如何访问Liferay Portal中OpenID Connect流程存储的会话数据与令牌?
Hey Robert, let's tackle your problem step by step. I've worked with Liferay's OpenID Connect integration before, so here's what you need to know:
Why OPEN_ID_CONNECT_SESSION returns null
Directly fetching the attribute from HttpSession fails for two key reasons:
- Liferay encapsulates OpenID Connect session data within its own service layer, not as a raw HttpSession attribute (the internal attribute name might even be non-public or scoped differently across versions).
- Portlet vs. Servlet session context differences: Liferay uses wrapped sessions for portlets, and the OpenID Connect session might be stored in the application scope rather than the default portlet scope, which your current HttpSession call might not access correctly.
How to properly retrieve the OpenID Connect session & access token
The recommended approach is to use Liferay's official OpenID Connect service API, which is designed for this exact use case. Here's a working code example:
import com.liferay.portal.kernel.service.ServiceContext; import com.liferay.portal.kernel.service.ServiceContextThreadLocal; import com.liferay.portal.security.sso.openid.connect.OpenIdConnectSession; import com.liferay.portal.security.sso.openid.connect.OpenIdConnectSessionService; // Get the current ServiceContext (handles Liferay's service scope) ServiceContext serviceContext = ServiceContextThreadLocal.getServiceContext(); // Retrieve the OpenIdConnectSessionService instance OpenIdConnectSessionService openIdConnectSessionService = serviceContext.getService(OpenIdConnectSessionService.class); // Fetch the session object safely OpenIdConnectSession openIdConnectSession = openIdConnectSessionService.getOpenIdConnectSession(); if (openIdConnectSession != null) { String apiAccessToken = openIdConnectSession.getAccessToken(); // Use this token to call your internal APIs }
If you absolutely need to work with the session directly (not recommended, as it ties you to internal implementation details), you can try accessing the application-scoped portlet session:
import javax.portlet.PortletSession; PortletSession portletSession = actionRequest.getPortletSession(); OpenIdConnectSession openIdConnectSession = (OpenIdConnectSession) portletSession.getAttribute( "OPEN_ID_CONNECT_SESSION", PortletSession.APPLICATION_SCOPE);
Just note that this might break if Liferay changes internal attribute naming in future updates.
Does Liferay 7.2 support your use case?
Absolutely. Liferay's OpenID Connect integration is explicitly designed to handle scenarios where you need to use the returned access token for downstream API calls. The official service API ensures you can safely retrieve the token without relying on fragile internal session attributes.
Make sure your portlet or custom component has the necessary dependencies:
- Add
com.liferay.portal.security.sso.openid.connectto yourbnd.bndfile'sImport-Packagesection. - Ensure your code runs within a valid Liferay service context (the example above handles this via
ServiceContextThreadLocal).
内容的提问来源于stack exchange,提问作者Robert Engel

