Grafana集成Keycloak配置openid等scope时获取邮箱地址错误如何解决?
问题原因
Grafana使用通用OAuth对接身份源时,默认会在配置的api_url路径后拼接/emails后缀请求邮箱地址,而Keycloak的OpenID UserInfo接口不存在该路径,邮箱字段直接包含在UserInfo接口的返回JSON中,因此触发资源不存在的报错。
解决方案
- 修改grafana.ini配置文件中
[auth.generic_oauth]配置段,新增邮箱属性映射规则,指定Grafana直接从UserInfo返回结果的根节点读取email字段,无需额外请求独立的邮箱接口:
[auth.generic_oauth] enabled = true allow_sign_up = true team_ids = allowed_organizations = name = Keycloak scopes = openid profile email client_id = grafana client_secret = ba342011-3705-483c-8e04-7f95be561cd5 auth_url = http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/auth token_url = http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/token api_url = http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/userinfo # 新增以下2行配置 email_attribute_name = email email_attribute_path = email # 若存在用户名、登录名显示异常,可额外添加以下2行配置 name_attribute_path = name login_attribute_path = preferred_username
- 验证Keycloak侧配置是否正确:
- 登录Keycloak管理后台,进入对应grafana客户端的「作用域」配置页,确认email作用域已添加
- 进入客户端「映射器」配置页,确认email映射规则存在,且「添加到用户信息」开关已开启
- 可通过以下命令手动验证UserInfo接口返回值是否包含email字段:
正常返回结果应包含curl -H "Authorization: Bearer 你获取到的Access Token" http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/userinfo"email": "你的邮箱地址"字段。 - 修改配置后重启Grafana服务,重新发起登录流程即可正常认证。
内容的提问来源于stack exchange,提问作者Ciocoiu Petrisor
相关产品推荐
相关产品推荐

