WSO2 IS升级至6.1.0后OAuth2认证报错:idn_oauth2_user_consent表不存在
WSO2 IS 5.11.0升级至6.1.0后OAuth2认证报错问题咨询
问题场景
- 通过docker-is项目将WSO2 IS 5.11.0 Docker镜像升级至6.1.0版本
- 服务器启动正常,默认超级管理员用户界面可正常访问
- 原在5.11.0中可正常工作的OAuth2服务提供者,在6.1.0的认证流程中报错,核心日志显示数据库不存在
idn_oauth2_user_consent表,错误栈如下:
TID: [-1234] [oauth2] [2023-08-30 07:58:51,502] [a09ede89-1b16-4294-b422-680ce83e7a15] DEBUG {org.wso2.carbon.identity.oauth.endpoint.authz.OAuth2AuthzEndpoint} - Server error occurred while performing authorization org.apache.oltu.oauth2.common.exception.OAuthSystemException: Error occurred while checking user has already approved the consent required OAuth scopes. at org.wso2.carbon.identity.oauth.endpoint.authz.OAuth2AuthzEndpoint.isUserAlreadyApproved(OAuth2AuthzEndpoint.java:3056) ... Caused by: org.postgresql.util.PSQLException: ERROR: relation "idn_oauth2_user_consent" does not exist Position: 62 ...
用户咨询
是否需要在升级WSO2 IS后执行数据库升级命令,还是该操作应在Docker镜像首次启动时自动完成?
回答
- WSO2 IS从5.x跨版本升级到6.x时,必须手动执行数据库升级脚本,Docker镜像首次启动不会自动完成数据库结构的升级。
- 6.1.0版本新增了
idn_oauth2_user_consent这类用于OAuth2用户同意管理的表,而5.11.0的数据库中没有这些结构,这是导致认证报错的直接原因。 - 具体操作要点:
- 获取WSO2 IS 6.1.0对应PostgreSQL数据库的官方升级脚本
- 先备份当前数据库,避免数据丢失
- 执行升级脚本,完成数据库表结构和数据的迁移
- 重启WSO2 IS 6.1.0镜像,验证OAuth2认证流程恢复正常
内容的提问来源于stack exchange,提问作者Victor Da Silva
相关产品推荐
相关产品推荐

