WSO2 IS 5.11.0是否存在处理忘记密码的REST API?求Java调用示例
WSO2 IS 5.11.0 忘记密码相关API及Java调用示例
是否存在忘记密码相关API?
SCIM 2.0标准并未定义忘记密码的操作,WSO2 IS 5.11.0提供了独立的REST API来处理密码重置/忘记密码流程,核心分为两个步骤:
- 发送密码重置验证码(至用户邮箱或手机号)
- 验证验证码并完成密码重置
对应的API端点详情:
发送验证码
- 请求方法:
POST - 端点:
/api/identity/user/v1.0/initiate-reset-password - 请求体示例:
{ "user": { "username": "testuser", "realm": "PRIMARY" }, "properties": [ { "key": "notificationChannel", "value": "EMAIL" } ] }
- 请求方法:
验证验证码并重置密码
- 请求方法:
POST - 端点:
/api/identity/user/v1.0/confirm-reset-password - 请求体示例:
{ "code": "xxxxxx", "user": { "username": "testuser", "realm": "PRIMARY" }, "newPassword": "newStrongPassword123!" }
- 请求方法:
Java应用调用示例
以下使用Apache HttpClient实现API调用,需提前引入httpclient依赖。
1. 发起密码重置(发送验证码)
import org.apache.http.HttpEntity; import org.apache.http.HttpResponse; import org.apache.http.client.HttpClient; import org.apache.http.client.methods.HttpPost; import org.apache.http.entity.StringEntity; import org.apache.http.impl.client.HttpClients; import org.apache.http.util.EntityUtils; public class PasswordResetInitiator { public static void main(String[] args) throws Exception { HttpClient httpClient = HttpClients.createDefault(); HttpPost postRequest = new HttpPost("https://<IS_HOST>:<IS_PORT>/api/identity/user/v1.0/initiate-reset-password"); // 设置请求头 postRequest.setHeader("Content-Type", "application/json"); postRequest.setHeader("Authorization", "Bearer <ACCESS_TOKEN>"); // 需获取有权限的OAuth2令牌 // 构造请求体 String jsonBody = "{\"user\":{\"username\":\"testuser\",\"realm\":\"PRIMARY\"},\"properties\":[{\"key\":\"notificationChannel\",\"value\":\"EMAIL\"}]}"; StringEntity entity = new StringEntity(jsonBody); postRequest.setEntity(entity); // 发送请求并处理响应 HttpResponse response = httpClient.execute(postRequest); HttpEntity responseEntity = response.getEntity(); String responseString = EntityUtils.toString(responseEntity); System.out.println("Response: " + responseString); } }
2. 验证验证码并重置密码
import org.apache.http.HttpEntity; import org.apache.http.HttpResponse; import org.apache.http.client.HttpClient; import org.apache.http.client.methods.HttpPost; import org.apache.http.entity.StringEntity; import org.apache.http.impl.client.HttpClients; import org.apache.http.util.EntityUtils; public class PasswordResetConfirmer { public static void main(String[] args) throws Exception { HttpClient httpClient = HttpClients.createDefault(); HttpPost postRequest = new HttpPost("https://<IS_HOST>:<IS_PORT>/api/identity/user/v1.0/confirm-reset-password"); postRequest.setHeader("Content-Type", "application/json"); postRequest.setHeader("Authorization", "Bearer <ACCESS_TOKEN>"); // 构造请求体,替换为实际验证码和新密码 String jsonBody = "{\"code\":\"xxxxxx\",\"user\":{\"username\":\"testuser\",\"realm\":\"PRIMARY\"},\"newPassword\":\"newStrongPassword123!\"}"; StringEntity entity = new StringEntity(jsonBody); postRequest.setEntity(entity); HttpResponse response = httpClient.execute(postRequest); HttpEntity responseEntity = response.getEntity(); String responseString = EntityUtils.toString(responseEntity); System.out.println("Response: " + responseString); } }
关键注意事项
- 替换代码中的
<IS_HOST>、<IS_PORT>为你的WSO2 IS部署地址和端口 <ACCESS_TOKEN>需通过WSO2 IS的OAuth2端点获取,令牌需具备internal_user_mgt_update等相关权限- 需确保WSO2 IS已配置好邮箱/短信通知服务,否则验证码无法正常发送
内容的提问来源于stack exchange,提问作者Aldo Inácio da Silva
相关产品推荐
相关产品推荐

