Fuseki 2.4配置Shiro认证后SPARQL连接未触发鉴权问题求助
问题
我使用Fuseki 2.4,已在shiro.ini中配置基础认证。设置凭据并重启服务后,访问Fuseki管理端点/$/datasets/时,正常触发认证错误(符合预期);但通过SPARQL连接Fuseki数据时,未做任何认证却直接连接成功,和未配置认证时的表现一致。我预期SPARQL连接也应触发认证,求解决方法。
当前shiro.ini配置
[main] # Development ssl.enabled = false plainMatcher=org.apache.shiro.authc.credential.SimpleCredentialsMatcher #iniRealm=org.apache.shiro.realm.text.IniRealm iniRealm.credentialsMatcher = $plainMatcher localhostFilter=org.apache.jena.fuseki.authz.LocalhostFilter [users] # Implicitly adds "iniRealm = org.apache.shiro.realm.text.IniRealm" admin=password123 [roles] [urls] ## Control functions open to anyone /$/status = anon /$/ping = anon ## and the rest are restricted to localhost. ##/$/** = localhostFilter ## If you want simple, basic authentication user/password ## on the operations, ## 1 - set a better password in [users] above. ## 2 - comment out the "/$/** = localhost" line and use: /$/** = authcBasic,user[admin] ## or to allow any access. ##/$/** = anon # Everything else /**=anon
解决方法
问题核心是SPARQL端点不属于/$/**路径范围,而你在[urls]里设置了/**=anon,允许所有非管理路径匿名访问。
具体修改方案:
- 如果你要给单个数据集的SPARQL端点加认证(比如数据集名为
myDataset),在[urls]段添加:/myDataset/** = authcBasic,user[admin] - 如果你要给所有数据集的SPARQL端点加认证,直接把
/**=anon替换为:
注意保留/** = authcBasic,user[admin]/$/status和/$/ping的anon配置,这两个是健康检查接口,通常无需认证。
修改完成后重启Fuseki服务,再发起SPARQL请求就会触发基础认证了。
内容的提问来源于stack exchange,提问作者Bhavya
相关产品推荐
相关产品推荐

