You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JBoss EAP 7.4 standalone.xml中缺失使用ApplicationDomain的application-http-authentication

JBoss EAP 7.4 Elytron应用级配置缺失问题解答

问题原因

  • 默认standalone.xml仅包含核心管理功能所需的Elytron配置,指南中提到的application-http-authentication等应用级安全配置,默认存在于standalone-full.xml或standalone-ha.xml这类包含完整功能的配置文件中。
  • 官方文档描述的是EAP支持的预配置能力,并非所有配置都会在最精简的standalone.xml中默认启用。

手动添加应用级Elytron配置

如果需要在standalone.xml中启用该配置,可以添加以下内容到对应节点:

1. 添加ApplicationRealm与ApplicationDomain

<security-domains>
    <security-domain name="ApplicationDomain" default-realm="ApplicationRealm" permission-mapper="default-permission-mapper">
        <realm name="ApplicationRealm" role-decoder="groups-to-roles"/>
    </security-domain>
    <!-- 保留原有的ManagementDomain配置 -->
    <security-domain name="ManagementDomain" default-realm="ManagementRealm" permission-mapper="default-permission-mapper">
        <realm name="ManagementRealm" role-decoder="groups-to-roles"/>
    </security-domain>
</security-domains>

<realms>
    <properties-realm name="ApplicationRealm" groups-attribute="groups">
        <users path="application-users.properties" relative-to="jboss.server.config.dir"/>
        <groups path="application-roles.properties" relative-to="jboss.server.config.dir"/>
    </properties-realm>
    <!-- 保留原有的ManagementRealm配置 -->
    <properties-realm name="ManagementRealm" groups-attribute="groups">
        <users path="mgmt-users.properties" relative-to="jboss.server.config.dir"/>
        <groups path="mgmt-groups.properties" relative-to="jboss.server.config.dir"/>
    </properties-realm>
</realms>

<role-decoders>
    <simple-role-decoder name="groups-to-roles" attribute="groups"/>
</role-decoders>

2. 添加application-http-authentication配置

在Elytron子系统的<http>节点内添加:

<http-authentication-factory name="application-http-authentication" security-domain="ApplicationDomain" http-server-mechanism-factory="global">
    <mechanism-configuration>
        <mechanism mechanism-name="BASIC">
            <mechanism-realm realm-name="ApplicationRealm"/>
        </mechanism>
    </mechanism-configuration>
</http-authentication-factory>

3. 关联到Undertow子系统(可选)

若要让应用使用该认证工厂,需在Undertow子系统中配置引用:

<subsystem xmlns="urn:wildfly:undertow:12.0" default-server="default-server" default-virtual-host="default-host" default-servlet-container="default" default-security-domain="ApplicationDomain">
    <application-security-domains>
        <application-security-domain name="application-domain" http-authentication-factory="application-http-authentication"/>
    </application-security-domains>
    <!-- 保留原有的Undertow配置 -->
</subsystem>

内容的提问来源于stack exchange,提问作者ericj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 04:43:14