You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Apache Archiva中集成OAuth2.0并实现谷歌账号登录

Alright, let's walk through how to integrate OAuth2.0 with Apache Archiva specifically for Google account login. I’ve helped folks set this up before, so here’s a practical, step-by-step breakdown that should get you sorted:

1. Grab Your Google OAuth2.0 Credentials First

First things first, you need to set up OAuth credentials in the Google Cloud Console:

  • Head to the Google Cloud Console, create a new project (or use an existing one).
  • Navigate to APIs & Services > Credentials, then click Create Credentials > OAuth client ID.
  • When prompted, select Web application as the application type.
  • Under Authorized redirect URIs, add your Archiva callback URL. It should look like this:
    http://<your-archiva-domain>:<port>/archiva/servlet/oauth/callback/google
    (Make sure to replace <your-archiva-domain> and <port> with your actual server details—keep an eye on http vs https if you’re using SSL!)
  • Once created, copy the Client ID and Client Secret—you’ll need these for Archiva’s config.
2. Configure OAuth2.0 Support in Apache Archiva

Assuming you’re running Archiva 2.2.x or newer (these versions have built-in OAuth support), follow these steps:

  • Log into Archiva as an admin, go to Admin > Security > Authentication Providers.
  • Click Add Provider, then select OAuth2 Provider from the dropdown.
  • For the provider type, choose Google.
  • Paste the Client ID and Client Secret you copied earlier into the respective fields.
  • Set up user mapping: This tells Archiva how to turn Google’s user data into an Archiva account.
    • Use the Google email field as the Archiva username (this is usually the safest bet since emails are unique).
    • Enable Auto Create User if you want Archiva to automatically create accounts for first-time Google users.
    • Assign default roles (like user or repository-viewer) so new users have basic access right away.
3. Tweak Archiva’s Security Settings
  • Go to Admin > Security > Authentication Settings.
  • Add the OAuth2 provider to your authentication chain. You can place it before or after the default form authentication—if you put it first, users will see the Google login option right away.
  • Double-check the scope settings: Archiva should default to requesting openid email profile from Google, which gives it the necessary user data. If you need additional scopes, you can add them here, but the default should be enough for basic login.
4. Test the Login Flow
  • Restart your Archiva server to apply all config changes.
  • Go to your Archiva login page—you should now see a Login with Google button (or similar option) alongside the regular username/password form.
  • Click it, sign in with your Google account, and grant the requested permissions.
  • You should be redirected back to Archiva and logged in automatically.
  • Verify everything works: Check Admin > User Management to confirm the new user was created with the correct roles, and try accessing a repository to ensure permissions are applied.
Troubleshooting Common Issues
  • Callback URL mismatch: If you get an error after logging into Google, double-check that the redirect URI in Google Cloud Console matches exactly what’s in Archiva (including http/https, port, and path). Even a single typo will break this.
  • User not created: If auto-creation isn’t working, make sure Auto Create User is enabled in the OAuth provider settings, and that Archiva’s user registration isn’t restricted (check Admin > Security > User Management > Registration Settings).
  • Permission errors: If the logged-in user can’t do anything, confirm you assigned the right default roles in the OAuth provider config. You can always adjust roles manually later in User Management.

内容的提问来源于stack exchange,提问作者kirti kumbhar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:33:11