WSO2 Identity Server 6.1.0谷歌登录报错“无效租户gmail.com”排查
问题分析与修复方案
问题根源
你遇到的以下错误:
ERROR {org.wso2.carbon.identity.application.authentication.framework.handler.request.impl.DefaultRequestCoordinator} - Exception in Authentication Framework org.wso2.carbon.identity.base.IdentityRuntimeException: Invalid tenant domain gmail.com at org.wso2.carbon.identity.base.IdentityRuntimeException.error(IdentityRuntimeException.java:55) at org.wso2.carbon.identity.core.util.IdentityTenantUtil.getTenantId(IdentityTenantUtil.java:274)
核心原因是WSO2 Identity Server默认会从谷歌返回的用户邮箱域名(gmail.com)识别租户,但你的环境中并未配置gmail.com作为合法租户域,导致租户验证失败。这是WSO2 Identity Server层面的配置问题,无需修改前端应用。
修复步骤
1. 调整谷歌身份提供商的租户归属配置
- 登录WSO2 IS管理控制台,进入
Identity Providers > 你的谷歌身份提供商 > Advanced Configuration - 启用Use Tenant Domain from Local Claim选项
- 在对应的本地声明中选择
http://wso2.org/claims/tenantDomain,并设置固定值为你的默认租户域(通常是carbon.super) - 保存配置
2. 可选:修改用户存储的租户识别规则(多租户场景)
如果你的环境是多租户,但不需要通过邮箱域名自动识别租户:
- 进入
User Stores > 主用户存储 > Advanced Settings - 将Tenant Domain Retrieval from Username设置为
Disabled - 保存配置
验证
完成上述配置后,重新发起谷歌登录流程,跳转回应用时即可正常完成认证。
内容的提问来源于stack exchange,提问作者user666
相关产品推荐
相关产品推荐

