使用mod_auth_openidc在应用中获取Claims失败求助
Apache mod_auth_openidc 无法传递Claims到请求头/环境变量问题
我使用正常运行的Keycloak作为OIDC服务端,客户端是在Keycloak中注册为webapp.home的测试应用iNetOrgPerson.html,由Apache和mod_auth_openidc管理。认证功能正常,但无法以请求头或环境变量形式获取Claims,推测是httpd配置问题但找不到原因,求解决思路。
我的httpd配置
<VirtualHost *:80> ServerName www.webapp.home ServerAlias webapp.home DocumentRoot /var/www/webapp.home ErrorLog logs/webapp_home.error_log CustomLog logs/webapp_home.access_log combined OIDCCryptoPassphrase webapp_home OIDCScope "openid email" OIDCProviderMetadataURL http://zbook.home:8180/realms/testRealm/.well-known/openid-configuration OIDCClientID webapp.home OIDCClientSecret lx2ThK3H6fKlqPVD8LLuNNJuyForkrwu OIDCRedirectURI http://webapp.home/redirect_uri OIDCProviderTokenEndpointAuth client_secret_basic OIDCPassClaimsAs headers OIDCPassIDTokenAs claims OIDCPassUserInfoAs claims OIDCRemoteUserClaim email <Location /> AuthType openid-connect Require valid-user DirectoryIndex iNetOrgPerson.html </Location> </VirtualHost>
用来打印请求头的JS脚本
<script> var x= ""; if(window.fetch) fetch(location, {method:'HEAD'}) .then(function(r) { r.headers.forEach(function(Value, Header) { x= x + Header + ": " + Value + "\n\n"; }); }) .then(function() { document.body.appendChild(document.createElement("pre")).textContent= x; }); else document.write("This does not work in your browser - no support for fetch API"); </script>
脚本输出结果
accept-ranges: bytes connection: Keep-Alive content-length: 3900 content-type: text/html; charset=UTF-8 date: Mon, 01 Jan 2024 21:48:41 GMT etag: "f3c-60de9584a1702" keep-alive: timeout=5, max=99 last-modified: Mon, 01 Jan 2024 21:48:40 GMT server: Apache/2.4.58 (Fedora Linux) OpenSSL/3.0.9 mod_auth_gssapi/1.6.3 mod_wsgi/4.9.1 Python/3.11
排查修复建议
- 前端JS看不到后端注入的请求头:你用
fetch获取的是浏览器收到的响应头,而mod_auth_openidc注入的Claims头是Apache传给后端应用的请求头,前端根本访问不到这些。要验证是否传递成功,得用后端脚本(比如PHP的<?php print_r($_SERVER); ?>)查看服务器环境变量或请求头。 - 调整配置项位置:把
OIDCPassClaimsAs headers这类Claims传递的配置移到<Location />块内部,mod_auth_openidc的部分配置需要在AuthType生效的位置块内才能正确触发。修改后:<Location /> AuthType openid-connect Require valid-user OIDCPassClaimsAs headers OIDCPassIDTokenAs claims OIDCPassUserInfoAs claims DirectoryIndex iNetOrgPerson.html </Location> - 确认Keycloak端的权限配置:在Keycloak的
webapp.home客户端设置里,确保emailClaim被添加到关联的Client Scopes中,且用户账号存在有效的email属性。可以直接访问Keycloak的UserInfo端点验证是否能拿到预期的Claims。 - 开启调试日志排查:在VirtualHost中添加
OIDCLogLevel debug,然后查看webapp_home.error_log,里面会有Claims处理的详细日志,能帮你定位是否有配置或权限问题。
内容的提问来源于stack exchange,提问作者Pascal Jakobi
相关产品推荐
相关产品推荐

