Curity 6.0.0添加email scope后向oauth-authorize发送POST请求抛出400错误问题咨询
从你提供的配置和服务器日志来看,这个400错误的根源很清晰——你在Curity社区版中使用了需要商业许可证的功能。
问题细节拆解
- 你的客户端配置里(第13行)添加了
emailscope:
<scope>email</scope>
- 当发起授权请求时,服务器日志明确抛出了许可证相关的警告和错误:
2021-04-09T13:40:06:466+0000 WARN LawmynV9 c2073b3a {req-203} se.curity.identityserver.claims.StandardClaimValuesResolver - One or more of the configured claims providers isn't licensed
2021-04-09T13:40:06:466+0000 WARN LawmynV9 c2073b3a {req-203} se.curity.identityserver.tokens.scripting.TokenProcedure - Token procedure with ID _default-authorize-code threw an Exception: A license violation has occurred
2021-04-09T13:40:06:466+0000 INFO LawmynV9 c2073b3a {req-203} se.curity.identityserver.controllers.InteractiveOAuthController - Unable to translate error thrown by procedure, responding with server error
原因分析
Curity社区版确实允许你在配置界面添加email这类标准OIDC scope,但该功能属于商业授权范畴,社区版没有对应的许可证权限来实际处理这个scope的请求。当授权流程尝试解析email声明时,触发了许可证校验,最终导致流程失败,返回了400错误(服务器内部错误的包装)。
解决方案
如果你需要使用email这类需要授权的scope,有两个选择:
- 升级到Curity的商业许可证版本,获得完整的功能权限
- 移除配置中的
emailscope,只保留社区版支持的openid等基础scope,这样授权流程就能正常执行了
内容的提问来源于stack exchange,提问作者wilsotc

