如何在WebSphere Liberty应用中通过社交登录从OIDC Token生成授权角色
Open Liberty中JWT角色授权配置问题
已在WebSphere/Open Liberty服务器上通过OIDC Token和social-login功能完成认证,但无法从JWT Token中提取角色并实现不同Servlet的基于角色授权。
server.xml配置
<server description="new server"> <!-- Enable features --> <featureManager> <feature>appSecurity-3.0</feature> <feature>socialLogin-1.0</feature> <feature>microProfile-4.1</feature> <feature>jsp-2.3</feature> <feature>localConnector-1.0</feature> </featureManager> <logging traceSpecification="*=info" consoleLogLevel="INFO"/> <oidcLogin clientId="${clientId}" clientSecret="${clientSecret}" discoveryEndpoint="${oAuthServerUrl}/.well-known/openid-configuration" id="liberty-aad-oidc-javaeecafe" signatureAlgorithm="RS256" userNameAttribute="email" groupNameAttribute="role"/> <authFilter id="myAuthFilter"> <requestUrl id="myRequestUrl" matchType="contains" urlPattern="/*" /> </authFilter> <keyStore id="defaultKeyStore" password="${env.keystore_password}" /> <keyStore id="mytruststore" location="${server.config.dir}/mytruststore.jks" password="****" /> <ssl id="defaultSSLConfig" keyStoreRef="defaultKeyStore" trustDefaultCerts="true" trustStoreRef="mytruststore" /> <applicationManager autoExpand="true" /> <httpEndpoint host="*" httpPort="9080" httpsPort="9443" id="defaultHttpEndpoint" /> <mpJwt id="myMpJwt" jwksUri="${oAuthServerUrl}/publickeys" issuer="${oAuthServerUrl}" authFilterRef="myAuthFilter" groupNameAttribute="role"/> <applicationMonitor updateTrigger="mbean" /> <applicationMonitor dropinsEnabled="false"/> <webApplication contextRoot="/" id="oidcsampleapp" location="oidcsampleapp-1.0.0.war" name="oidcsampleapp" > <application-bnd> <security-role name="admin-role"> <group name="admin" /> </security-role> <!-- <security-role name="admin"> <special-subject type="ALL_AUTHENTICATED_USERS" /> </security-role> --> </application-bnd> </webApplication> </server>
当前仅特定配置下请求能转发至应用,否则访问会被拒绝。目标是从JWT Token中获取admin-role作为安全主体角色。
web.xml安全配置
<security-role> <role-name>admin-role</role-name> </security-role> <security-role> <role-name>user-role</role-name> </security-role> <security-constraint> <web-resource-collection> <web-resource-name>AdminServlet</web-resource-name> <url-pattern>/admin/*</url-pattern> <http-method>GET</http-method> <http-method>PUT</http-method> <http-method>POST</http-method> <http-method>DELETE</http-method> </web-resource-collection> <auth-constraint> <role-name>admin-role</role-name> </auth-constraint> <user-data-constraint> <transport-guarantee>NONE</transport-guarantee> </user-data-constraint> </security-constraint>
<security-role> <role-name>admin-role</role-name> </security-role> <security-role> <role-name>appuser-role</role-name> </security-role> <security-constraint> <web-resource-collection> <web-resource-name>AdminServlet</web-resource-name> <url-pattern>/admin/*</url-pattern> <http-method>GET</http-method> <http-method>PUT</http-method> <http-method>POST</http-method> <http-method>DELETE</http-method> </web-resource-collection> <auth-constraint> <role-name>admin-role</role-name> </auth-constraint> <user-data-constraint> <transport-guarantee>NONE</transport-guarantee> </user-data-constraint> </security-constraint>
收到的JWT Token
{ "iss": "https://xxxxx.xxxxx", "exp": 1665245032, "aud": [ "931280e3-xxxx-xxxx-xxxxx-xxxxxxx" ], "sub": "xxxxx-xxxx-xxxxxxx-xxxx-xxxxxxxxx", "amr": [ "saml" ], "iat": 1665241432, "tenant": "xxxxxxxxx", "scope": "openid appid_default appid_readuserattr appid_readprofile appid_writeuserattr appid_authenticated", "role": "admin-role", "surname": "Basu", "groups": [ "014a0054-942f-4c20-a6e0-235dd906ca1c" ], "entityID": "https://sts.windows.net/81fa766e-a349-4867-8bf4-ab35e250a08f/" }
内容的提问来源于stack exchange,提问作者Rishav Basu
相关产品推荐
相关产品推荐

