You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为WildFly 19的文件目录列表添加身份验证?

为WildFly 19的文件目录列表添加身份验证机制

你已通过Undertow配置实现/SoftwareRepository路径的文件目录列表功能,但目前无需认证即可访问。要给该路径添加身份验证,需完成以下配置步骤:

1. 配置安全域(Security Domain)

在WildFly的standalone.xml或domain.xml中找到<security>子系统,添加用于存储用户、角色信息的安全域(以下以属性文件存储为例,也可适配LDAP、数据库等存储方式):

<subsystem xmlns="urn:jboss:domain:security:2.0">
    <security-domains>
        <!-- 新增安全域 -->
        <security-domain name="SoftwareRepoSecurity" cache-type="default">
            <authentication>
                <login-module code="UsersRoles" flag="required">
                    <module-option name="usersProperties" value="${jboss.server.config.dir}/software-repo-users.properties"/>
                    <module-option name="rolesProperties" value="${jboss.server.config.dir}/software-repo-roles.properties"/>
                </login-module>
            </authentication>
        </security-domain>
    </security-domains>
</subsystem>

随后在WildFly的standalone/configuration目录下创建两个属性文件:

  • software-repo-users.properties:存储用户名与加密密码,格式为用户名=加密密码。可通过WildFly自带工具生成加密密码:
    # 使用add-user.sh生成用户,执行后会自动在configuration目录生成相关文件,可直接复用内容
    $WILDFLY_HOME/bin/add-user.sh -u user1 -p your-password -g repo-users
    
  • software-repo-roles.properties:存储用户对应角色,格式为用户名=角色名,例如user1=repo-users

2. 修改Undertow子系统配置,添加安全约束

更新你现有的Undertow配置,开启路径安全验证、配置认证规则并关联安全域:

<subsystem xmlns="urn:jboss:domain:undertow:10.0">
    ...
    <server name="default-server">
        <http-listener name="default" socket-binding="http" redirect-socket="https"/>
        <host name="default-host" alias="localhost">
            <!-- 给目标路径开启安全验证 -->
            <location name="/SoftwareRepository" handler="SoftwareRepo" security-enabled="true"/>
            <!-- 配置安全约束,限定可访问的角色 -->
            <security-constraint>
                <web-resource-collection name="SoftwareRepoResources">
                    <web-resource-name>Software Repository</web-resource-name>
                    <url-pattern>/SoftwareRepository/*</url-pattern>
                </web-resource-collection>
                <auth-constraint>
                    <role-name>repo-users</role-name>
                </auth-constraint>
            </security-constraint>
            <!-- 设置认证机制,这里用BASIC认证,也可选择FORM、DIGEST等 -->
            <authentication-mechanism>
                <mechanism-name>BASIC</mechanism-name>
                <mechanism-realm-name>SoftwareRepoRealm</mechanism-realm-name>
            </authentication-mechanism>
        </host>
    </server>
    ...
    <handlers>
        <file name="SoftwareRepo" path="<Path to Directory>" case-sensitive="false" directory-listing="true"/>
    </handlers>
    <!-- 关联Undertow应用与安全域 -->
    <application-security-domains>
        <application-security-domain name="SoftwareRepoSecurity" security-domain="SoftwareRepoSecurity"/>
    </application-security-domains>
</subsystem>

3. 验证配置效果

重启WildFly服务器后,访问http://localhost:8080/SoftwareRepository时,浏览器会弹出身份验证窗口,只有输入正确的用户名(且拥有repo-users角色)及密码,才能访问文件目录列表。

关键配置说明

  • security-enabled="true":开启目标路径的安全验证开关
  • security-constraint:定义需要保护的资源路径范围,以及允许访问的角色
  • authentication-mechanism:指定认证方式,BASIC为基础HTTP弹窗认证,FORM则需自定义登录页面
  • application-security-domains:将Undertow的安全配置与之前创建的安全域绑定

内容的提问来源于stack exchange,提问作者Dhamotharan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 05:30:58