如何为WildFly 19的文件目录列表添加身份验证?
为WildFly 19的文件目录列表添加身份验证机制
你已通过Undertow配置实现/SoftwareRepository路径的文件目录列表功能,但目前无需认证即可访问。要给该路径添加身份验证,需完成以下配置步骤:
1. 配置安全域(Security Domain)
在WildFly的standalone.xml或domain.xml中找到<security>子系统,添加用于存储用户、角色信息的安全域(以下以属性文件存储为例,也可适配LDAP、数据库等存储方式):
<subsystem xmlns="urn:jboss:domain:security:2.0"> <security-domains> <!-- 新增安全域 --> <security-domain name="SoftwareRepoSecurity" cache-type="default"> <authentication> <login-module code="UsersRoles" flag="required"> <module-option name="usersProperties" value="${jboss.server.config.dir}/software-repo-users.properties"/> <module-option name="rolesProperties" value="${jboss.server.config.dir}/software-repo-roles.properties"/> </login-module> </authentication> </security-domain> </security-domains> </subsystem>
随后在WildFly的standalone/configuration目录下创建两个属性文件:
software-repo-users.properties:存储用户名与加密密码,格式为用户名=加密密码。可通过WildFly自带工具生成加密密码:# 使用add-user.sh生成用户,执行后会自动在configuration目录生成相关文件,可直接复用内容 $WILDFLY_HOME/bin/add-user.sh -u user1 -p your-password -g repo-userssoftware-repo-roles.properties:存储用户对应角色,格式为用户名=角色名,例如user1=repo-users
2. 修改Undertow子系统配置,添加安全约束
更新你现有的Undertow配置,开启路径安全验证、配置认证规则并关联安全域:
<subsystem xmlns="urn:jboss:domain:undertow:10.0"> ... <server name="default-server"> <http-listener name="default" socket-binding="http" redirect-socket="https"/> <host name="default-host" alias="localhost"> <!-- 给目标路径开启安全验证 --> <location name="/SoftwareRepository" handler="SoftwareRepo" security-enabled="true"/> <!-- 配置安全约束,限定可访问的角色 --> <security-constraint> <web-resource-collection name="SoftwareRepoResources"> <web-resource-name>Software Repository</web-resource-name> <url-pattern>/SoftwareRepository/*</url-pattern> </web-resource-collection> <auth-constraint> <role-name>repo-users</role-name> </auth-constraint> </security-constraint> <!-- 设置认证机制,这里用BASIC认证,也可选择FORM、DIGEST等 --> <authentication-mechanism> <mechanism-name>BASIC</mechanism-name> <mechanism-realm-name>SoftwareRepoRealm</mechanism-realm-name> </authentication-mechanism> </host> </server> ... <handlers> <file name="SoftwareRepo" path="<Path to Directory>" case-sensitive="false" directory-listing="true"/> </handlers> <!-- 关联Undertow应用与安全域 --> <application-security-domains> <application-security-domain name="SoftwareRepoSecurity" security-domain="SoftwareRepoSecurity"/> </application-security-domains> </subsystem>
3. 验证配置效果
重启WildFly服务器后,访问http://localhost:8080/SoftwareRepository时,浏览器会弹出身份验证窗口,只有输入正确的用户名(且拥有repo-users角色)及密码,才能访问文件目录列表。
关键配置说明
security-enabled="true":开启目标路径的安全验证开关security-constraint:定义需要保护的资源路径范围,以及允许访问的角色authentication-mechanism:指定认证方式,BASIC为基础HTTP弹窗认证,FORM则需自定义登录页面application-security-domains:将Undertow的安全配置与之前创建的安全域绑定
内容的提问来源于stack exchange,提问作者Dhamotharan
相关产品推荐
相关产品推荐

