非Spring Boot的Spring EAR应用部署JBoss 7.2.4集成Keycloak求助
方案可行性及落地步骤
该方案完全可行,Keycloak原生支持与JBoss EAP 7.2.4集成,同时可对接AD作为用户数据源,无需迁移至Spring Boot。以下是具体实现流程:
1. 配置Keycloak对接AD用户源
- 在Keycloak控制台创建用户联盟,选择LDAP类型,填入AD的连接参数(域名、LDAP服务器地址、绑定账号密码、用户/组搜索基准DN等),开启用户与组的同步。
- 同步完成后,验证AD账号可在Keycloak正常登录,且组信息正确同步。
2. 为JBoss 7.2.4安装Keycloak适配器
JBoss EAP 7.2.x兼容官方Keycloak JBoss适配器,操作步骤:
- 下载与Keycloak服务器版本匹配的JBoss适配器(建议选用Keycloak 15.x/16.x版本,适配EAP 7.2)。
- 执行适配器包中的
jboss-cli.sh(Linux)或jboss-cli.bat(Windows)脚本,自动将适配器模块安装到JBoss的modules目录,并更新standalone.xml/domain.xml,添加Keycloak安全域配置。 - 重启JBoss,检查日志确认Keycloak模块加载正常,无报错。
3. 配置Spring应用的安全拦截逻辑
基于Spring Security集成Keycloak,无需Spring Boot依赖:
- 在应用构建文件(如
pom.xml)中添加Keycloak Spring Security依赖(版本需与适配器一致):
<dependency> <groupId>org.keycloak</groupId> <artifactId>keycloak-spring-security-adapter</artifactId> <version>15.0.2</version> </dependency>
- 创建Spring Security配置类,继承
KeycloakWebSecurityConfigurerAdapter,实现认证与权限控制:
@Configuration @EnableWebSecurity public class ApiSecurityConfig extends KeycloakWebSecurityConfigurerAdapter { @Autowired public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception { KeycloakAuthenticationProvider authProvider = keycloakAuthenticationProvider(); // 将Keycloak角色映射为Spring Security权限 authProvider.setGrantedAuthoritiesMapper(new SimpleAuthorityMapper()); auth.authenticationProvider(authProvider); } @Bean @Override protected SessionAuthenticationStrategy sessionAuthenticationStrategy() { return new RegisterSessionAuthenticationStrategy(new SessionRegistryImpl()); } @Override protected void configure(HttpSecurity http) throws Exception { super.configure(http); // 保护所有REST API路径,指定允许访问的角色(对应AD同步到Keycloak的组) http.authorizeRequests() .antMatchers("/api/**").hasAnyRole("ADMIN", "APP_USER") .anyRequest().permitAll(); } }
- 在应用的
web.xml中添加Spring Security过滤器,确保请求先经过认证拦截:
<filter> <filter-name>springSecurityFilterChain</filter-name> <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> </filter> <filter-mapping> <filter-name>springSecurityFilterChain</filter-name> <url-pattern>/*</url-pattern> </filter-mapping>
4. 配置应用的Keycloak客户端信息
- 在Keycloak控制台创建对应应用的客户端,客户端类型选择
confidential,配置应用的重定向URI(如http://your-app-domain/*)和Web Origins。 - 创建
keycloak.json文件,放置在应用的WEB-INF目录下,填入客户端配置信息:
{ "realm": "your-realm-name", "auth-server-url": "http://keycloak-server:8080/auth", "ssl-required": "external", "resource": "your-client-id", "credentials": { "secret": "your-client-secret" }, "use-resource-role-mappings": true, "confidential-port": 0 }
5. 验证功能
- 启动Keycloak、JBoss,部署EAR应用。
- 访问受保护的REST API,会自动跳转至Keycloak登录页,使用AD账号登录后即可正常访问。
- 测试不同AD组的用户,验证权限控制是否符合预期。
内容的提问来源于stack exchange,提问作者Otis Ottington
相关产品推荐
相关产品推荐

