:
      - mongo-db
      - orion-v2
    networks:
      default:
        ipv4_address: 172.18.1.100
    ports:
      - "${IOTA_NORTH_PORT}:${IOTA_NORTH_PORT}" # localhost:4041
      - "${IOTA_SOUTH_PORT}:${IOTA_SOUTH_PORT}" # localhost:7896
    environment:
      - IOTA_CB_HOST=orion-proxy
      - IOTA_CB_PORT=${ORION_PROXY_PORT} # port the context broker listens on to update context
      - IOTA_NORTH_PORT=${IOTA_NORTH_PORT}
      - IOTA_REGISTRY_TYPE=mongodb #Whether to hold IoT device info in memory or in a database
      - IOTA_LOG_LEVEL=DEBUG # The log level of the IoT Agent
      - IOTA_TIMESTAMP=true # Supply timestamp information with each measurement
      - IOTA_CB_NGSI_VERSION=v2 # use NGSIv2 when sending updates for active attributes
      - IOTA_AUTOCAST=true # Ensure Ultralight number values are read as numbers not strings
      - IOTA_MONGO_HOST=mongo-db # The host name of MongoDB
      - IOTA_MONGO_PORT=${MONGO_DB_PORT} # The port mongoDB is listening on
      - IOTA_MONGO_DB=iotagentjson # The name of the database used in mongoDB
      - IOTA_HTTP_PORT=${IOTA_SOUTH_PORT} # The port used for device traffic over HTTP
      - IOTA_PROVIDER_URL=http://iot-agent:${IOTA_NORTH_PORT}
      - IOTA_CB_NGSI_VERSION=v2
      - IOTA_AUTOCAST=true
      - IOTA_AUTH_ENABLED=true
      - IOTA_AUTH_TYPE=oauth2
      - IOTA_AUTH_HEADER=Authorization
      - IOTA_AUTH_HOST=keyrock
      - IOTA_AUTH_PORT=${KEYROCK_PORT}
      - IOTA_AUTH_URL=http://keyrock:${KEYROCK_PORT}
      - IOTA_AUTH_CLIENT_ID=tutorial-dckr-site-0000-xpresswebapp
      - IOTA_AUTH_CLIENT_SECRET=tutorial-dckr-host-0000-clientsecret
      - IOTA_AUTH_PERMANENT_TOKEN=true
      - IOTA_AUTH_TOKEN_PATH=/oauth2/token
    healthcheck:
      interval: 5s
    deploy:
      restart_policy:
        condition: on-failure
        delay: 60s
        max_attempts: 10

  keyrock:
    image: quay.io/fiware/idm:${KEYROCK_VERSION}
    container_name: fiware-keyrock
    hostname: keyrock
    networks:
      default:
        ipv4_address: 172.18.1.5
    depends_on:
      - mysql-db
      - authzforce
    ports:
      - "${KEYROCK_PORT}:${KEYROCK_PORT}" # localhost:3005
    environment:
      - DEBUG=idm:*
      - IDM_DB_HOST=mysql-db
      - IDM_DB_PASS_FILE=/run/secrets/my_secret_data
      - IDM_DB_USER=root
      - IDM_HOST=http://localhost:${KEYROCK_PORT}
      - IDM_PORT=${KEYROCK_PORT}
      - IDM_HTTPS_PORT=${KEYROCK_HTTPS_PORT}
      - IDM_ADMIN_USER=alice
      - IDM_ADMIN_EMAIL=alice-the-admin@test.com
      - IDM_ADMIN_PASS=test
      - IDM_PDP_LEVEL=advanced
      - IDM_AUTHZFORCE_ENABLED=true
      - IDM_AUTHZFORCE_HOST=authzforce
      - IDM_AUTHZFORCE_PORT=${AUTHZFORCE_PORT}
      - IDM_CSP_FORM_ACTION=*
      - IDM_CORS_ENABLED=true
      - IDM_CORS_ORIGIN=*
      - IDM_CORS_METHODS=*
      - IDM_CORS_ALLOWED_HEADERS=*
      - IDM_CORS_CREDENTIALS=true
      - IDM_CORS_PREFLIGHT=true
      - IDM_CORS_EXPOSED_HEADERS=*
      - IDM_CORS_MAX_AGE=600
    secrets:
      - my_secret_data
    healthcheck:
      interval: 5s
    deploy:
      restart_policy:
        condition: on-failure
        delay: 60s
        max_attempts: 10

已配置的CORS参数

- IDM_CORS_ENABLED=true
  - IDM_CORS_ORIGIN=*
  - IDM_CORS_METHODS=*
  - IDM_CORS_ALLOWED_HEADERS=*
  - IDM_CORS_CREDENTIALS=true
  - IDM_CORS_PREFLIGHT=true
  - IDM_CORS_EXPOSED_HEADERS=*
  - IDM_CORS_MAX_AGE=600

请求示例

用户登录请求(正常执行)

curl -iX POST \
  'http://localhost:3005/v1/auth/tokens' \
  -H 'Content-Type: application/json' \
  -d '{
  "token": "d848eb12-889f-433b-9811-6a4fbf0b86ca"
}'

创建用户请求(出现CORS错误)

curl -iX POST \
  'http://localhost:3005/v1/users' \
  -H 'Content-Type: application/json' \
  -H 'X-Auth-token: {{X-Auth-token}}' \
  -d '{
  "user": {
    "username": "alice",
    "email": "alice@test.com",
    "password": "test"
  }
}'

CORS错误信息

Access to fetch at 'http://{valid server-ip}:3005/v1/users' from origin 'http://{valid server-ip}:8989' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.

问题排查与解决方案

1. 验证Token有效性与权限

登录请求无需认证即可通过,但创建用户请求需携带X-Auth-token。如果Token无效、过期或用户无创建权限,Keyrock会直接返回4xx错误且不附加CORS头,导致浏览器抛出CORS错误。

  • 调用GET http://localhost:3005/v1/auth/tokens检查Token状态
  • 确认发起请求的用户拥有管理员角色或创建用户的权限

2. 修正Keyrock的IDM_HOST配置

当前IDM_HOST设置为http://localhost:${KEYROCK_PORT},但实际请求使用服务器IP而非localhost,可能导致Keyrock在认证请求中未正确注入CORS头。修改Keyrock环境变量:

- IDM_HOST=http://{valid server-ip}:${KEYROCK_PORT}

替换{valid server-ip}为实际服务器IP,重启Keyrock容器。

3. 排查Authzforce集成影响

启用了IDM_AUTHZFORCE_ENABLED=true,Authzforce的拦截逻辑可能覆盖Keyrock的CORS响应头设置:

  • 临时关闭Authzforce:设置IDM_AUTHZFORCE_ENABLED=false,重启容器后测试创建用户请求
  • 若关闭后问题消失,需配置Authzforce添加CORS响应头,或调整两者集成优先级

4. 查看Keyrock日志定位问题

利用已开启的DEBUG=idm:*查看容器日志:

docker logs fiware-keyrock

重点关注创建用户请求的处理流程,确认是否因认证失败、内部错误导致未返回CORS头。


内容的提问来源于stack exchange,提问作者hadi gheitasi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 00:39:52