You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置WSO2 Identity Server 5.11.0仅使用HTTP模式?

配置WSO2 Identity Server 5.11.0仅使用HTTP流量

针对你遇到的HTTPS重定向、登录后跳转异常以及微服务交互失败问题,以下是完整的配置解决方案:

1. 核心传输层配置(deployment.toml)

修改${CARBON_HOME}/repository/conf/deployment.toml,禁用HTTPS并统一所有服务的基础URL为HTTP:

# 启用HTTP传输并配置端口
[transport.http]
enabled = true
port = 9763

# 完全禁用HTTPS传输
[transport.https]
enabled = false

# 配置服务器主机名和基础URL
[server]
hostname = "some-host"
base_url = "http://some-host:9763"

# 修正控制台和My Account的URL(解决日志中端口为-1的问题)
[identity_apps]
my_account_url = "http://some-host:9763/myaccount"
console_url = "http://some-host:9763/console"

2. 管理控制台HTTP访问配置(carbon.xml)

修改${CARBON_HOME}/repository/conf/carbon.xml,确保HTTP管理控制台生效并禁用HTTPS控制台:

<!-- 启用HTTP管理控制台 -->
<EnableHTTPAdminConsole>true</EnableHTTPAdminConsole>
<!-- 允许所有管理服务通过HTTP访问 -->
<HttpAdminServices>*</HttpAdminServices>
<!-- 禁用HTTPS管理控制台 -->
<EnableAdminConsole>false</EnableAdminConsole>

3. 身份服务端点配置(deployment.toml)

添加以下配置,将所有OAuth2/OIDC、SCIM等核心服务端点强制设为HTTP,避免重定向:

# OAuth2/OIDC端点配置
[oauth.endpoints]
oauth2_authorization_endpoint = "http://some-host:9763/oauth2/authorize"
oauth2_token_endpoint = "http://some-host:9763/oauth2/token"
oauth2_revoke_endpoint = "http://some-host:9763/oauth2/revoke"
oauth2_introspect_endpoint = "http://some-host:9763/oauth2/introspect"

# OIDC用户信息端点
[oidc.endpoints]
userinfo_endpoint = "http://some-host:9763/oauth2/userinfo"

# SCIM2端点配置
[scim]
base_url = "http://some-host:9763/scim2"

4. 修复登录后重定向回登录页问题

登录到已可用的HTTP管理控制台http://some-host:9763/carbon/admin,修改控制台对应的服务提供者回调URL:

  • 进入主菜单 > Service Providers > List,找到carbon.super服务提供者
  • 点击Edit,切换到Inbound Authentication Configuration > OAuth/OpenID Connect Configuration
  • 修改回调URL为:http://some-host:9763/carbon/admin/login.jsp
  • 保存配置

同时,确保你自定义的服务提供者(Java微服务、Angular前端)的回调URL都配置为HTTP协议,而非HTTPS。

5. 微服务交互适配

调整你的Spring Cloud Gateway和后端微服务的配置:

  • 将令牌验证的端点改为http://some-host:9763/oauth2/introspect
  • 将拉取用户角色/信息的SCIM端点改为http://some-host:9763/scim2/Users/{userId}/groups(或对应需求的端点)

6. 重启服务并验证

完成所有配置后,重启WSO2 Identity Server,验证以下场景:

  • 访问http://some-host:9763/carbon/admin无HTTPS重定向
  • 使用管理员凭据登录后可正常进入控制台,无跳转回登录页的问题
  • 微服务的令牌验证、角色拉取请求可通过HTTP正常完成,无重定向错误

内容的提问来源于stack exchange,提问作者overbet13

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 19:27:28