Ory Oathkeeper访问规则中的正则URL无法匹配问题求助
Ory Oathkeeper规则匹配异常:kratos规则正常但自定义规则失效
我使用Ory Oathkeeper已有一段时间,两个月前一切正常,但重新使用后出现异常。我拥有oathkeeper.yml、kratos.json和rules.json三个配置文件,Oathkeeper配置已正确指定kratos和rules规则文件,kratos.json中的规则可正常工作,但rules.json中的访问规则完全失效。
通过CLI命令oathkeeper rules list已确认两个文件的访问规则均被加载,这让我认为问题并非规则本身,但将正则表达式放到regexr等在线测试工具中显示可正常匹配。我猜测可能是Oathkeeper使用的Go库出现问题,或是我的JSON配置有误。
配置文件内容
kratos.json
[ { "id": "ory:kratos:public", "upstream": { "preserve_host": true, "url": "http://kratos:4433", "strip_path": "/.ory/kratos/public" }, "match": { "url": "<(http|https):\\/\\/([\\w-]+(\\.[\\w-]+)*|[\\d.]+)(:\\d+)?\\/\\.ory\\/kratos\\/public(\\/.*)?>", "methods": ["GET", "POST" ,"PUT", "DELETE", "PATCH"] }, "authenticators": [{ "handler": "noop" }], "authorizer": { "handler": "allow" }, "mutators": [{ "handler": "noop" }] } ]
rules.json
[ { "id": "fusion:account:protected", "upstream": { "preserve_host": true, "url": "http://host.docker.internal:80", "strip_path": "/api/account" }, "match": { "url": "<(http|https):\\/\\/([\\w-]+(\\.[\\w-]+)*|[\\d.]+)(:\\d+)?\\/api\\/account(\\/.*)?>", "methods": ["GET", "POST" ,"PUT", "DELETE", "PATCH"] }, "authenticators": [{ "handler": "cookie_session" }, { "handler": "oauth2_introspection" }, { "handler": "anonymous" }], "authorizer": { "handler": "allow" }, "mutators": [{ "handler": "id_token" }], "errors": [{ "handler": "json" }] } ]
oathkeeper.yml
serve: proxy: port: 4455 # run the proxy at port 4455 api: port: 4456 # run the api at port 4456 access_rules: matching_strategy: regexp repositories: - file:///etc/config/oathkeeper/rules.json - file:///etc/config/oathkeeper/kratos.json log: level: debug format: text leak_sensitive_values: true errors: fallback: - json handlers: json: enabled: true config: verbose: true redirect: enabled: true config: to: https://www.ory.sh/docs mutators: header: enabled: true config: headers: X-User: "{{ print .Subject }}" noop: enabled: true id_token: enabled: true config: issuer_url: http://localhost:4455/ jwks_url: file:///etc/config/oathkeeper/jwks.json claims: '{"scope":"{{ .Extra.scope }}"}' authorizers: allow: enabled: true deny: enabled: true remote_json: enabled: true config: remote: http://keto:4466/check forward_response_headers_to_upstream: [] payload: | { "namespace": "...", "subject": "...", "object": "...", "relation": "..." } authenticators: noop: enabled: true cookie_session: enabled: true config: check_session_url: http://kratos:4433/sessions/whoami preserve_path: true extra_from: "@this" subject_from: "identity.id" only: - ory_kratos_session anonymous: enabled: true config: subject: guest oauth2_introspection: enabled: true config: introspection_url: http://hydra:4445/oauth2/introspect
尝试操作与错误信息
我尝试在配置中硬编码URL,但同样无效,访问http://localhost:4455/test时仍收到如下错误响应:
{ "error": { "code": 404, "status": "Not Found", "message": "Requested url does not match any rules" } }
内容的提问来源于stack exchange,提问作者Kieron Wiltshire
相关产品推荐
相关产品推荐

