You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 API Manager与Keyrock角色权限问题求助

WSO2 API Manager 4.1.0 对接Keyrock身份提供商非管理员账号403权限问题

问题现象

在Debian 10机器上通过ZIP包部署WSO2 API Manager 4.1.0,并将Keyrock实例配置为外部身份提供商后:

  • Keyrock管理员账号可正常访问API Manager的Publisher控制台
  • 其他Keyrock账号登录后触发Error 403 : Forbidden - The server could not verify that you are authorized to access the requested resource.

已验证的配置

WSO2 API Manager侧配置

  • 基础声明配置(Basic Claim Configuration)
  • 角色配置(Role Configuration):已尝试为用户赋予全部角色
  • OAuth2/OpenID Connect联合认证器配置
  • 即时配置(Just-in-Time Provisioning)

Keyrock侧配置

  • 应用配置(Application configuration)
  • 用户授权配置(Users authorization)

补充排查信息

  • 出现403错误时,WSO2无相关日志输出
  • Keyrock返回给WSO2的JWT令牌内容:
{
  "organizations": [],
  "displayName": "",
  "roles": [
    {
      "id": "1a209432-7bfe-4055-9028-a42524fc5418",
      "name": "publisher"
    },
    {
      "id": "8192fef7-d77d-4389-a618-082ccddd33ad",
      "name": "apim_publisher"
    }
  ],
  "app_id": "babab169-10ea-4283-a64a-7fba4aca6ce9",
  "trusted_apps": [],
  "isGravatarEnabled": false,
  "id": "1a8f660f-d32f-46c1-a5f5-80a5cbffd219",
  "authorization_decision": "",
  "app_azf_domain": "",
  "eidas_profile": {},
  "attributes": {},
  "shared_attributes": "",
  "username": "pierre.josselin",
  "email": "email@example.com",
  "image": "",
  "gravatar": "",
  "extra": "",
  "iss": "http://localhost:3000",
  "sub": "1a8f660f-d32f-46c1-a5f5-80a5cbffd219",
  "aud": "babab169-10ea-4283-a64a-7fba4aca6ce9",
  "exp": 1657904225,
  "iat": 1657900625,
  "at_hash": "9zTg2zPtFlbJpLmKE8Izsg=="
}

内容的提问来源于stack exchange,提问作者user19509066

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 19:45:55