Wildfly 26.1.3启用OIDC后BASIC认证失效(ELY06017)的解决咨询
Wildfly 26.1.3启用OIDC后BASIC认证失效问题解决
环境与应用结构
- 部署环境:Wildfly 26.1.3
- 部署应用:
myapp.ear,包含三个模块:myservlet.war:通过web.xml配置BASIC认证,依赖ApplicationDomain安全域myRest.war:基于wildfly:elytron-oidc-client:1.0+ Keycloak实现OIDC认证myServices.jar:包含EJB与实体类
问题现象
启用OIDC前,myservlet.war的BASIC认证正常工作;启用OIDC后,OIDC认证功能正常,但myservlet.war的BASIC认证失效,抛出HTTP 500内部服务器错误,错误信息如下:
org.wildfly.security.http.HttpAuthenticationException: ELY06017: HTTP authentication is required but no authentication mechansims are available. at: org.wildfly.security.http.HttpAuthenticator$AuthenticationExchange.authenticate(HttpAuthenticator.java:317)
根据文档说明,OIDC子系统会自动创建安全域,导致原有ApplicationDomain安全域无法被正常调用,需求是重新激活原有标准安全域ApplicationDomain,同时保留OIDC认证功能。
相关配置
OIDC子系统配置(standalone.xml)
<subsystem xmlns="urn:wildfly:elytron-oidc-client:1.0"> <secure-deployment name="myRest.war"> <auth-server-url>https://auth.sample.com/auth</auth-server-url> <ssl-required>ALL</ssl-required> <realm>myRealm</realm> <resource>myResource</resource> <credential name="secret" secret="mySecret"/> </secure-deployment> </subsystem>
BASIC认证配置
web.xml中启用BASIC认证:
<login-config> <auth-method>BASIC</auth-method> </login-config>
standalone.xml中为标准安全域配置,禁用OIDC配置后BASIC认证可恢复正常。
解决方案
要同时保留OIDC和BASIC认证功能,需确保ApplicationDomain对应的HTTP认证机制被正确注册,并为myservlet.war明确绑定该安全域:
1. 确认Elytron中ApplicationDomain的HTTP认证工厂配置
检查standalone.xml的elytron子系统,确保ApplicationDomain关联了支持BASIC认证的HTTP认证工厂:
<elytron xmlns="urn:wildfly:elytron:15.0"> <!-- 确保ApplicationDomain安全域存在 --> <security-domain name="ApplicationDomain" default-realm="ApplicationRealm" permission-mapper="default-permission-mapper"> <realm name="ApplicationRealm" role-decoder="groups-to-roles"/> </security-domain> <!-- 配置支持BASIC的HTTP认证工厂 --> <http-authentication-factory name="application-http-auth-factory" security-domain="ApplicationDomain" http-server-mechanism-factory="global"> <mechanism-configuration> <mechanism name="BASIC"/> </mechanism-configuration> </http-authentication-factory> </elytron>
2. 为myservlet.war绑定专属安全域配置
在undertow子系统中,为myservlet.war单独配置安全域绑定,指定使用上述HTTP认证工厂:
<subsystem xmlns="urn:jboss:domain:undertow:12.0"> <server name="default-server"> <host name="default-host" alias="localhost"> <!-- 为myservlet.war绑定ApplicationDomain的认证配置 --> <application-security-domain name="ApplicationDomain" http-authentication-factory="application-http-auth-factory" for-war="myservlet.war"/> </host> </server> </subsystem>
3. 保留OIDC的专属作用范围
原OIDC配置中secure-deployment的name="myRest.war"已确保仅作用于该WAR,无需修改。
4. 验证配置
重启Wildfly后,访问myservlet.war的资源会触发BASIC认证,访问myRest.war的资源则走OIDC认证流程,二者可正常共存。
内容的提问来源于stack exchange,提问作者Georg Raffer
相关产品推荐
相关产品推荐

