AWS ALB后的Wildfly服务器Basic Authentication失效求助
我为 REST API 部署了 Basic Authentication 认证,本地运行完全正常,但将服务器部署在 AWS Application Load Balancer(ALB)之后,用户无法完成认证。已经尝试在 ALB 上设置粘性会话,问题仍未解决。使用的 Wildfly 版本为 25.0.0,采用 Elytron Security。
相关配置文件
jboss-web.xml
<?xml version="1.0" encoding="UTF-8"?> <jboss-web version="8.0" xmlns="http://www.jboss.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.jboss.org/schema/jbossas http://www.jboss.com/xml/ns/javaee http://www.jboss.org/schema/jbossas/jboss-web_8_0.xsd"> <context-root>/kycVerification</context-root> <security-domain flushOnSessionInvalidation="true">kyc</security-domain> <security-domain flushOnSessionInvalidation="true">kycApi</security-domain> </jboss-web>
web.xml
<servlet-mapping> <servlet-name>javax.ws.rs.core.Application</servlet-name> <url-pattern>/rest/*</url-pattern> </servlet-mapping> <session-config> <session-timeout>5</session-timeout> <cookie-config> <name>__Securepg</name> <http-only>true</http-only> <secure>true</secure> </cookie-config> <tracking-mode>COOKIE</tracking-mode> </session-config> <security-constraint> <web-resource-collection> <web-resource-name>rest</web-resource-name> <description>Security KycClientGatewayApi</description> <url-pattern>/rest/*</url-pattern> <http-method>GET</http-method> <http-method>POST</http-method> <http-method>TRACE</http-method> <http-method>HEAD</http-method> <http-method>DELETE</http-method> <http-method>CONNECT</http-method> <http-method>OPTIONS</http-method> <http-method>PUT</http-method> </web-resource-collection> <auth-constraint> <role-name>*</role-name> </auth-constraint> </security-constraint> <security-constraint> <web-resource-collection> <web-resource-name>WEB-INF</web-resource-name> <url-pattern>/WEB-INF/*</url-pattern> </web-resource-collection> <auth-constraint> </auth-constraint> </security-constraint> <login-config> <auth-method>BASIC</auth-method> <realm-name>kycApi</realm-name> </login-config> <security-role> <role-name>APIUSER</role-name> </security-role>
解决思路及步骤
检查 ALB 头部转发配置
确认 ALB 监听器规则未移除Authorization头部。若 ALB 使用 HTTPS 监听、后端 Wildfly 使用 HTTP,需开启 ALB 的X-Forwarded-Proto头部转发——因为你的 Cookie 配置了<secure>true</secure>,只有浏览器识别到请求为 HTTPS 时才会携带该 Cookie,后端需要通过代理头部识别真实请求协议。配置 Wildfly Elytron 信任代理头部
在 Wildfly 的 standalone.xml/domain.xml 中添加支持代理头部的 HTTP 机制工厂,让 Elytron 识别 ALB 转发的真实请求信息:<http-server-mechanism-factory name="trust-proxy"> <mechanism-configuration> <mechanism name="BASIC"> <mechanism-realm realm-name="kycApi"/> </mechanism> </mechanism-configuration> <proxy-options> <trust-x-forwarded-proto/> <trust-x-forwarded-for/> </proxy-options> </http-server-mechanism-factory>并在
kycApi安全域中引用该工厂:<security-domain name="kycApi" default-realm="kycApi" permission-mapper="default-permission-mapper"> <authentication> <http-mechanism-factory name="trust-proxy"/> <login-module name="UsersRoles" code="org.wildfly.security.auth.realm.users.UsersRolesLoginModule" flag="required"> <module-option name="usersProperties" value="${jboss.server.config.dir}/kycApi-users.properties"/> <module-option name="rolesProperties" value="${jboss.server.config.dir}/kycApi-roles.properties"/> </login-module> </authentication> </security-domain>修正 jboss-web.xml 的重复配置
你的 jboss-web.xml 中重复声明了<security-domain>,会导致配置冲突,保留 API 对应的kycApi即可:<jboss-web version="8.0" xmlns="http://www.jboss.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.jboss.org/schema/jbossas http://www.jboss.com/xml/ns/javaee http://www.jboss.org/schema/jbossas/jboss-web_8_0.xsd"> <context-root>/kycVerification</context-root> <security-domain flushOnSessionInvalidation="true">kycApi</security-domain> </jboss-web>开启 Wildfly 连接器的代理地址转发
若 ALB 转发到 Wildfly 的 HTTP 端口,需在 Undertow 连接器中开启proxy-address-forwarding,让后端识别真实客户端地址和协议:<subsystem xmlns="urn:jboss:domain:undertow:12.0" default-server="default-server" default-virtual-host="default-host" default-servlet-container="default" default-security-domain="other"> <server name="default-server"> <http-listener name="default" socket-binding="http" proxy-address-forwarding="true"/> <!-- 其他配置 --> </server> </subsystem>
内容的提问来源于stack exchange,提问作者Tushal Joggesser

