WSO2 Identity Server 5.7.0 SMS OTP配置问题及API触发咨询
WSO2 Identity Server 5.7.0 SMS OTP配置问题及扩展咨询
配置问题说明
在WSO2 IS 5.7.0里按官方文档配置SMS OTP(用Nexmo当短信提供商,Postman调用API能正常发消息)时,碰到三个问题:
- 用户profile页面的「disable otp sms」显示成文本框,不是复选框
- 登录时页面直接跳回登录页,没法完成认证
- 没有手机号的用户,在更新信息页面会报错
相关错误日志
日志片段1
TID: [-1234] [] [2023-04-20 13:47:13,962] WARN {org.apache.cxf.phase.PhaseInterceptorChain} - Interceptor for {http://authz.endpoint.oauth.identity.carbon.wso2.org/}OAuth2AuthzEndpoint has thrown exception, unwinding now org.apache.cxf.interceptor.Fault: Could not send Message. at org.apache.cxf.interceptor.MessageSenderInterceptor$MessageSenderEndingInterceptor.handleMessage(MessageSenderInterceptor.java:64) Caused by: org.apache.catalina.connector.ClientAbortException: java.io.IOException: Broken pipe at org.apache.catalina.connector.OutputBuffer.doFlush(OutputBuffer.java:370)
日志片段2
Caused by: org.wso2.carbon.identity.authenticator.smsotp.exception.SMSOTPException: User does not exist in the User Store. at org.wso2.carbon.identity.authenticator.smsotp.SMSOTPUtils.verifyUserExists(SMSOTPUtils.java:150) TID: [-1234] [] [2023-04-20 13:46:09,025] ERROR {org.wso2.carbon.identity.application.authentication.framework.handler.step.impl.DefaultStepHandler} - Failed to get the parameters from authentication xml file. org.wso2.carbon.identity.application.authentication.framework.exception.AuthenticationFailedException: Failed to get the parameters from authentication xml file. at org.wso2.carbon.identity.authenticator.smsotp.SMSOTPAuthenticator.initiateAuthenticationRequest(SMSOTPAuthenticator.java:164)
问题解决方法
1. 「disable otp sms」显示为文本框的问题
这是5.7.0版本的UI属性配置问题,改一下配置文件就行:
- 找到
<IS_HOME>/repository/conf/identity/identity-mgt.properties文件 - 检查有没有
Identity.Management.User.Profile.Attribute.DisableSMSOTP=boolean这行,没有就加上 - 重启服务器,刷新页面就能看到复选框了
2. 登录重定向回登录页的问题
结合日志里的错误提示,按下面步骤排查:
- 打开
<IS_HOME>/repository/conf/identity/application-authentication.xml,检查SMS OTP认证器的配置,确保所有必填参数(比如Nexmo的API密钥、用户存储域)都填对了 - 确认认证器里的
<Parameter name="UserStoreDomain">值和你用的用户存储域一致(默认是PRIMARY) - 检查登录的用户是否真的存在于指定的用户存储域里,而且用户的手机号属性已经正确配置
3. 无手机号用户更新页面报错的问题
这是因为SMS OTP认证器默认要求用户必须有手机号,改配置关掉强制校验:
- 打开
<IS_HOME>/repository/conf/identity/identity-mgt.properties - 添加或修改
Identity.Management.User.Profile.Attribute.Mobile.Required=false,把手机号设为非必填 - 重启服务器后,无手机号的用户就能正常更新信息了
登录场景外触发SMS OTP的实现方法
5.7.0的官方文档没写这个功能,但可以通过以下几种方式实现:
方法1:自定义REST API扩展
自己写一个API端点,调用WSO2的SMS OTP工具类来生成并发送验证码:
- 先通过用户管理API获取目标用户的信息,确认手机号存在
- 在自定义API里调用
SMSOTPUtils.generateOTP()生成验证码,再调用SMSOTPUtils.sendOTP()发送到用户手机
方法2:事件处理器扩展
利用WSO2的事件框架,在特定业务事件触发时自动发SMS OTP:
- 写一个自定义事件处理器,监听比如用户密码重置、账户激活这类事件
- 处理器里调用SMS OTP相关工具类,自动生成并发送验证码
方法3:独立认证流程
在Identity Server里创建一个不依赖登录的独立认证流程,专门用来触发SMS OTP发送:
- 用认证框架的扩展点,定义一个只包含SMS OTP发送步骤的流程
- 前端直接调用这个流程的端点,就能触发验证码发送
内容的提问来源于stack exchange,提问作者user666
相关产品推荐
相关产品推荐

