You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rails集成Keycloak Gem+Redis缓存存储遇CookieOverflow问题求助

Alright, let's tackle this CookieOverflow issue you're hitting when using Keycloak with Rails' redis_cache_store. I've run into similar problems before, so here's a breakdown of what's happening and how to fix it:

Why This Happens

Even though you've configured Rails to use Redis for session storage, the Keycloak gem you're using is likely storing large authentication-related data (like ID tokens, refresh tokens, or user claims) directly in cookies, rather than leveraging the Redis-backed session. Browser cookies have a strict size limit (usually ~4KB), so once that data exceeds this threshold, you get the ActionDispatch::Cookies::CookieOverflow error.


Fixes to Try (Ordered by Recommendation)

1. Configure Your Keycloak Gem to Use Rails Session

First, check the documentation for your specific Keycloak gem (whether it's devise-keycloak-authenticatable, keycloak-ruby, or another) for settings that force it to store authentication data in the Rails session instead of cookies.

For example, if you're using the Devise integration:

  • Look for a configuration option like store_token_in_session or similar. Enabling this will push the large token data into your Redis-backed session instead of cookies.
  • Add this to your Devise initializer (e.g., config/initializers/devise.rb):
    config.warden do |manager|
      manager.default_strategies(scope: :user).unshift :keycloak_authenticatable
      manager.strategies[:keycloak_authenticatable].store_token_in_session = true
    end
    

2. Lock Down Your Redis Session Store Configuration

Double-check that your session store is properly pointing to Redis and not falling back to cookie storage. Update your config/initializers/session_store.rb with explicit settings:

Rails.application.config.session_store :cache_store,
  key: ENV['APP_SESSION_KEY'],
  expire_after: 1.day, # Match your Keycloak session timeout
  cache: Rails.cache # Explicitly tie to your Redis cache instance

Also, confirm your Redis cache is correctly configured in your environment file (e.g., config/environments/production.rb):

config.cache_store = :redis_cache_store, {
  url: ENV['REDIS_URL'],
  namespace: "#{ENV['APP_NAME']}:cache",
  expires_in: 1.day
}

3. Manually Move Keycloak Data to Redis Session

If your gem doesn't support session storage out of the box, you can intercept the Keycloak auth callback and manually transfer the large data to the Rails session:

  1. In your auth callback controller (e.g., app/controllers/users/omniauth_callbacks_controller.rb):

    def keycloak
      # Grab the full auth data from Keycloak
      keycloak_auth_data = request.env['omniauth.auth']
      
      # Store the large data in Redis-backed session
      session[:keycloak_auth] = keycloak_auth_data
      
      # Delete any large cookies the gem might have set
      cookies.delete(:keycloak_id_token) # Replace with actual cookie name from your gem
      cookies.delete(:keycloak_refresh_token)
      
      # Proceed with your normal auth flow
      sign_in_and_redirect User.from_omniauth(keycloak_auth_data)
    end
    
  2. When you need to access Keycloak data later, pull it from the session instead of cookies:

    # Instead of cookies[:keycloak_id_token]
    current_keycloak_data = session[:keycloak_auth]
    

4. Trim Down Keycloak Token Size

If the above fixes aren't feasible, you can reduce the size of the data Keycloak sends:

  • Log into your Keycloak admin console
  • Go to your client's Scope settings
  • Remove any unnecessary client scopes, user attributes, or role claims that are being included in the ID/access tokens
  • This will shrink the token payload, making it fit within the cookie limit (if you absolutely have to store it in cookies)

5. Enable Cookie Compression (Temporary Band-Aid)

As a last resort, you can enable Rails' cookie compression to squeeze more data into cookies. This is not a long-term fix, but it might buy you time:

# Add to config/application.rb or your environment file
config.action_dispatch.cookies_serializer = :json
config.action_dispatch.cookie_compression = :zlib

Final Notes

The best long-term solution is to ensure all large authentication data lives in your Redis-backed session, not cookies. This aligns with your requirement to use redis_cache_store and avoids browser cookie limitations entirely.

内容的提问来源于stack exchange,提问作者Beu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 12:32:40