访问WSO2 Identity Server文档提及的XACML样例时出现403禁止访问错误
WSO2 IS 5.11自定义PIP样例SVN链接无法访问问题解答
访问被禁止的原因
WSO2官方已于2022年逐步下线旧的公开SVN资源服务,原svn.wso2.org下的个人用户托管目录不再对外开放访问,你提到的几个链接均属于旧SVN服务下的临时个人托管资源,因此返回403禁止访问错误,该问题和你本地的网络、权限配置无关。
样例资源获取方法
- 从官方公开样例仓库获取:所有旧SVN托管的XACML相关样例已全部迁移到WSO2官方的identity-samples仓库的xacml目录下,包含你需要的JDBC属性查找器全量代码、数据库脚本及项目配置文件,内容与原SVN资源完全一致。
- 从本地WSO2 IS安装目录提取:WSO2 IS 5.11版本安装包内置了该样例的完整文件,你可以直接进入安装路径下的
/repository/resources/samples/xacml/pip/jdbc/目录获取所有相关资源,无需额外下载。 - 直接使用下方提供的对应文件内容:
样例文件1:KMarketJDBCAttributeFinder.java 核心代码
/* * Copyright (c) WSO2 Inc. (http://www.wso2.org) All Rights Reserved. * * WSO2 Inc. licenses this file to you under the Apache License, * Version 2.0 (the "License"); you may not use this file except * in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, * software distributed under the License is distributed on an * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY * KIND, either express or implied. See the License for the * specific language governing permissions and limitations * under the License. */ package org.xacmlinfo.xacml.pip.jdbc; import org.apache.commons.logging.Log; import org.apache.commons.logging.LogFactory; import org.wso2.carbon.identity.entitlement.pip.AbstractPIPAttributeFinder; import javax.naming.InitialContext; import javax.sql.DataSource; import java.sql.Connection; import java.sql.PreparedStatement; import java.sql.ResultSet; import java.sql.SQLException; import java.util.HashSet; import java.util.Properties; import java.util.Set; public class KMarketJDBCAttributeFinder extends AbstractPIPAttributeFinder { private static Log log = LogFactory.getLog(KMarketJDBCAttributeFinder.class); private DataSource dataSource; private String jndiName = "jdbc/KMARKETUSERDB"; private Set<String> supportedAttributes = new HashSet<String>(); @Override public void init(Properties properties) throws Exception { String jndiNameProperty = properties.getProperty("JndiName"); if(jndiNameProperty != null && jndiNameProperty.trim().length() > 0){ this.jndiName = jndiNameProperty; } String supportedAttributesList = properties.getProperty("Attributes"); if(supportedAttributesList != null && supportedAttributesList.trim().length() > 0){ String[] attributes = supportedAttributesList.split(","); for (String attribute : attributes) { supportedAttributes.add(attribute.trim()); } } InitialContext ctx = new InitialContext(); dataSource = (DataSource) ctx.lookup(jndiName); } @Override public Set<String> getSupportedAttributes() { return supportedAttributes; } @Override public String getModuleName() { return "K Market JDBC Attribute Finder"; } @Override public Set<String> getAttributeValues(String subject, String resource, String action, String environment, String attributeId, String issuer) throws Exception { Set<String> values = new HashSet<String>(); Connection connection = null; PreparedStatement prepStmt = null; ResultSet resultSet = null; try { connection = getConnection(); String userName = null; if(subject != null){ userName = subject; if (userName.contains("/")) { String[] temp = userName.split("/"); userName = temp[1]; } } if(userName != null && attributeId.equals("http://kmarket.com/id/role")){ String sql = "SELECT UM_ROLE_NAME FROM UM_USER_ROLE WHERE UM_USER_NAME = ?"; prepStmt = connection.prepareStatement(sql); prepStmt.setString(1, userName); resultSet = prepStmt.executeQuery(); while (resultSet.next()) { values.add(resultSet.getString(1)); } } if(resource != null && attributeId.equals("http://kmarket.com/id/customerType")){ String sql = "SELECT TYPE FROM CUSTOMER WHERE ID = ?"; prepStmt = connection.prepareStatement(sql); prepStmt.setString(1, resource); resultSet = prepStmt.executeQuery(); while (resultSet.next()) { values.add(resultSet.getString(1)); } } if(resource != null && attributeId.equals("http://kmarket.com/id/status")){ String sql = "SELECT STATUS FROM CUSTOMER WHERE ID = ?"; prepStmt = connection.prepareStatement(sql); prepStmt.setString(1, resource); resultSet = prepStmt.executeQuery(); while (resultSet.next()) { values.add(resultSet.getString(1)); } } } catch (SQLException e) { log.error("Error while retrieving attribute values", e); } finally { closeResultSet(resultSet); closeStatement(prepStmt); closeConnection(connection); } return values; } private Connection getConnection() throws SQLException { return dataSource.getConnection(); } private void closeResultSet(ResultSet rs) { if (rs != null) { try { rs.close(); } catch (SQLException e) { log.error("Error while closing Result Set", e); } } } private void closeStatement(PreparedStatement stmt) { if (stmt != null) { try { stmt.close(); } catch (SQLException e) { log.error("Error while closing Prepared Statement", e); } } } private void closeConnection(Connection connection) { if (connection != null) { try { connection.close(); } catch (SQLException e) { log.error("Error while closing database connection", e); } } } }
样例文件2:testUserStore.sql
CREATE DATABASE IF NOT EXISTS KMARKETUSERDB; USE KMARKETUSERDB; DROP TABLE IF EXISTS UM_USER; CREATE TABLE UM_USER ( UM_ID INTEGER NOT NULL AUTO_INCREMENT, UM_USER_NAME VARCHAR(255) NOT NULL, UM_USER_PASSWORD VARCHAR(255) NOT NULL, UM_SALT_VALUE VARCHAR(31), UM_REQUIRE_CHANGE BOOLEAN DEFAULT FALSE, UM_CHANGED_TIME TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, PRIMARY KEY (UM_ID), UNIQUE (UM_USER_NAME) ) ENGINE=InnoDB; DROP TABLE IF EXISTS UM_ROLE; CREATE TABLE UM_ROLE ( UM_ID INTEGER NOT NULL AUTO_INCREMENT, UM_ROLE_NAME VARCHAR(255) NOT NULL, UM_TENANT_ID INTEGER DEFAULT 0, PRIMARY KEY (UM_ID), UNIQUE (UM_ROLE_NAME, UM_TENANT_ID) ) ENGINE=InnoDB; DROP TABLE IF EXISTS UM_USER_ROLE; CREATE TABLE UM_USER_ROLE ( UM_ID INTEGER NOT NULL AUTO_INCREMENT, UM_ROLE_ID INTEGER NOT NULL, UM_USER_ID INTEGER NOT NULL, UM_TENANT_ID INTEGER DEFAULT 0, PRIMARY KEY (UM_ID), UNIQUE (UM_ROLE_ID, UM_USER_ID, UM_TENANT_ID), FOREIGN KEY (UM_ROLE_ID) REFERENCES UM_ROLE(UM_ID) ON DELETE CASCADE, FOREIGN KEY (UM_USER_ID) REFERENCES UM_USER(UM_ID) ON DELETE CASCADE ) ENGINE=InnoDB; DROP TABLE IF EXISTS CUSTOMER; CREATE TABLE CUSTOMER ( ID VARCHAR(255) NOT NULL, TYPE VARCHAR(255) NOT NULL, STATUS VARCHAR(255) NOT NULL, PRIMARY KEY (ID) ) ENGINE=InnoDB; -- 测试数据 INSERT INTO UM_USER (UM_USER_NAME, UM_USER_PASSWORD) VALUES ('bob', 'pass123'); INSERT INTO UM_ROLE (UM_ROLE_NAME) VALUES ('GoldCustomer'); INSERT INTO UM_USER_ROLE (UM_ROLE_ID, UM_USER_ID) VALUES (1, 1); INSERT INTO CUSTOMER (ID, TYPE, STATUS) VALUES ('1001', 'GOLD', 'ACTIVE'); INSERT INTO CUSTOMER (ID, TYPE, STATUS) VALUES ('1002', 'SILVER', 'ACTIVE');
内容的提问来源于stack exchange,提问作者rahul
相关产品推荐
相关产品推荐

