You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wildfly 26.1.3启用OIDC后BASIC认证失效(ELY06017)的解决咨询

Wildfly 26.1.3启用OIDC后BASIC认证失效问题解决

环境与应用结构

  • 部署环境:Wildfly 26.1.3
  • 部署应用:myapp.ear,包含三个模块:
    • myservlet.war:通过web.xml配置BASIC认证,依赖ApplicationDomain安全域
    • myRest.war:基于wildfly:elytron-oidc-client:1.0 + Keycloak实现OIDC认证
    • myServices.jar:包含EJB与实体类

问题现象

启用OIDC前,myservlet.war的BASIC认证正常工作;启用OIDC后,OIDC认证功能正常,但myservlet.war的BASIC认证失效,抛出HTTP 500内部服务器错误,错误信息如下:

org.wildfly.security.http.HttpAuthenticationException: ELY06017: HTTP authentication is required but no authentication mechansims are available.

at:
org.wildfly.security.http.HttpAuthenticator$AuthenticationExchange.authenticate(HttpAuthenticator.java:317)

根据文档说明,OIDC子系统会自动创建安全域,导致原有ApplicationDomain安全域无法被正常调用,需求是重新激活原有标准安全域ApplicationDomain,同时保留OIDC认证功能。

相关配置

OIDC子系统配置(standalone.xml)

<subsystem xmlns="urn:wildfly:elytron-oidc-client:1.0">
    <secure-deployment name="myRest.war">
        <auth-server-url>https://auth.sample.com/auth</auth-server-url>
        <ssl-required>ALL</ssl-required>
        <realm>myRealm</realm>
        <resource>myResource</resource>
        <credential name="secret" secret="mySecret"/>
    </secure-deployment>
</subsystem>

BASIC认证配置

  • web.xml中启用BASIC认证:
<login-config>
    <auth-method>BASIC</auth-method>
</login-config>
  • standalone.xml中为标准安全域配置,禁用OIDC配置后BASIC认证可恢复正常。

解决方案

要同时保留OIDC和BASIC认证功能,需确保ApplicationDomain对应的HTTP认证机制被正确注册,并为myservlet.war明确绑定该安全域:

1. 确认Elytron中ApplicationDomain的HTTP认证工厂配置

检查standalone.xml的elytron子系统,确保ApplicationDomain关联了支持BASIC认证的HTTP认证工厂:

<elytron xmlns="urn:wildfly:elytron:15.0">
    <!-- 确保ApplicationDomain安全域存在 -->
    <security-domain name="ApplicationDomain" default-realm="ApplicationRealm" permission-mapper="default-permission-mapper">
        <realm name="ApplicationRealm" role-decoder="groups-to-roles"/>
    </security-domain>

    <!-- 配置支持BASIC的HTTP认证工厂 -->
    <http-authentication-factory name="application-http-auth-factory" security-domain="ApplicationDomain" http-server-mechanism-factory="global">
        <mechanism-configuration>
            <mechanism name="BASIC"/>
        </mechanism-configuration>
    </http-authentication-factory>
</elytron>

2. 为myservlet.war绑定专属安全域配置

在undertow子系统中,为myservlet.war单独配置安全域绑定,指定使用上述HTTP认证工厂:

<subsystem xmlns="urn:jboss:domain:undertow:12.0">
    <server name="default-server">
        <host name="default-host" alias="localhost">
            <!-- 为myservlet.war绑定ApplicationDomain的认证配置 -->
            <application-security-domain name="ApplicationDomain" http-authentication-factory="application-http-auth-factory" for-war="myservlet.war"/>
        </host>
    </server>
</subsystem>

3. 保留OIDC的专属作用范围

原OIDC配置中secure-deployment的name="myRest.war"已确保仅作用于该WAR,无需修改。

4. 验证配置

重启Wildfly后,访问myservlet.war的资源会触发BASIC认证,访问myRest.war的资源则走OIDC认证流程,二者可正常共存。

内容的提问来源于stack exchange,提问作者Georg Raffer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 14:42:07