You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ory Oathkeeper访问规则中的正则URL无法匹配问题求助

Ory Oathkeeper规则匹配异常:kratos规则正常但自定义规则失效

我使用Ory Oathkeeper已有一段时间,两个月前一切正常,但重新使用后出现异常。我拥有oathkeeper.yml、kratos.json和rules.json三个配置文件,Oathkeeper配置已正确指定kratos和rules规则文件,kratos.json中的规则可正常工作,但rules.json中的访问规则完全失效。

通过CLI命令oathkeeper rules list已确认两个文件的访问规则均被加载,这让我认为问题并非规则本身,但将正则表达式放到regexr等在线测试工具中显示可正常匹配。我猜测可能是Oathkeeper使用的Go库出现问题,或是我的JSON配置有误。

配置文件内容

kratos.json

[
  {
    "id": "ory:kratos:public",
    "upstream": {
      "preserve_host": true,
      "url": "http://kratos:4433",
      "strip_path": "/.ory/kratos/public"
    },
    "match": {
      "url": "<(http|https):\\/\\/([\\w-]+(\\.[\\w-]+)*|[\\d.]+)(:\\d+)?\\/\\.ory\\/kratos\\/public(\\/.*)?>",
      "methods": ["GET", "POST" ,"PUT", "DELETE", "PATCH"]
    },
    "authenticators": [{
      "handler": "noop"
    }],
    "authorizer": {
      "handler": "allow"
    },
    "mutators": [{
      "handler": "noop"
    }]
  }
]

rules.json

[
  {
    "id": "fusion:account:protected",
    "upstream": {
      "preserve_host": true,
      "url": "http://host.docker.internal:80",
      "strip_path": "/api/account"
    },
    "match": {
      "url": "<(http|https):\\/\\/([\\w-]+(\\.[\\w-]+)*|[\\d.]+)(:\\d+)?\\/api\\/account(\\/.*)?>",
      "methods": ["GET", "POST" ,"PUT", "DELETE", "PATCH"]
    },
    "authenticators": [{
      "handler": "cookie_session"
    }, {
      "handler": "oauth2_introspection"
    }, {
      "handler": "anonymous"
    }],
    "authorizer": {
      "handler": "allow"
    },
    "mutators": [{
      "handler": "id_token"
    }],
    "errors": [{
      "handler": "json"
    }]
  }
]

oathkeeper.yml

serve:
  proxy:
    port: 4455 # run the proxy at port 4455
  api:
    port: 4456 # run the api at port 4456

access_rules:
  matching_strategy: regexp
  repositories:
    - file:///etc/config/oathkeeper/rules.json
    - file:///etc/config/oathkeeper/kratos.json

log:
  level: debug
  format: text
  leak_sensitive_values: true

errors:
  fallback:
    - json
  handlers:
    json:
      enabled: true
      config:
        verbose: true
    redirect:
      enabled: true
      config:
        to: https://www.ory.sh/docs

mutators:
  header:
    enabled: true
    config:
      headers:
        X-User: "{{ print .Subject }}"
  noop:
    enabled: true
  id_token:
    enabled: true
    config:
      issuer_url: http://localhost:4455/
      jwks_url: file:///etc/config/oathkeeper/jwks.json
      claims: '{"scope":"{{ .Extra.scope }}"}'

authorizers:
  allow:
    enabled: true
  deny:
    enabled: true
  remote_json:
    enabled: true
    config:
      remote: http://keto:4466/check
      forward_response_headers_to_upstream: []
      payload: |
        {
            "namespace": "...",
            "subject": "...",
            "object": "...",
            "relation": "..."
        }

authenticators:
  noop:
    enabled: true
  cookie_session:
    enabled: true
    config:
      check_session_url: http://kratos:4433/sessions/whoami
      preserve_path: true
      extra_from: "@this"
      subject_from: "identity.id"
      only:
        - ory_kratos_session
  anonymous:
    enabled: true
    config:
      subject: guest
  oauth2_introspection:
    enabled: true
    config:
      introspection_url: http://hydra:4445/oauth2/introspect

尝试操作与错误信息

我尝试在配置中硬编码URL,但同样无效,访问http://localhost:4455/test时仍收到如下错误响应:

{
  "error": {
    "code": 404,
    "status": "Not Found",
    "message": "Requested url does not match any rules"
  }
}

内容的提问来源于stack exchange,提问作者Kieron Wiltshire

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 20:54:55