WSO2-IS邮件重置密码报错IdentityRecoveryServerException
问题描述
已参考官方文档《Password Recovery by Mail》配置WSO2 Identity Server邮件重置密码功能,但在MyAccount页面输入邮箱点击【Submit】按钮时触发错误,日志报错信息如下:
[2022-08-05 18:32:26,931] [4afcc623-e283-45b7-b306-38add4fe3cb9] ERROR {org.wso2.carbon.identity.recovery.endpoint.impl.RecoverPasswordApiServiceImpl} -
Error occurred in the server while performing the task. org.wso2.carbon.identity.recovery.IdentityRecoveryServerException:
Configured callback URL does not match with the provided callback URL: https://localhost:9444/authenticationendpoint/login.do%3Fclient_id=MY_ACCOUNT&code_challenge=Me2BTFFVJh5zLFgPjSkMqENroq2A_vE9IQOc6b7cjIk
&code_challenge_method=S256&commonAuthCallerPath=/oauth2/authorize&forceAuth=false&passiveAuth=false&redirect_uri=https://localhost:9444/myaccount/login&response_mode=form_post&response_type=code
&scope=SYSTEM+openid&tenantDomain=carbon.super&sessionDataKey=ddd9d751-20e4-4061-bb7b-d166318ceb85&relyingParty=MY_ACCOUNT&type=oidc&sp=My+Account&isSaaSApp=true&authenticators=BasicAuthenticator:LOCAL in the request.
解决方案
1. 检查MyAccount服务提供者的OAuth回调URL
- 登录WSO2 IS管理控制台(
https://localhost:9443/carbon) - 进入主菜单 > Identity > Service Providers > List,找到
My Account服务提供者 - 点击Edit,切换到Inbound Authentication Configuration > OAuth/OpenID Connect Configuration
- 确认已配置的回调URL列表中包含
https://localhost:9444/myaccount/login,注意端口、域名和路径必须完全匹配 - 若未找到该URL,点击Edit OAuth配置,添加此URL后保存
2. 验证Resident身份提供者的密码恢复回调配置
- 在管理控制台进入主菜单 > Identity > Identity Providers > Resident
- 切换到Account Management Policies > Password Recovery
- 检查Callback URL字段是否设置为
https://localhost:9444/myaccount/login,确保与请求中的回调地址一致
3. 清理缓存并重启服务
- 进入主菜单 > Tools > Cache Management,点击Clear All Caches清除服务端缓存
- 重启WSO2 Identity Server,使配置变更生效
4. 排查URL编码问题
日志中显示的回调URL包含转义字符(如%3F对应?,&对应&),确认配置的回调URL使用原始格式(如https://localhost:9444/myaccount/login),而非编码后的字符串
内容的提问来源于stack exchange,提问作者Aldo Inácio da Silva

