You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 API Manager 4.1.0:如何通过多个主机名暴露OAuth2 URL?

WSO2 API Manager 4.1.0 配置多OAuth2认证主机名并解决CORS问题

可以实现,以下是具体的配置步骤和CORS解决方案:

1. 配置多主机名(OAuth2认证端点)

WSO2 AM支持通过配置虚拟主机和主机别名来实现多域名的OAuth2认证端点,核心修改deployment.toml配置文件:

  • 添加主机别名,让服务器识别多个域名:
    [server]
    hostname = "default.example.com"  # 默认主机名
    server_url = "https://default.example.com:9443/services/"
    
    [server.host_names]
    example1.com = true
    example2.com = true
    
  • 配置网关虚拟主机,绑定每个域名到网关服务:
    [apim.gateway.virtual_hosts]
    [apim.gateway.virtual_hosts.example1]
    hostname = "example1.com"
    
    [apim.gateway.virtual_hosts.example2]
    hostname = "example2.com"
    
    配置完成后,WSO2会自动为每个虚拟主机生成对应的OAuth2认证端点,即https://example1.com/oauth2/authorize和https://example2.com/oauth2/authorize。

2. 配置CORS策略解决跨域错误

为了避免不同业务系统重定向时的CORS报错,需要同时配置全局API网关的CORS规则和OAuth2 web应用的CORS过滤器:

全局网关CORS配置(deployment.toml)

[apim.cors]
enable = true
allow_origins = ["https://example1.com", "https://example2.com"]
allow_methods = ["GET", "POST", "OPTIONS", "PUT", "DELETE"]
allow_headers = ["Authorization", "Content-Type", "Accept", "Origin"]
allow_credentials = true
expose_headers = ["Location"]  # 暴露重定向头,确保前端能获取跳转地址

OAuth2应用CORS过滤器配置

编辑repository/deployment/server/webapps/oauth2/WEB-INF/web.xml,添加CORS过滤器:

<filter>
    <filter-name>CORSFilter</filter-name>
    <filter-class>org.apache.catalina.filters.CorsFilter</filter-class>
    <init-param>
        <param-name>cors.allowed.origins</param-name>
        <param-value>https://example1.com,https://example2.com</param-value>
    </init-param>
    <init-param>
        <param-name>cors.allowed.methods</param-name>
        <param-value>GET,POST,OPTIONS,PUT,DELETE</param-value>
    </init-param>
    <init-param>
        <param-name>cors.allowed.headers</param-name>
        <param-value>Authorization,Content-Type,Accept,Origin</param-value>
    </init-param>
    <init-param>
        <param-name>cors.allow.credentials</param-name>
        <param-value>true</param-value>
    </init-param>
</filter>
<filter-mapping>
    <filter-name>CORSFilter</filter-name>
    <url-pattern>/*</url-pattern>
</filter-mapping>

3. 验证配置

  1. 重启WSO2 AM服务,确保配置生效。
  2. 分别访问两个域名的认证端点,确认页面能正常加载。
  3. 测试业务系统的认证重定向流程,检查浏览器控制台是否存在CORS错误。

注意事项

  • 确保所有配置的域名已正确解析到WSO2 AM服务器的IP地址。
  • 如果使用反向代理或负载均衡器,需要确保代理层传递正确的Host请求头,并为每个域名配置对应的SSL证书。

内容的提问来源于stack exchange,提问作者Lilan Mihiranga

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 04:02:36