如何在Wildfly OIDC中配置remote-user显示用户名
解决Wildfly OIDC返回preferred_username而非用户ID的配置方法
要让request.getRemoteUser()和request.getUserPrincipal().getName()返回Keycloak令牌中的preferred_username声明,只需在Wildfly的OIDC配置中指定principal-claim参数即可,分两种配置场景:
1. 服务器级配置(修改standalone.xml/domain.xml)
找到Wildfly配置文件中的Elytron OIDC客户端配置块,添加principal-claim="preferred_username"属性:
<subsystem xmlns="urn:wildfly:elytron-oidc-client:1.0"> <client name="your-oidc-client-name"> <authentication client-id="your-client-id" provider-url="https://your-keycloak-instance/auth/realms/your-realm" principal-claim="preferred_username" ssl-required="EXTERNAL"/> <credentials secret="your-client-secret"/> </client> </subsystem>
2. 应用级配置(使用oidc.json)
如果你的应用通过WEB-INF/oidc.json或类路径下的oidc.json配置OIDC,添加principalClaim字段:
{ "clientId": "your-client-id", "providerUrl": "https://your-keycloak-instance/auth/realms/your-realm", "secret": "your-client-secret", "principalClaim": "preferred_username" }
注意事项
- 确保Keycloak的令牌中包含
preferred_username声明:默认情况下Keycloak会自动添加该字段,对应用户设置的用户名(而非UUID格式的用户ID)。 - 修改配置后需重启Wildfly服务器,配置才会生效。
内容的提问来源于stack exchange,提问作者queeg
相关产品推荐
相关产品推荐

