Fiware Keyrock GE跨域问题:登录请求正常,其他请求触发CORS错误
FIWARE Keyrock CORS配置异常问题
问题现象
已在FIWARE中配置Keyrock通用使能器(GE)启用跨域资源共享(CORS),用户登录的POST请求可正常执行且无CORS问题,但发起创建用户等其他请求时出现CORS错误。预期配置允许所有源、方法、请求头,支持凭证与预检请求,但问题仍存在。
Keyrock Docker-Compose配置
version: "3.8" services: orion-v2: image: quay.io/fiware/orion:${ORION_VERSION} hostname: orion container_name: fiware-orion depends_on: - mongo-db networks: default: ipv4_address: 172.18.1.9 expose: - "${ORION_PORT}" ports: - "${ORION_PORT}:${ORION_PORT}" # localhost:1026 command: -logLevel DEBUG -noCache -dbhost mongo-db -corsOrigin __ALL healthcheck: test: curl --fail -s http://orion:${ORION_PORT}/version || exit 1 interval: 5s deploy: restart_policy: condition: on-failure delay: 60s max_attempts: 10 iot-agent: image: fiware/iotagent-json hostname: iot-agent container_name: fiware-iot-agent depends_on: - mongo-db - orion-v2 networks: default: ipv4_address: 172.18.1.100 ports: - "${IOTA_NORTH_PORT}:${IOTA_NORTH_PORT}" # localhost:4041 - "${IOTA_SOUTH_PORT}:${IOTA_SOUTH_PORT}" # localhost:7896 environment: - IOTA_CB_HOST=orion-proxy - IOTA_CB_PORT=${ORION_PROXY_PORT} # port the context broker listens on to update context - IOTA_NORTH_PORT=${IOTA_NORTH_PORT} - IOTA_REGISTRY_TYPE=mongodb #Whether to hold IoT device info in memory or in a database - IOTA_LOG_LEVEL=DEBUG # The log level of the IoT Agent - IOTA_TIMESTAMP=true # Supply timestamp information with each measurement - IOTA_CB_NGSI_VERSION=v2 # use NGSIv2 when sending updates for active attributes - IOTA_AUTOCAST=true # Ensure Ultralight number values are read as numbers not strings - IOTA_MONGO_HOST=mongo-db # The host name of MongoDB - IOTA_MONGO_PORT=${MONGO_DB_PORT} # The port mongoDB is listening on - IOTA_MONGO_DB=iotagentjson # The name of the database used in mongoDB - IOTA_HTTP_PORT=${IOTA_SOUTH_PORT} # The port used for device traffic over HTTP - IOTA_PROVIDER_URL=http://iot-agent:${IOTA_NORTH_PORT} - IOTA_CB_NGSI_VERSION=v2 - IOTA_AUTOCAST=true - IOTA_AUTH_ENABLED=true - IOTA_AUTH_TYPE=oauth2 - IOTA_AUTH_HEADER=Authorization - IOTA_AUTH_HOST=keyrock - IOTA_AUTH_PORT=${KEYROCK_PORT} - IOTA_AUTH_URL=http://keyrock:${KEYROCK_PORT} - IOTA_AUTH_CLIENT_ID=tutorial-dckr-site-0000-xpresswebapp - IOTA_AUTH_CLIENT_SECRET=tutorial-dckr-host-0000-clientsecret - IOTA_AUTH_PERMANENT_TOKEN=true - IOTA_AUTH_TOKEN_PATH=/oauth2/token healthcheck: interval: 5s deploy: restart_policy: condition: on-failure delay: 60s max_attempts: 10 keyrock: image: quay.io/fiware/idm:${KEYROCK_VERSION} container_name: fiware-keyrock