You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wildfly 27重定向登录返回SEND_CONTINUE及匿名主体问题

登录页重定向/转发时认证返回SEND_CONTINUE的问题

使用Wildfly 27.0.1,基于Jakarta命名空间开发,遇到如下认证异常问题:

相关配置

ApplicationConfig.java

@CustomFormAuthenticationMechanismDefinition(loginToContinue =         
@LoginToContinue(loginPage = "/login.xhtml", useForwardToLogin = true))
@FacesConfig
@ApplicationScoped
public class ApplicationConfig {
}

web.xml

<security-constraint>
    <web-resource-collection>
        <web-resource-name>index</web-resource-name>
        <url-pattern>/index.xhtml</url-pattern>
    </web-resource-collection>
    <auth-constraint>
        <role-name>ADMINISTRATOR</role-name>
        <role-name>USER</role-name>
    </auth-constraint>
</security-constraint>

LoginBacking.java

public void login() throws IOException {
    switch (continueAuthentication()) {
    case SEND_CONTINUE:
        facesContext.responseComplete();
        break;
    case SEND_FAILURE:
        facesContext.addMessage(null, new FacesMessage(FacesMessage.SEVERITY_ERROR, "Login failed", null));
        break;
    case SUCCESS:
        facesContext.addMessage(null, new FacesMessage(FacesMessage.SEVERITY_INFO, "Login succeeded", null));
        externalContext.redirect(externalContext.getRequestContextPath() + "/index.xhtml");
        break;
    case NOT_DONE:
        facesContext.addMessage(null, new FacesMessage(FacesMessage.SEVERITY_ERROR, "Login failed", null));
        break;
    }
}

private AuthenticationStatus continueAuthentication() {
    return securityContext.authenticate((HttpServletRequest) externalContext.getRequest(),
            (HttpServletResponse) externalContext.getResponse(),
            AuthenticationParameters.withParams().credential(new UsernamePasswordCredential(username, password)));
}

现象说明

  • 认证依赖JSR-375身份存储,该存储的调用和返回均正常
  • 访问受保护的index.xhtml跳转至登录页时,调用securityContext.authenticate()始终返回SEND_CONTINUE;直接访问login.xhtml登录时,认证正常返回SUCCESS
  • 认证后SecurityContext.getCallerPrincipal不为null,但为AnonymousCallerPrincipal实例,而非身份存储返回的调用者主体
  • 该行为与useForwardToLogin的设置无关,且未配置多部分认证

求相关解决方案或最新思路?

内容的提问来源于stack exchange,提问作者Dominic Hilsbos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 17:23:25