You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 Identity Server 6.1.0谷歌登录报错“无效租户gmail.com”排查

问题分析与修复方案

问题根源

你遇到的以下错误:

ERROR {org.wso2.carbon.identity.application.authentication.framework.handler.request.impl.DefaultRequestCoordinator} - Exception in Authentication Framework org.wso2.carbon.identity.base.IdentityRuntimeException: Invalid tenant domain gmail.com
        at org.wso2.carbon.identity.base.IdentityRuntimeException.error(IdentityRuntimeException.java:55)
        at org.wso2.carbon.identity.core.util.IdentityTenantUtil.getTenantId(IdentityTenantUtil.java:274)

核心原因是WSO2 Identity Server默认会从谷歌返回的用户邮箱域名(gmail.com)识别租户,但你的环境中并未配置gmail.com作为合法租户域,导致租户验证失败。这是WSO2 Identity Server层面的配置问题,无需修改前端应用。

修复步骤

1. 调整谷歌身份提供商的租户归属配置

  • 登录WSO2 IS管理控制台,进入Identity Providers > 你的谷歌身份提供商 > Advanced Configuration
  • 启用Use Tenant Domain from Local Claim选项
  • 在对应的本地声明中选择http://wso2.org/claims/tenantDomain,并设置固定值为你的默认租户域(通常是carbon.super)
  • 保存配置

2. 可选:修改用户存储的租户识别规则(多租户场景)

如果你的环境是多租户,但不需要通过邮箱域名自动识别租户:

  • 进入User Stores > 主用户存储 > Advanced Settings
  • 将Tenant Domain Retrieval from Username设置为Disabled
  • 保存配置

验证

完成上述配置后,重新发起谷歌登录流程,跳转回应用时即可正常完成认证。


内容的提问来源于stack exchange,提问作者user666

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 23:42:38