You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地部署Keycloak获取Token时遇NullPointerException错误求助

Keycloak获取Token时出现NullPointerException问题排查

问题描述

本地部署Keycloak 24.0.2,创建了test-realm领域、test-client客户端和用户user1(密码123456),调用http://localhost:8180/realms/test-realm/protocol/openid-connect/token端点获取Token时,服务器抛出NullPointerException,响应返回unknown_error。

服务器错误日志

2024-04-10 16:20:26,836 ERROR [org.keycloak.services.error.KeycloakErrorHandler] (executor-thread-1) Uncaught server error: java.lang.NullPointerException: Cannot invoke "Object.toString()" because the return value of "io.vertx.core.http.HttpServerRequest.authority()" is null
    at org.jboss.resteasy.reactive.server.vertx.VertxResteasyReactiveRequestContext.getRequestHost(VertxResteasyReactiveRequestContext.java:194)
    at org.jboss.resteasy.reactive.server.core.ResteasyReactiveRequestContext.getAuthority(ResteasyReactiveRequestContext.java:481)
    at org.jboss.resteasy.reactive.server.jaxrs.UriInfoImpl.getBaseUri(UriInfoImpl.java:131)
    at org.keycloak.urls.HostnameProvider.getScheme(HostnameProvider.java:51)
    at org.keycloak.quarkus.runtime.hostname.DefaultHostnameProvider.fromFrontEndUrl(DefaultHostnameProvider.java:181)
    at org.keycloak.quarkus.runtime.hostname.DefaultHostnameProvider.getScheme(DefaultHostnameProvider.java:90)
    at org.keycloak.models.KeycloakUriInfo.<init>(KeycloakUriInfo.java:51)
    at org.keycloak.services.DefaultKeycloakContext.getUri(DefaultKeycloakContext.java:78)
    at org.keycloak.services.DefaultKeycloakContext.getUri(DefaultKeycloakContext.java:85)
    at org.keycloak.protocol.oidc.endpoints.TokenEndpoint.checkSsl(TokenEndpoint.java:156)
    at org.keycloak.protocol.oidc.endpoints.TokenEndpoint.processGrantRequest(TokenEndpoint.java:129)
    at org.keycloak.protocol.oidc.endpoints.TokenEndpoint$quarkusrestinvoker$processGrantRequest_6408e15340992839b66447750c221d9aaa837bd7.invoke(Unknown Source)
    at org.jboss.resteasy.reactive.server.handlers.InvocationHandler.handle(InvocationHandler.java:29)
    at io.quarkus.resteasy.reactive.server.runtime.QuarkusResteasyReactiveRequestContext.invokeHandler(QuarkusResteasyReactiveRequestContext.java:141)
    at org.jboss.resteasy.reactive.common.core.AbstractResteasyReactiveContext.run(AbstractResteasyReactiveContext.java:147)
    at io.quarkus.vertx.core.runtime.VertxCoreRecorder$14.runWith(VertxCoreRecorder.java:582)
    at org.jboss.threads.EnhancedQueueExecutor$Task.run(EnhancedQueueExecutor.java:2513)
    at org.jboss.threads.EnhancedQueueExecutor$ThreadBody.run(EnhancedQueueExecutor.java:1538)
    at org.jboss.threads.DelegatingRunnable.run(DelegatingRunnable.java:29)
    at org.jboss.threads.ThreadLocalResettingRunnable.run(ThreadLocalResettingRunnable.java:29)
    at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30)
    at java.base/java.lang.Thread.run(Thread.java:1583)

服务器响应

{
    "error": "unknown_error",
    "error_description": "For more on this error consult the server log at the debug level."
}

启动日志关键信息

2024-04-10 16:19:46,573 INFO  [org.keycloak.quarkus.runtime.hostname.DefaultHostnameProvider] (main) Hostname settings: Base URL: <unset>, Hostname: <request>, Strict HTTPS: false, Path: <request>, Strict BackChannel: false, Admin URL: <unset>, Admin: <request>, Port: -1, Proxied: false
...
2024-04-10 16:19:52,155 INFO  [io.quarkus] (main) Keycloak 24.0.2 on JVM (powered by Quarkus 3.8.3) started in 7.393s. Listening on: http://0.0.0.0:8180

解决方案

1. 启动时指定固定主机名和端口

Keycloak默认从请求中解析主机信息,当请求缺少Host头或解析失败时会触发NPE。启动时显式配置主机名和端口即可规避该问题:

命令行启动示例:

./kc.sh start-dev --hostname=localhost --hostname-port=8180

环境变量方式:

export KEYCLOAK_HOSTNAME=localhost
export KEYCLOAK_HOSTNAME_PORT=8180
./kc.sh start-dev

2. 确保请求包含正确的Host头

发送POST请求时必须携带Host: localhost:8180头,curl请求完整示例:

curl -X POST http://localhost:8180/realms/test-realm/protocol/openid-connect/token \
  -H "Host: localhost:8180" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=password&username=user1&password=123456&client_id=test-client"

3. 检查客户端配置

  • 确认test-client的Access Type设置为confidential或public(密码模式下两种类型均支持,confidential类型需额外携带client_secret参数)
  • 确保Valid Redirect URIs或Web Origins配置正确(本地测试可设为*或http://localhost:*)

内容的提问来源于stack exchange,提问作者merel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 08:56:08