如何配置WSO2 Identity Server 5.11.0仅使用HTTP模式?
配置WSO2 Identity Server 5.11.0仅使用HTTP流量
针对你遇到的HTTPS重定向、登录后跳转异常以及微服务交互失败问题,以下是完整的配置解决方案:
1. 核心传输层配置(deployment.toml)
修改${CARBON_HOME}/repository/conf/deployment.toml,禁用HTTPS并统一所有服务的基础URL为HTTP:
# 启用HTTP传输并配置端口 [transport.http] enabled = true port = 9763 # 完全禁用HTTPS传输 [transport.https] enabled = false # 配置服务器主机名和基础URL [server] hostname = "some-host" base_url = "http://some-host:9763" # 修正控制台和My Account的URL(解决日志中端口为-1的问题) [identity_apps] my_account_url = "http://some-host:9763/myaccount" console_url = "http://some-host:9763/console"
2. 管理控制台HTTP访问配置(carbon.xml)
修改${CARBON_HOME}/repository/conf/carbon.xml,确保HTTP管理控制台生效并禁用HTTPS控制台:
<!-- 启用HTTP管理控制台 --> <EnableHTTPAdminConsole>true</EnableHTTPAdminConsole> <!-- 允许所有管理服务通过HTTP访问 --> <HttpAdminServices>*</HttpAdminServices> <!-- 禁用HTTPS管理控制台 --> <EnableAdminConsole>false</EnableAdminConsole>
3. 身份服务端点配置(deployment.toml)
添加以下配置,将所有OAuth2/OIDC、SCIM等核心服务端点强制设为HTTP,避免重定向:
# OAuth2/OIDC端点配置 [oauth.endpoints] oauth2_authorization_endpoint = "http://some-host:9763/oauth2/authorize" oauth2_token_endpoint = "http://some-host:9763/oauth2/token" oauth2_revoke_endpoint = "http://some-host:9763/oauth2/revoke" oauth2_introspect_endpoint = "http://some-host:9763/oauth2/introspect" # OIDC用户信息端点 [oidc.endpoints] userinfo_endpoint = "http://some-host:9763/oauth2/userinfo" # SCIM2端点配置 [scim] base_url = "http://some-host:9763/scim2"
4. 修复登录后重定向回登录页问题
登录到已可用的HTTP管理控制台http://some-host:9763/carbon/admin,修改控制台对应的服务提供者回调URL:
- 进入主菜单 > Service Providers > List,找到
carbon.super服务提供者 - 点击Edit,切换到Inbound Authentication Configuration > OAuth/OpenID Connect Configuration
- 修改回调URL为:
http://some-host:9763/carbon/admin/login.jsp - 保存配置
同时,确保你自定义的服务提供者(Java微服务、Angular前端)的回调URL都配置为HTTP协议,而非HTTPS。
5. 微服务交互适配
调整你的Spring Cloud Gateway和后端微服务的配置:
- 将令牌验证的端点改为
http://some-host:9763/oauth2/introspect - 将拉取用户角色/信息的SCIM端点改为
http://some-host:9763/scim2/Users/{userId}/groups(或对应需求的端点)
6. 重启服务并验证
完成所有配置后,重启WSO2 Identity Server,验证以下场景:
- 访问
http://some-host:9763/carbon/admin无HTTPS重定向 - 使用管理员凭据登录后可正常进入控制台,无跳转回登录页的问题
- 微服务的令牌验证、角色拉取请求可通过HTTP正常完成,无重定向错误
内容的提问来源于stack exchange,提问作者overbet13
相关产品推荐
相关产品推荐

