You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 IS通过SCIM2 API创建用户时外部声明inn未生效的问题

SCIM2 API添加自定义声明inn不生效问题

我尝试通过SCIM2 API创建带有自定义声明的用户,操作步骤如下:

  • 创建声明http://wso2.org/claims/inn
  • 将该声明添加至SCIM企业用户扩展架构urn:ietf:params:scim:schemas:extension:enterprise:2.0:User
  • 发送以下创建用户的请求:
{
    "schemas": ["urn:ietf:params:scim:schemas:extension:enterprise:2.0:User"],
    "name": {
        "familyName": "TryAddClaims",
        "givenName": "rest11@test.com"
    },
    "userName": "rest11@test.com",
    "password": "admin",
    "emails": [{
            "primary": true,
            "value": "rest11@test.com",
            "type": "home"
        }
    ],
    "urn:ietf:params:scim:schemas:extension:enterprise:2.0:User":{
        "organization": "rest_organization",
        "inn": "inn"
    }
}

但收到的响应中仅包含organization字段,inn字段缺失:

{
    "emails": [
        {
            "type": "home",
            "value": "rest11@test.com"
        },
        "rest11@test.com"
    ],
    "meta": {
        "created": "2022-09-12T07:43:20.474255Z",
        "location": "my-host/scim2/Users/1d64942c-ce24-48cf-ad47-665f4f9c37f8",
        "lastModified": "2022-09-12T07:43:20.474255Z",
        "resourceType": "User"
    },
    "schemas": [
        "urn:ietf:params:scim:schemas:core:2.0:User",
        "urn:ietf:params:scim:schemas:extension:enterprise:2.0:User"
    ],
    "roles": [
        {
            "type": "default",
            "value": "Internal/everyone"
        },
        {
            "display": "everyone"
        }
    ],
    "name": {
        "givenName": "rest11@test.com",
        "familyName": "TryAddClaims"
    },
    "id": "1d64942c-ce24-48cf-ad47-665f4f9c37f8",
    "userName": "rest11@test.com",
    "urn:ietf:params:scim:schemas:extension:enterprise:2.0:User": {
        "organization": "rest_organization"
    }
}

同时在WSO2管理面板中,该用户的inn字段也为空。为何配置方式相同的情况下,inn字段未生效,而organization字段正常?


可能的原因及解决步骤

1. 声明与用户存储属性未正确映射

organization是SCIM企业扩展的默认属性,已预先完成用户存储映射。而自定义声明inn需要手动配置映射:

  • 进入WSO2管理控制台的主菜单 > 身份 > 声明 > 列表,找到http://wso2.org/claims/inn声明
  • 检查用户存储属性是否已设置:
    • 若使用JDBC用户存储,需映射到UM_USER_ATTRIBUTE表的对应字段(可自定义属性名称)
    • 若使用LDAP用户存储,需映射到LDAP中已定义的inn属性
  • 保存配置后,重新测试SCIM请求

2. SCIM扩展架构的属性配置不完整

添加声明到SCIM架构时,需确保属性的元数据配置正确:

  • 进入主菜单 > 身份 > SCIM > SCIM2 Schema Extensions
  • 找到urn:ietf:params:scim:schemas:extension:enterprise:2.0:User架构,查看inn属性的配置:
    • 确认返回(Return)选项已勾选,确保该属性会包含在SCIM响应中
    • 确认多值(Multi-Valued)设为false(因为inn是单值属性)
    • 若未添加该属性,需重新将inn声明关联到该架构并保存

3. 用户存储不支持自定义属性

  • 若使用JDBC用户存储:默认的UM_USER_ATTRIBUTE表可以存储任意自定义属性,无需额外修改;但如果使用自定义用户表,需确保表中存在inn字段
  • 若使用LDAP用户存储:需要在LDAP服务器中为用户条目添加支持inn属性的对象类,确保用户可以存储该属性

4. 缓存导致配置未生效

修改声明或SCIM配置后,缓存可能会阻止新配置生效:

  • 进入主菜单 > 系统 > 缓存管理,清除声明缓存和SCIM Schema缓存
  • 重启WSO2 Identity Server,确保所有配置更新生效

内容的提问来源于stack exchange,提问作者Артём Власов

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 17:30:56