You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenLiberty授权失败:用户bob无admin角色访问权限

权限授权失败排查:用户bob无法访问/admin路径

我跟着OpenLiberty安全入门教程开发小型应用,输入正确用户名密码登录后,访问/admin路径时出现错误:

Authorization failed for user bob while invoking ServletsJspExperiments on /admin. The user is not granted access to any of the required roles: [admin]

提供的配置与日志

Servlet代码

@FormAuthenticationMechanismDefinition(
        loginToContinue = @LoginToContinue(errorPage = "/error.html",
                loginPage = "/login.html"))
@ServletSecurity(value = @HttpConstraint(rolesAllowed = { "user", "admin" },
        transportGuarantee = ServletSecurity.TransportGuarantee.CONFIDENTIAL))
public class AdminServlet extends HttpServlet {

    @Inject
    private SecurityContext securityContext;

    @Override
    protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
        System.out.println("Inside doGet AdminServlet");
        if (securityContext.isCallerInRole("admin")) {
//            resp.sendRedirect("/admin.jsf");
            resp.getWriter().println("You are in admin page");
        }
    }
}

server.xml配置

<featureManager>
        <feature>appSecurity-4.0</feature>

        <feature>servlet-5.0</feature>

        <!-- needed to run JSP examples -->
        <feature>pages-3.0</feature>

        <!-- needed to make JDBC calls -->
        <feature>jdbc-4.3</feature>

        <!-- for TLS -->
        <feature>transportSecurity-1.0</feature>
    </featureManager>

  ....

    <include location="userRegistry.xml"/>

    <webApplication location="ServletExperiments.war" contextRoot="${app.context.root}">

        <application-bnd>
            <security-role name="admin">
                <user name="bob" />
            </security-role>
        </application-bnd>
    </webApplication>

userRegistry.xml配置

<server description="Sample Liberty server">
    <basicRegistry id="basic" realm="WebRealm">
        <user name="bob"
              password="{xor}PTA9Lyg7" /> <!-- bobpwd -->
    </basicRegistry>
</server>

web.xml相关配置

<!-- SECURITY ROLES -->
<security-role>
    <role-name>admin</role-name>
</security-role>

<security-constraint>
    <web-resource-collection>
        <web-resource-name>AdminViewProperties</web-resource-name>
        <url-pattern>/admin</url-pattern>
        <http-method>GET</http-method>
    </web-resource-collection>
    <auth-constraint>
        <role-name>admin</role-name>
    </auth-constraint>
</security-constraint>

登录时的日志(中文翻译)

[1/12/23, 17:13:20:637 EET] 0000002b com.ibm.ws.security.token.internal.TokenManagerImpl          I CWWKS4001I: 安全令牌无法验证,可能原因如下:
1. 安全令牌由另一台使用不同密钥的服务器生成。
2. 创建令牌的令牌服务的配置或安全密钥已更改。
3. 创建令牌的令牌服务已不可用。
[1/12/23, 17:13:20:642 EET] 0000002b com.ibm.ws.security.jaspi.JaspiServiceImpl                   I CWWKS1652A: 针对Web请求/ServletsJspExperiments/admin的身份验证失败,状态为AuthStatus.SEND_CONTINUE。用户定义的Java身份验证SPI容器(JASPIC)服务null判定身份验证数据无效。
[1/12/23, 17:13:25:136 EET] 0000003a com.ibm.ws.security.javaeesec.cdi.beans.Utils                I CWWKS1930I: 未找到配置的IdentityStore对象。如果已配置用户注册表,则将改用它。如果必须使用IdentityStore对象,请确保其配置正确。
[1/12/23, 17:13:25:170 EET] 0000003f y.authorization.builtin.internal.BuiltinAuthorizationService I CWWKS2104I: 将使用与访问资源所需角色名称匹配的用户组名称,对应用ServletsJspExperiments中的资源做出授权决策。
[1/12/23, 17:13:25:171 EET] 0000003f .ibm.ws.webcontainer.security.WebAppSecurityCollaboratorImpl A CWWKS9104A: 用户bob调用ServletsJspExperiments的/admin路径时授权失败。该用户未被授予任何所需角色的访问权限:[admin]。

排查与解决方法

1. 检查应用角色绑定是否生效

从日志CWWKS2104I可以看出,当前授权决策是通过用户组名匹配角色名判断的,而非你在server.xml中配置的application-bnd。可能原因:

  • 确认server.xml中webApplication的location路径是否指向正确的ServletExperiments.war包,避免路径错误导致绑定配置未加载。
  • 检查war包内部是否存在ibm-web-bnd.xml文件,该文件的角色映射优先级高于server.xml,若存在需确保其正确配置了bob到admin角色的映射。

2. 统一权限配置方式

你的AdminServlet同时使用了@ServletSecurity注解和web.xml的security-constraint,两者权限规则存在差异(注解允许user/admin访问,web.xml仅允许admin)。建议保留一种配置方式:

  • 要么删除@ServletSecurity注解,仅通过web.xml控制权限;
  • 要么删除web.xml中的security-constraint,仅使用注解配置。

3. 清理无效令牌

日志开头的CWWKS4001I提示令牌验证失败,可能是旧会话残留导致:

  • 清除浏览器缓存和Cookie,重启OpenLiberty服务器后重新登录测试。

4. 验证用户注册表配置

虽然bob能登录,但可再次确认:

  • userRegistry.xml中bob的密码{xor}PTA9Lyg7对应明文bobpwd,确保登录时输入正确;
  • basicRegistry的realm名称WebRealm与应用配置的realm一致(默认值无需修改)。

内容的提问来源于stack exchange,提问作者Teshte

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 20:35:15