You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 APIM 4.1.0:自定义OIDC身份提供商多租户用户分配问题

实现自定义OAuth2身份提供商登录时分配用户到指定租户

可以实现,以下是针对WSO2 API Manager 4.1.0的具体操作步骤:

1. 确保身份提供商返回租户域名相关声明

你的自定义IDP以邮箱作为用户名,需确保IDP返回的JWT或用户信息中包含可提取租户域名的字段(比如邮箱的域名部分)。如果IDP支持,优先让其直接返回tenantDomain声明;若不支持,可通过邮箱字段解析获取租户域名。

2. 配置IDP的声明映射

登录Carbon控制台,进入Identity > Identity Providers > 你的自定义IDP > Claim Configuration > Basic Claim Configuration:

  • 勾选Use Local Claim Dialect
  • 在Claim Mapping区域添加映射规则:
    • 远程Claim(IDP返回的字段名):若用邮箱解析则填email,若IDP直接返回租户域名则填tenantDomain
    • 本地Claim:选择http://wso2.org/claims/tenantDomain
  • 若需通过邮箱解析租户域名,额外配置转换规则:
    进入Claim Configuration > Advanced Claim Configuration > Claim Transformations,添加一条规则:
    • 输入Claim:email
    • 转换类型:Regex Extractor
    • 正则表达式:@(.*)$(提取邮箱@后的域名部分)
    • 输出Claim:http://wso2.org/claims/tenantDomain

3. 调整deployment.toml配置

在<APIM_HOME>/repository/conf/deployment.toml中添加或修改以下配置:

[tenant_mgt]
enable_email_domain = true

[authentication.authenticator.oidc]
enable_tenant_domain_from_claim = true
  • enable_email_domain = true:允许系统通过邮箱域名识别租户
  • enable_tenant_domain_from_claim = true:开启从IDP声明中读取租户域名的功能

4. 配置服务提供商的租户识别选项

回到Carbon控制台的Identity > Service Providers > apim_publisher/apim_devportal > Local & Outbound Authentication Configuration:

  • 勾选Use tenant domain in local subject identifier
  • 确认自定义IDP已设置为该服务提供商的默认认证器

5. 验证配置

  1. 确保目标租户已在APIM中创建(比如example.com租户)
  2. 使用邮箱为user@example.com的用户通过自定义IDP登录开发者门户或发布者
  3. 登录Carbon控制台,切换到目标租户,查看用户列表,确认该用户已创建在对应租户下

注意事项

  • IDP返回的租户域名必须与APIM中已创建的租户域名完全一致,否则用户仍会被创建到carbon.super
  • 若用户已在carbon.super租户存在,需先删除该用户,重新登录才会在目标租户创建新用户
  • 确保自定义IDP的用户信息端点能正确返回所需的声明字段

内容的提问来源于stack exchange,提问作者albcar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 22:36:34