You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在WebSphere Liberty应用中通过社交登录从OIDC Token生成授权角色

Open Liberty中JWT角色授权配置问题

已在WebSphere/Open Liberty服务器上通过OIDC Token和social-login功能完成认证,但无法从JWT Token中提取角色并实现不同Servlet的基于角色授权。

server.xml配置

<server description="new server">
       <!-- Enable features -->
       <featureManager>
             <feature>appSecurity-3.0</feature>
             <feature>socialLogin-1.0</feature>
             <feature>microProfile-4.1</feature>
             <feature>jsp-2.3</feature>
             <feature>localConnector-1.0</feature>
       </featureManager> 

       <logging traceSpecification="*=info" consoleLogLevel="INFO"/>

       <oidcLogin clientId="${clientId}"
             clientSecret="${clientSecret}"
             discoveryEndpoint="${oAuthServerUrl}/.well-known/openid-configuration"
             id="liberty-aad-oidc-javaeecafe" signatureAlgorithm="RS256"
             userNameAttribute="email" groupNameAttribute="role"/>

       <authFilter id="myAuthFilter">
             <requestUrl id="myRequestUrl" matchType="contains"
                    urlPattern="/*" />
       </authFilter>

       <keyStore id="defaultKeyStore"
             password="${env.keystore_password}" />
       <keyStore id="mytruststore"
             location="${server.config.dir}/mytruststore.jks" password="****" />

       <ssl id="defaultSSLConfig" keyStoreRef="defaultKeyStore"
             trustDefaultCerts="true" trustStoreRef="mytruststore" />

       <applicationManager autoExpand="true" />

       <httpEndpoint host="*" httpPort="9080" httpsPort="9443"
             id="defaultHttpEndpoint" />

       <mpJwt id="myMpJwt"
             jwksUri="${oAuthServerUrl}/publickeys"
             issuer="${oAuthServerUrl}"
             authFilterRef="myAuthFilter" groupNameAttribute="role"/>          

       <applicationMonitor updateTrigger="mbean" />    

       <applicationMonitor dropinsEnabled="false"/>

       <webApplication contextRoot="/" id="oidcsampleapp"
             location="oidcsampleapp-1.0.0.war" name="oidcsampleapp" >

             <application-bnd>
                    <security-role name="admin-role">
                          <group name="admin" />
                    </security-role>
                    <!-- <security-role name="admin">
                          <special-subject type="ALL_AUTHENTICATED_USERS" />
                    </security-role> -->
             </application-bnd>
       </webApplication>
</server>

当前仅特定配置下请求能转发至应用,否则访问会被拒绝。目标是从JWT Token中获取admin-role作为安全主体角色。

web.xml安全配置

<security-role>
         <role-name>admin-role</role-name>
   </security-role>
   <security-role>
         <role-name>user-role</role-name>
   </security-role>

   <security-constraint>
         <web-resource-collection>
                <web-resource-name>AdminServlet</web-resource-name>
                <url-pattern>/admin/*</url-pattern>
                <http-method>GET</http-method>
                <http-method>PUT</http-method>
                <http-method>POST</http-method>
                <http-method>DELETE</http-method>
         </web-resource-collection>

         <auth-constraint>
                <role-name>admin-role</role-name>
         </auth-constraint>

         <user-data-constraint>
                <transport-guarantee>NONE</transport-guarantee>
         </user-data-constraint>
   </security-constraint>
<security-role>
         <role-name>admin-role</role-name>
   </security-role>
   <security-role>
         <role-name>appuser-role</role-name>
   </security-role>

   <security-constraint>
         <web-resource-collection>
                <web-resource-name>AdminServlet</web-resource-name>
                <url-pattern>/admin/*</url-pattern>
                <http-method>GET</http-method>
                <http-method>PUT</http-method>
                <http-method>POST</http-method>
                <http-method>DELETE</http-method>
         </web-resource-collection>

         <auth-constraint>
                <role-name>admin-role</role-name>
         </auth-constraint>
         <user-data-constraint>
                <transport-guarantee>NONE</transport-guarantee>
         </user-data-constraint>
   </security-constraint>

收到的JWT Token

{
  "iss": "https://xxxxx.xxxxx",
  "exp": 1665245032,
  "aud": [
    "931280e3-xxxx-xxxx-xxxxx-xxxxxxx"
  ],
  "sub": "xxxxx-xxxx-xxxxxxx-xxxx-xxxxxxxxx",
  "amr": [
    "saml"
  ],
  "iat": 1665241432,
  "tenant": "xxxxxxxxx",
  "scope": "openid appid_default appid_readuserattr appid_readprofile appid_writeuserattr appid_authenticated",
  "role": "admin-role",
  "surname": "Basu",
  "groups": [
    "014a0054-942f-4c20-a6e0-235dd906ca1c"
  ],
  "entityID": "https://sts.windows.net/81fa766e-a349-4867-8bf4-ab35e250a08f/"
}

内容的提问来源于stack exchange,提问作者Rishav Basu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 01:15:45