WSO2自适应认证自定义statusMsg失效及401日志报错原因咨询
问题描述
添加自适应认证脚本后,当用户名格式不符合要求时,预期显示自定义状态消息:Access Denied, invalid username format.,但实际显示默认提示:Something went wrong during the authentication process. Please try signing in again.。
使用的自适应认证脚本:
function onLoginRequest(context) { executeStep(1, { onSuccess: function(context) { var user = context.currentKnownSubject; if(user!= null && user.username != null && !user.username.equals('')) { Log.info("username: " + user.username); } else { sendError('',{'status':'AUTHENTICATION USERNAME ERROR', 'statusMsg': 'Access denied, invalid username format.'}); } } }); }
同时,wso2carbon.log中出现如下401错误:
TID: [-1234] [authenticationendpoint] [2022-10-05 15:44:12,715] [37951f7d-8240-48d4-ad4f-1d4c8a6a3ec4] ERROR {org.wso2.carbon.identity.application.authentication.endpoint.util.AuthContextAPIClient} - Sending GET request to URL : https://dev.wso2istemp.com/api/identity/auth/v1.1/data/AuthenticationError/0b0efc37-819d-4b39-85b2-517126c3c9cb, failed. java.io.IOException: Server returned HTTP response code: 401 for URL: https://dev.wso2istemp.com/api/identity/auth/v1.1/data/AuthenticationError/0b0efc37-819d-4b39-85b2-517126c3c9cb ... org.wso2.carbon.identity.application.authentication.endpoint.util.AuthContextAPIClient.getContextProperties(AuthContextAPIClient.java:70) at org.apache.jsp.retry_jsp._jspService(retry_jsp.java:194) ... org.wso2.carbon.ui.filters.cache.ContentTypeBasedCachePreventionFilter.doFilter(ContentTypeBasedCachePreventionFilter.java:53) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:189) ... org.wso2.carbon.identity.application.authentication.endpoint.util.filter.AuthenticationEndpointFilter.doFilter(AuthenticationEndpointFilter.java:190) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:189) ...
<IS_HOME>/repository/conf/deployment.toml中的[server]配置:
[server] hostname = "dev.wso2istemp.com" node_ip = "127.0.0.1" base_path = "https://$ref{server.hostname}:${carbon.management.port}"
问题分析
1. wso2carbon.log中401报错的原因
base_path配置错误:当前配置使用了${carbon.management.port}(管理端口,默认9443),而认证端点调用的内部认证API属于应用服务范畴,管理端口的接口需要管理员权限才能访问,普通的认证端点请求没有携带管理员凭证,因此被服务端拒绝,返回401 Unauthorized。- 正确的
base_path应该使用${carbon.ssl.port}(应用服务端口,默认与管理端口一致为9443,但配置变量需对应),确保认证端点调用的是无需管理员权限的应用服务API。
2. 自定义状态消息无法正常显示的原因
- 脚本逻辑错误:代码中的
sendError放在了executeStep(1)的onSuccess回调中,这个回调仅在步骤1(用户名密码验证)成功后触发,此时context.currentKnownSubject必然是验证通过的有效用户,不可能为空或用户名为空,因此sendError分支永远不会被执行。 - API调用失败导致无法获取自定义错误:即使脚本逻辑正确,由于上述401错误,认证端点无法通过内部API获取你设置的自定义错误信息,只能 fallback 显示默认的错误提示。
内容的提问来源于stack exchange,提问作者Nipuna Upeksha
相关产品推荐
相关产品推荐

