WSO2 APIM 4.1.0:自定义OIDC身份提供商多租户用户分配问题
实现自定义OAuth2身份提供商登录时分配用户到指定租户
可以实现,以下是针对WSO2 API Manager 4.1.0的具体操作步骤:
1. 确保身份提供商返回租户域名相关声明
你的自定义IDP以邮箱作为用户名,需确保IDP返回的JWT或用户信息中包含可提取租户域名的字段(比如邮箱的域名部分)。如果IDP支持,优先让其直接返回tenantDomain声明;若不支持,可通过邮箱字段解析获取租户域名。
2. 配置IDP的声明映射
登录Carbon控制台,进入Identity > Identity Providers > 你的自定义IDP > Claim Configuration > Basic Claim Configuration:
- 勾选Use Local Claim Dialect
- 在Claim Mapping区域添加映射规则:
- 远程Claim(IDP返回的字段名):若用邮箱解析则填
email,若IDP直接返回租户域名则填tenantDomain - 本地Claim:选择
http://wso2.org/claims/tenantDomain
- 远程Claim(IDP返回的字段名):若用邮箱解析则填
- 若需通过邮箱解析租户域名,额外配置转换规则:
进入Claim Configuration > Advanced Claim Configuration > Claim Transformations,添加一条规则:- 输入Claim:
email - 转换类型:
Regex Extractor - 正则表达式:
@(.*)$(提取邮箱@后的域名部分) - 输出Claim:
http://wso2.org/claims/tenantDomain
- 输入Claim:
3. 调整deployment.toml配置
在<APIM_HOME>/repository/conf/deployment.toml中添加或修改以下配置:
[tenant_mgt] enable_email_domain = true [authentication.authenticator.oidc] enable_tenant_domain_from_claim = true
enable_email_domain = true:允许系统通过邮箱域名识别租户enable_tenant_domain_from_claim = true:开启从IDP声明中读取租户域名的功能
4. 配置服务提供商的租户识别选项
回到Carbon控制台的Identity > Service Providers > apim_publisher/apim_devportal > Local & Outbound Authentication Configuration:
- 勾选Use tenant domain in local subject identifier
- 确认自定义IDP已设置为该服务提供商的默认认证器
5. 验证配置
- 确保目标租户已在APIM中创建(比如
example.com租户) - 使用邮箱为
user@example.com的用户通过自定义IDP登录开发者门户或发布者 - 登录Carbon控制台,切换到目标租户,查看用户列表,确认该用户已创建在对应租户下
注意事项
- IDP返回的租户域名必须与APIM中已创建的租户域名完全一致,否则用户仍会被创建到
carbon.super - 若用户已在
carbon.super租户存在,需先删除该用户,重新登录才会在目标租户创建新用户 - 确保自定义IDP的用户信息端点能正确返回所需的声明字段
内容的提问来源于stack exchange,提问作者albcar
相关产品推荐
相关产品推荐

