OpenLiberty授权失败:用户bob无admin角色访问权限
权限授权失败排查:用户bob无法访问/admin路径
我跟着OpenLiberty安全入门教程开发小型应用,输入正确用户名密码登录后,访问/admin路径时出现错误:
Authorization failed for user bob while invoking ServletsJspExperiments on /admin. The user is not granted access to any of the required roles: [admin]
提供的配置与日志
Servlet代码
@FormAuthenticationMechanismDefinition( loginToContinue = @LoginToContinue(errorPage = "/error.html", loginPage = "/login.html")) @ServletSecurity(value = @HttpConstraint(rolesAllowed = { "user", "admin" }, transportGuarantee = ServletSecurity.TransportGuarantee.CONFIDENTIAL)) public class AdminServlet extends HttpServlet { @Inject private SecurityContext securityContext; @Override protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException { System.out.println("Inside doGet AdminServlet"); if (securityContext.isCallerInRole("admin")) { // resp.sendRedirect("/admin.jsf"); resp.getWriter().println("You are in admin page"); } } }
server.xml配置
<featureManager> <feature>appSecurity-4.0</feature> <feature>servlet-5.0</feature> <!-- needed to run JSP examples --> <feature>pages-3.0</feature> <!-- needed to make JDBC calls --> <feature>jdbc-4.3</feature> <!-- for TLS --> <feature>transportSecurity-1.0</feature> </featureManager> .... <include location="userRegistry.xml"/> <webApplication location="ServletExperiments.war" contextRoot="${app.context.root}"> <application-bnd> <security-role name="admin"> <user name="bob" /> </security-role> </application-bnd> </webApplication>
userRegistry.xml配置
<server description="Sample Liberty server"> <basicRegistry id="basic" realm="WebRealm"> <user name="bob" password="{xor}PTA9Lyg7" /> <!-- bobpwd --> </basicRegistry> </server>
web.xml相关配置
<!-- SECURITY ROLES --> <security-role> <role-name>admin</role-name> </security-role> <security-constraint> <web-resource-collection> <web-resource-name>AdminViewProperties</web-resource-name> <url-pattern>/admin</url-pattern> <http-method>GET</http-method> </web-resource-collection> <auth-constraint> <role-name>admin</role-name> </auth-constraint> </security-constraint>
登录时的日志(中文翻译)
[1/12/23, 17:13:20:637 EET] 0000002b com.ibm.ws.security.token.internal.TokenManagerImpl I CWWKS4001I: 安全令牌无法验证,可能原因如下: 1. 安全令牌由另一台使用不同密钥的服务器生成。 2. 创建令牌的令牌服务的配置或安全密钥已更改。 3. 创建令牌的令牌服务已不可用。 [1/12/23, 17:13:20:642 EET] 0000002b com.ibm.ws.security.jaspi.JaspiServiceImpl I CWWKS1652A: 针对Web请求/ServletsJspExperiments/admin的身份验证失败,状态为AuthStatus.SEND_CONTINUE。用户定义的Java身份验证SPI容器(JASPIC)服务null判定身份验证数据无效。 [1/12/23, 17:13:25:136 EET] 0000003a com.ibm.ws.security.javaeesec.cdi.beans.Utils I CWWKS1930I: 未找到配置的IdentityStore对象。如果已配置用户注册表,则将改用它。如果必须使用IdentityStore对象,请确保其配置正确。 [1/12/23, 17:13:25:170 EET] 0000003f y.authorization.builtin.internal.BuiltinAuthorizationService I CWWKS2104I: 将使用与访问资源所需角色名称匹配的用户组名称,对应用ServletsJspExperiments中的资源做出授权决策。 [1/12/23, 17:13:25:171 EET] 0000003f .ibm.ws.webcontainer.security.WebAppSecurityCollaboratorImpl A CWWKS9104A: 用户bob调用ServletsJspExperiments的/admin路径时授权失败。该用户未被授予任何所需角色的访问权限:[admin]。
排查与解决方法
1. 检查应用角色绑定是否生效
从日志CWWKS2104I可以看出,当前授权决策是通过用户组名匹配角色名判断的,而非你在server.xml中配置的application-bnd。可能原因:
- 确认
server.xml中webApplication的location路径是否指向正确的ServletExperiments.war包,避免路径错误导致绑定配置未加载。 - 检查war包内部是否存在
ibm-web-bnd.xml文件,该文件的角色映射优先级高于server.xml,若存在需确保其正确配置了bob到admin角色的映射。
2. 统一权限配置方式
你的AdminServlet同时使用了@ServletSecurity注解和web.xml的security-constraint,两者权限规则存在差异(注解允许user/admin访问,web.xml仅允许admin)。建议保留一种配置方式:
- 要么删除
@ServletSecurity注解,仅通过web.xml控制权限; - 要么删除
web.xml中的security-constraint,仅使用注解配置。
3. 清理无效令牌
日志开头的CWWKS4001I提示令牌验证失败,可能是旧会话残留导致:
- 清除浏览器缓存和Cookie,重启OpenLiberty服务器后重新登录测试。
4. 验证用户注册表配置
虽然bob能登录,但可再次确认:
userRegistry.xml中bob的密码{xor}PTA9Lyg7对应明文bobpwd,确保登录时输入正确;basicRegistry的realm名称WebRealm与应用配置的realm一致(默认值无需修改)。
内容的提问来源于stack exchange,提问作者Teshte
相关产品推荐
相关产品推荐

