You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

访问WSO2 Identity Server文档提及的XACML样例时出现403禁止访问错误

WSO2 IS 5.11自定义PIP样例SVN链接无法访问问题解答

访问被禁止的原因

WSO2官方已于2022年逐步下线旧的公开SVN资源服务,原svn.wso2.org下的个人用户托管目录不再对外开放访问,你提到的几个链接均属于旧SVN服务下的临时个人托管资源,因此返回403禁止访问错误,该问题和你本地的网络、权限配置无关。

样例资源获取方法

  • 从官方公开样例仓库获取:所有旧SVN托管的XACML相关样例已全部迁移到WSO2官方的identity-samples仓库的xacml目录下,包含你需要的JDBC属性查找器全量代码、数据库脚本及项目配置文件,内容与原SVN资源完全一致。
  • 从本地WSO2 IS安装目录提取:WSO2 IS 5.11版本安装包内置了该样例的完整文件,你可以直接进入安装路径下的/repository/resources/samples/xacml/pip/jdbc/目录获取所有相关资源,无需额外下载。
  • 直接使用下方提供的对应文件内容:

样例文件1:KMarketJDBCAttributeFinder.java 核心代码

/*
 *  Copyright (c) WSO2 Inc. (http://www.wso2.org) All Rights Reserved.
 *
 *  WSO2 Inc. licenses this file to you under the Apache License,
 *  Version 2.0 (the "License"); you may not use this file except
 *  in compliance with the License.
 *  You may obtain a copy of the License at
 *
 *    http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing,
 * software distributed under the License is distributed on an
 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
 * KIND, either express or implied.  See the License for the
 * specific language governing permissions and limitations
 * under the License.
 */
package org.xacmlinfo.xacml.pip.jdbc;

import org.apache.commons.logging.Log;
import org.apache.commons.logging.LogFactory;
import org.wso2.carbon.identity.entitlement.pip.AbstractPIPAttributeFinder;

import javax.naming.InitialContext;
import javax.sql.DataSource;
import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.util.HashSet;
import java.util.Properties;
import java.util.Set;

public class KMarketJDBCAttributeFinder extends AbstractPIPAttributeFinder {

    private static Log log = LogFactory.getLog(KMarketJDBCAttributeFinder.class);
    private DataSource dataSource;
    private String jndiName = "jdbc/KMARKETUSERDB";
    private Set<String> supportedAttributes = new HashSet<String>();

    @Override
    public void init(Properties properties) throws Exception {
        String jndiNameProperty = properties.getProperty("JndiName");
        if(jndiNameProperty != null && jndiNameProperty.trim().length() > 0){
            this.jndiName = jndiNameProperty;
        }
        String supportedAttributesList = properties.getProperty("Attributes");
        if(supportedAttributesList != null && supportedAttributesList.trim().length() > 0){
            String[] attributes = supportedAttributesList.split(",");
            for (String attribute : attributes) {
                supportedAttributes.add(attribute.trim());
            }
        }
        InitialContext ctx = new InitialContext();
        dataSource = (DataSource) ctx.lookup(jndiName);
    }

    @Override
    public Set<String> getSupportedAttributes() {
        return supportedAttributes;
    }

    @Override
    public String getModuleName() {
        return "K Market JDBC Attribute Finder";
    }

    @Override
    public Set<String> getAttributeValues(String subject, String resource, String action, String environment,
                                          String attributeId, String issuer) throws Exception {
        Set<String> values = new HashSet<String>();
        Connection connection = null;
        PreparedStatement prepStmt = null;
        ResultSet resultSet = null;
        try {
            connection = getConnection();
            String userName = null;
            if(subject != null){
                userName = subject;
                if (userName.contains("/")) {
                    String[] temp = userName.split("/");
                    userName = temp[1];
                }
            }
            if(userName != null && attributeId.equals("http://kmarket.com/id/role")){
                String sql = "SELECT UM_ROLE_NAME FROM UM_USER_ROLE WHERE UM_USER_NAME = ?";
                prepStmt = connection.prepareStatement(sql);
                prepStmt.setString(1, userName);
                resultSet = prepStmt.executeQuery();
                while (resultSet.next()) {
                    values.add(resultSet.getString(1));
                }
            }
            if(resource != null && attributeId.equals("http://kmarket.com/id/customerType")){
                String sql = "SELECT TYPE FROM CUSTOMER WHERE ID = ?";
                prepStmt = connection.prepareStatement(sql);
                prepStmt.setString(1, resource);
                resultSet = prepStmt.executeQuery();
                while (resultSet.next()) {
                    values.add(resultSet.getString(1));
                }
            }
            if(resource != null && attributeId.equals("http://kmarket.com/id/status")){
                String sql = "SELECT STATUS FROM CUSTOMER WHERE ID = ?";
                prepStmt = connection.prepareStatement(sql);
                prepStmt.setString(1, resource);
                resultSet = prepStmt.executeQuery();
                while (resultSet.next()) {
                    values.add(resultSet.getString(1));
                }
            }
        } catch (SQLException e) {
            log.error("Error while retrieving attribute values", e);
        } finally {
            closeResultSet(resultSet);
            closeStatement(prepStmt);
            closeConnection(connection);
        }
        return values;
    }

