You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak自定义JS策略中$evaluation变量未定义问题咨询

自定义Keycloak JS授权策略变量全部未定义问题排查

问题描述

按照Keycloak官方JS授权策略指南创建自定义脚本,但脚本内所有变量(如$evaluation、context等)均显示未定义,请求协助排查解决。

JS策略代码

var context = $evaluation.context;
var identity = context.identity;
var permission = $evaluation.permission;
var resource = permission.resource;
var attributes = identity.getAttributes();

print('**** evaluation ' + JSON.stringify($evaluation));
print('**** context ' + JSON.stringify(context));
print('**** identity ' + JSON.stringify(identity));
print('**** attributes ' + JSON.stringify(attributes));

if (attributes.owner == identity.id) {
    $evaluation.grant();
}

Keycloak日志

keycloak-authorization-keycloak-1  | 2022-12-30 14:52:46,319 WARN  [org.keycloak.connections.httpclient.DefaultHttpClientFactory] (executor-thread-2) TruststoreProvider is disabled
keycloak-authorization-keycloak-1  | 2022-12-30 14:52:48,087 WARN  [org.keycloak.services.managers.AuthenticationManager] (executor-thread-1) Required action provider factory 'CONFIGURE_RECOVERY_AUTHN_CODES' configured in the realm 'myrealm' is not available. Provider not found or feature is disabled.
keycloak-authorization-keycloak-1  | 2022-12-30 14:52:48,088 WARN  [org.keycloak.services.managers.AuthenticationManager] (executor-thread-1) Required action provider factory 'UPDATE_EMAIL' configured in the realm 'myrealm' is not available. Provider not found or feature is disabled.
keycloak-authorization-keycloak-1  | **** evaluation undefined
keycloak-authorization-keycloak-1  | **** context undefined
keycloak-authorization-keycloak-1  | **** identity undefined
keycloak-authorization-keycloak-1  | **** attributes undefined

Docker配置

services:
  keycloak:
    image: quay.io/keycloak/keycloak:latest
    volumes:
      - keycloak:/opt/keycloak/data
      - ./js-policies/target/js-policies.jar:/opt/keycloak/providers/js-policies.jar
    ports:
      - 9000:8080
    environment:
      KEYCLOAK_ADMIN: admin
      KEYCLOAK_ADMIN_PASSWORD: admin
    command:
      - start-dev

排查与解决方案

1. 确认JS策略提供者扩展部署正确

  • Keycloak默认不包含JS策略支持,需确保部署了官方或兼容的JS策略提供者jar包。你挂载的js-policies.jar需与当前Keycloak版本(latest对应19+)匹配,若为自定义编译扩展,检查编译依赖是否与Keycloak版本一致。
  • 启动Keycloak时查看日志,确认是否有类似Registered provider: js-policy的加载成功信息,无此信息则说明扩展未正确加载,需检查jar包路径、权限或完整性。

2. 修正脚本变量名与属性取值方式

  • Keycloak 17+(Quarkus版本)中,JS策略的上下文变量为evaluation而非$evaluation,去掉$符号后重试:
    var context = evaluation.context;
    var identity = context.identity;
    var permission = evaluation.permission;
    var resource = permission.resource;
    var attributes = identity.getAttributes();
    
    print('**** evaluation ' + JSON.stringify(evaluation));
    print('**** context ' + JSON.stringify(context));
    print('**** identity ' + JSON.stringify(identity));
    print('**** attributes ' + JSON.stringify(attributes));
    
    // getAttributes()返回MultiMap,需取数组第一个元素比较
    if (attributes.owner && attributes.owner[0] === identity.id) {
        evaluation.grant();
    }
    

3. 验证授权服务配置

  • 确保当前Realm已启用Authorization Services,且策略已正确绑定到权限,权限关联到目标资源,评估流程能触发该策略。

4. 检查Docker挂载与扩展加载

  • 进入容器执行ls -l /opt/keycloak/providers/,确认js-policies.jar存在且权限正常(容器用户可读取)。
  • 添加环境变量KC_LOG_LEVEL=debug启动Keycloak,查看扩展加载时是否有类缺失、依赖错误等debug日志。

内容的提问来源于stack exchange,提问作者sashok_bg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 23:50:25