hostname: keyrock networks: default: ipv4_address: 172.18.1.5 depends_on: - mysql-db - authzforce ports: - "${KEYROCK_PORT}:${KEYROCK_PORT}" # localhost:3005 environment: - DEBUG=idm:* - IDM_DB_HOST=mysql-db - IDM_DB_PASS_FILE=/run/secrets/my_secret_data - IDM_DB_USER=root - IDM_HOST=http://localhost:${KEYROCK_PORT} - IDM_PORT=${KEYROCK_PORT} - IDM_HTTPS_PORT=${KEYROCK_HTTPS_PORT} - IDM_ADMIN_USER=alice - IDM_ADMIN_EMAIL=alice-the-admin@test.com - IDM_ADMIN_PASS=test - IDM_PDP_LEVEL=advanced - IDM_AUTHZFORCE_ENABLED=true - IDM_AUTHZFORCE_HOST=authzforce - IDM_AUTHZFORCE_PORT=${AUTHZFORCE_PORT} - IDM_CSP_FORM_ACTION=* - IDM_CORS_ENABLED=true - IDM_CORS_ORIGIN=* - IDM_CORS_METHODS=* - IDM_CORS_ALLOWED_HEADERS=* - IDM_CORS_CREDENTIALS=true - IDM_CORS_PREFLIGHT=true - IDM_CORS_EXPOSED_HEADERS=* - IDM_CORS_MAX_AGE=600 secrets: - my_secret_data healthcheck: interval: 5s deploy: restart_policy: condition: on-failure delay: 60s max_attempts: 10
已配置的CORS参数
- IDM_CORS_ENABLED=true - IDM_CORS_ORIGIN=* - IDM_CORS_METHODS=* - IDM_CORS_ALLOWED_HEADERS=* - IDM_CORS_CREDENTIALS=true - IDM_CORS_PREFLIGHT=true - IDM_CORS_EXPOSED_HEADERS=* - IDM_CORS_MAX_AGE=600
请求示例
用户登录请求(正常执行)
curl -iX POST \ 'http://localhost:3005/v1/auth/tokens' \ -H 'Content-Type: application/json' \ -d '{ "token": "d848eb12-889f-433b-9811-6a4fbf0b86ca" }'
创建用户请求(出现CORS错误)
curl -iX POST \ 'http://localhost:3005/v1/users' \ -H 'Content-Type: application/json' \ -H 'X-Auth-token: {{X-Auth-token}}' \ -d '{ "user": { "username": "alice", "email": "alice@test.com", "password": "test" } }'
CORS错误信息
Access to fetch at 'http://{valid server-ip}:3005/v1/users' from origin 'http://{valid server-ip}:8989' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.
问题排查与解决方案
1. 验证Token有效性与权限
登录请求无需认证即可通过,但创建用户请求需携带X-Auth-token。如果Token无效、过期或用户无创建权限,Keyrock会直接返回4xx错误且不附加CORS头,导致浏览器抛出CORS错误。
- 调用
GET http://localhost:3005/v1/auth/tokens检查Token状态 - 确认发起请求的用户拥有管理员角色或创建用户的权限
2. 修正Keyrock的IDM_HOST配置
当前IDM_HOST设置为http://localhost:${KEYROCK_PORT},但实际请求使用服务器IP而非localhost,可能导致Keyrock在认证请求中未正确注入CORS头。修改Keyrock环境变量:
- IDM_HOST=http://{valid server-ip}:${KEYROCK_PORT}
替换{valid server-ip}为实际服务器IP,重启Keyrock容器。
3. 排查Authzforce集成影响
启用了IDM_AUTHZFORCE_ENABLED=true,Authzforce的拦截逻辑可能覆盖Keyrock的CORS响应头设置:
- 临时关闭Authzforce:设置
IDM_AUTHZFORCE_ENABLED=false,重启容器后测试创建用户请求 - 若关闭后问题消失,需配置Authzforce添加CORS响应头,或调整两者集成优先级
4. 查看Keyrock日志定位问题
利用已开启的DEBUG=idm:*查看容器日志:
docker logs fiware-keyrock
重点关注创建用户请求的处理流程,确认是否因认证失败、内部错误导致未返回CORS头。
内容的提问来源于stack exchange,提问作者hadi gheitasi
相关产品推荐
相关产品推荐

