You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS ALB后的Wildfly服务器Basic Authentication失效求助

问题:AWS ALB 后 Wildfly 的 Basic Authentication 认证失败

我为 REST API 部署了 Basic Authentication 认证,本地运行完全正常,但将服务器部署在 AWS Application Load Balancer(ALB)之后,用户无法完成认证。已经尝试在 ALB 上设置粘性会话,问题仍未解决。使用的 Wildfly 版本为 25.0.0,采用 Elytron Security。

相关配置文件

jboss-web.xml

<?xml version="1.0" encoding="UTF-8"?> 
<jboss-web version="8.0" xmlns="http://www.jboss.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.jboss.org/schema/jbossas http://www.jboss.com/xml/ns/javaee http://www.jboss.org/schema/jbossas/jboss-web_8_0.xsd">     
    <context-root>/kycVerification</context-root>     
    <security-domain flushOnSessionInvalidation="true">kyc</security-domain>     
    <security-domain flushOnSessionInvalidation="true">kycApi</security-domain> 
</jboss-web>

web.xml

<servlet-mapping>
    <servlet-name>javax.ws.rs.core.Application</servlet-name>
    <url-pattern>/rest/*</url-pattern>
</servlet-mapping>
<session-config>
    <session-timeout>5</session-timeout>
    <cookie-config>
        <name>__Securepg</name>
        <http-only>true</http-only>
        <secure>true</secure>
    </cookie-config>
    <tracking-mode>COOKIE</tracking-mode>
</session-config>

<security-constraint>
    <web-resource-collection>
        <web-resource-name>rest</web-resource-name>
        <description>Security KycClientGatewayApi</description>
        <url-pattern>/rest/*</url-pattern>
        <http-method>GET</http-method>
        <http-method>POST</http-method>
        <http-method>TRACE</http-method>
        <http-method>HEAD</http-method>
        <http-method>DELETE</http-method>
        <http-method>CONNECT</http-method>
        <http-method>OPTIONS</http-method>
        <http-method>PUT</http-method>
    </web-resource-collection>
    <auth-constraint>
        <role-name>*</role-name>
    </auth-constraint>
</security-constraint>
<security-constraint>
    <web-resource-collection>
        <web-resource-name>WEB-INF</web-resource-name>
        <url-pattern>/WEB-INF/*</url-pattern>
    </web-resource-collection>
    <auth-constraint>
    </auth-constraint>
</security-constraint>
<login-config>
    <auth-method>BASIC</auth-method>
    <realm-name>kycApi</realm-name>
</login-config>
<security-role>
    <role-name>APIUSER</role-name>
</security-role>

解决思路及步骤

  1. 检查 ALB 头部转发配置
    确认 ALB 监听器规则未移除 Authorization 头部。若 ALB 使用 HTTPS 监听、后端 Wildfly 使用 HTTP,需开启 ALB 的 X-Forwarded-Proto 头部转发——因为你的 Cookie 配置了 <secure>true</secure>,只有浏览器识别到请求为 HTTPS 时才会携带该 Cookie,后端需要通过代理头部识别真实请求协议。

  2. 配置 Wildfly Elytron 信任代理头部
    在 Wildfly 的 standalone.xml/domain.xml 中添加支持代理头部的 HTTP 机制工厂,让 Elytron 识别 ALB 转发的真实请求信息:

    <http-server-mechanism-factory name="trust-proxy">
        <mechanism-configuration>
            <mechanism name="BASIC">
                <mechanism-realm realm-name="kycApi"/>
            </mechanism>
        </mechanism-configuration>
        <proxy-options>
            <trust-x-forwarded-proto/>
            <trust-x-forwarded-for/>
        </proxy-options>
    </http-server-mechanism-factory>
    

    并在 kycApi 安全域中引用该工厂:

    <security-domain name="kycApi" default-realm="kycApi" permission-mapper="default-permission-mapper">
        <authentication>
            <http-mechanism-factory name="trust-proxy"/>
            <login-module name="UsersRoles" code="org.wildfly.security.auth.realm.users.UsersRolesLoginModule" flag="required">
                <module-option name="usersProperties" value="${jboss.server.config.dir}/kycApi-users.properties"/>
                <module-option name="rolesProperties" value="${jboss.server.config.dir}/kycApi-roles.properties"/>
            </login-module>
        </authentication>
    </security-domain>
    
  3. 修正 jboss-web.xml 的重复配置
    你的 jboss-web.xml 中重复声明了 <security-domain>,会导致配置冲突,保留 API 对应的 kycApi 即可:

    <jboss-web version="8.0" xmlns="http://www.jboss.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.jboss.org/schema/jbossas http://www.jboss.com/xml/ns/javaee http://www.jboss.org/schema/jbossas/jboss-web_8_0.xsd">     
        <context-root>/kycVerification</context-root>     
        <security-domain flushOnSessionInvalidation="true">kycApi</security-domain> 
    </jboss-web>
    
  4. 开启 Wildfly 连接器的代理地址转发
    若 ALB 转发到 Wildfly 的 HTTP 端口,需在 Undertow 连接器中开启 proxy-address-forwarding,让后端识别真实客户端地址和协议:

    <subsystem xmlns="urn:jboss:domain:undertow:12.0" default-server="default-server" default-virtual-host="default-host" default-servlet-container="default" default-security-domain="other">
        <server name="default-server">
            <http-listener name="default" socket-binding="http" proxy-address-forwarding="true"/>
            <!-- 其他配置 -->
        </server>
    </subsystem>
    

内容的提问来源于stack exchange,提问作者Tushal Joggesser

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 04:15:45