    private Connection getConnection() throws SQLException {
        return dataSource.getConnection();
    }

    private void closeResultSet(ResultSet rs) {
        if (rs != null) {
            try {
                rs.close();
            } catch (SQLException e) {
                log.error("Error while closing Result Set", e);
            }
        }
    }

    private void closeStatement(PreparedStatement stmt) {
        if (stmt != null) {
            try {
                stmt.close();
            } catch (SQLException e) {
                log.error("Error while closing Prepared Statement", e);
            }
        }
    }

    private void closeConnection(Connection connection) {
        if (connection != null) {
            try {
                connection.close();
            } catch (SQLException e) {
                log.error("Error while closing database connection", e);
            }
        }
    }
}

样例文件2:testUserStore.sql

CREATE DATABASE IF NOT EXISTS KMARKETUSERDB;
USE KMARKETUSERDB;

DROP TABLE IF EXISTS UM_USER;
CREATE TABLE UM_USER (
    UM_ID INTEGER NOT NULL AUTO_INCREMENT,
    UM_USER_NAME VARCHAR(255) NOT NULL,
    UM_USER_PASSWORD VARCHAR(255) NOT NULL,
    UM_SALT_VALUE VARCHAR(31),
    UM_REQUIRE_CHANGE BOOLEAN DEFAULT FALSE,
    UM_CHANGED_TIME TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
    PRIMARY KEY (UM_ID),
    UNIQUE (UM_USER_NAME)
) ENGINE=InnoDB;

DROP TABLE IF EXISTS UM_ROLE;
CREATE TABLE UM_ROLE (
    UM_ID INTEGER NOT NULL AUTO_INCREMENT,
    UM_ROLE_NAME VARCHAR(255) NOT NULL,
    UM_TENANT_ID INTEGER DEFAULT 0,
    PRIMARY KEY (UM_ID),
    UNIQUE (UM_ROLE_NAME, UM_TENANT_ID)
) ENGINE=InnoDB;

DROP TABLE IF EXISTS UM_USER_ROLE;
CREATE TABLE UM_USER_ROLE (
    UM_ID INTEGER NOT NULL AUTO_INCREMENT,
    UM_ROLE_ID INTEGER NOT NULL,
    UM_USER_ID INTEGER NOT NULL,
    UM_TENANT_ID INTEGER DEFAULT 0,
    PRIMARY KEY (UM_ID),
    UNIQUE (UM_ROLE_ID, UM_USER_ID, UM_TENANT_ID),
    FOREIGN KEY (UM_ROLE_ID) REFERENCES UM_ROLE(UM_ID) ON DELETE CASCADE,
    FOREIGN KEY (UM_USER_ID) REFERENCES UM_USER(UM_ID) ON DELETE CASCADE
) ENGINE=InnoDB;

DROP TABLE IF EXISTS CUSTOMER;
CREATE TABLE CUSTOMER (
    ID VARCHAR(255) NOT NULL,
    TYPE VARCHAR(255) NOT NULL,
    STATUS VARCHAR(255) NOT NULL,
    PRIMARY KEY (ID)
) ENGINE=InnoDB;

-- 测试数据
INSERT INTO UM_USER (UM_USER_NAME, UM_USER_PASSWORD) VALUES ('bob', 'pass123');
INSERT INTO UM_ROLE (UM_ROLE_NAME) VALUES ('GoldCustomer');
INSERT INTO UM_USER_ROLE (UM_ROLE_ID, UM_USER_ID) VALUES (1, 1);
INSERT INTO CUSTOMER (ID, TYPE, STATUS) VALUES ('1001', 'GOLD', 'ACTIVE');
INSERT INTO CUSTOMER (ID, TYPE, STATUS) VALUES ('1002', 'SILVER', 'ACTIVE');

内容的提问来源于stack exchange,提问作者rahul

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 03:54:04