WSO2 IS 5.7.0:如何在UserOperationEventListener的doPostAddUser中获取AuthenticationContext
获取UserOperationEventListener中doPostAddUser方法的AuthenticationContext
嘿,我完全懂你的需求——JIT创建联合用户后,想绕过DefaultClaimHandler的过滤直接拿到原始IDP声明对吧?其实在doPostAddUser里获取AuthenticationContext很简单,咱们一步步来操作:
1. 导入必要的类
首先确保代码里引入这两个核心类:
import org.wso2.carbon.identity.core.context.AuthenticationContext; import org.wso2.carbon.identity.core.context.AuthenticationContextHolder;
2. 在doPostAddUser中获取认证上下文并读取未过滤声明
WSO2 Identity Server会把当前认证上下文存在ThreadLocal里,你可以通过AuthenticationContextHolder直接取出,然后获取未被过滤的IDP声明:
@Override public void doPostAddUser(String userName, Object credential, String[] roleList, Map<String, String> claims, String profile, UserStoreManager userStoreManager) throws UserStoreException { // 从ThreadLocal中取出当前认证上下文 AuthenticationContext authContext = AuthenticationContextHolder.getContext(); if (authContext != null) { // 获取未被DefaultClaimHandler过滤的原始IDP声明 Map<String, Object> unfilteredIdpClaims = (Map<String, Object>) authContext.getProperty(FrameworkConstants.UNFILTERED_IDP_CLAIM_VALUES); // 在这里处理你的自定义逻辑 if (unfilteredIdpClaims != null) { // 比如遍历声明做业务处理 for (Map.Entry<String, Object> entry : unfilteredIdpClaims.entrySet()) { String claimKey = entry.getKey(); Object claimValue = entry.getValue(); // 你的业务逻辑代码... } } } }
3. 关键注意点
- 空值校验:一定要先判断
authContext和unfilteredIdpClaims是否为null,毕竟有些场景(比如后台手动创建用户)不会触发认证流程,ThreadLocal里就没有上下文;但JIT是在认证流程中触发的,所以这个上下文肯定存在。 - 类型匹配:
UNFILTERED_IDP_CLAIM_VALUES对应的属性值是Map<String, Object>类型,因为IDP返回的声明可能是数组或其他非字符串类型,别直接转成Map<String, String>哦。
这样你就能直接拿到原始的IDP声明,不用依赖声明映射配置来处理啦!
内容的提问来源于stack exchange,提问作者giafar
相关产品推荐
相关产品推荐

