如何让WSO2 APIM 4.1网关认可迁移的旧Opaque Access Token
背景
从WSO2 APIM 2.6版本迁移至4.1版本(部署架构为单Gateway-worker+单Control-plane),需复用已部署在移动应用中的旧access token——该令牌为无限有效期,无法重新生成并重新部署移动应用。
目前已在4.1版本中创建对应API,采用Opaque token认证方式,新生成的Opaque token可正常调用API,仅替换为旧令牌时出现验证失败。
已执行操作
- 更新数据库令牌:执行SQL语句修改
IDN_OAUTH2_ACCESS_TOKEN表中的令牌值及哈希:UPDATE "IDN_OAUTH2_ACCESS_TOKEN" SET ACCESS_TOKEN = '64a84d453e9259d2104210035d8436f4', ACCESS_TOKEN_HASH = '{"hash":"4cf7cd7f4ddc89b9900554bcf8e3ca71c605c59b278b3996a330f1fd4a3ff372","algorithm":"SHA-256"}' WHERE ROWID = 'xxx' - 清除缓存:重启网关以清除令牌缓存
- 禁用缓存测试:临时配置禁用相关令牌缓存:
[apim.cache.gateway_token] enable = false [apim.cache.km_token] enable = false [apim.cache.restapi_token] enable = false - 验证密钥管理器返回:调用令牌接口时,密钥管理器可正确返回旧令牌:
返回结果:curl -k -X POST https://my-keymanager.dev/oauth2/token -d "grant_type=client_credentials" -H"Authorization: Basic XXXXX"{"access_token":"64a84d453e9259d2104210035d8436f4","scope":"default","token_type":"Bearer","expires_in":xxx}
问题现象
使用旧令牌调用API时,始终返回900901无效凭据错误:
调用命令:
curl -k -X GET "https://my-gateway.dev/test-api/32155" -H "accept: application/json" -H "Authorization: Bearer 64a84d453e9259d2104210035d8436f4"
错误响应:
{"code":"900901","message":"Invalid Credentials","description":"Access failure for API: /my-Api/v2.0.0, version: v2.0.0 status: (900901) - Invalid Credentials. Make sure you have provided the correct security credentials"}
网关DEBUG日志:
DEBUG {org.wso2.carbon.apimgt.gateway.handlers.security.APIAuthenticationHandler} - API authentication failed with error 900901 org.wso2.carbon.apimgt.gateway.handlers.security.APISecurityException: Access failure for API: /eQuilibre/v2.0.0, version: v2.0.0 status: (900901) - Invalid Credentials
at org.wso2.carbon.apimgt.gateway.handlers.security.APIAuthenticationHandler.isAuthenticate_aroundBody56(APIAuthenticationHandler.java:536)
at org.wso2.carbon.apimgt.gateway.handlers.security.APIAuthenticationHandler.isAuthenticate(APIAuthenticationHandler.java:516)
at org.wso2.carbon.apimgt.gateway.handlers.security.APIAuthenticationHandler.handleRequest_aroundBody46(APIAuthenticationHandler.java:402)
at org.wso2.carbon.apimgt.gateway.handlers.security.APIAuthenticationHandler.handleRequest(APIAuthenticationHandler.java:353)
at org.apache.synapse.api.API.process(API.java:403)
推测网关并未请求密钥管理器验证该旧令牌,遗漏了关键配置或操作步骤,请问如何让网关接受该旧令牌?
补充说明
- 采用WSO2 APIM 4.1的Opaque token认证机制
- 从2.6版本迁移,其他使用Opaque token的版本可能存在相同问题,核心需求为迁移令牌值
内容的提问来源于stack exchange,提问作者SpikeeJu

