Ejabberd OAuth无法生成令牌及REST API配置咨询(Ubuntu16.04)
Absolutely, you’ll need to modify /etc/ejabberd/ejabberd.yml to fix both your OAuth token generation issue and enable REST API support. Let’s break down the solutions step by step, tailored to your Ubuntu 16.04 setup:
1. Fixing Ejabberd OAuth Token Generation
OAuth functionality isn’t enabled out of the box, so you’ll need to add and adjust several config sections:
Step 1: Enable OAuth in HTTP Listeners
Update your existing listen block for port 5280 to include the OAuth handler:
listen: - port: 4560 module: ejabberd_xmlrpc access_commands: {} - port: 5280 ip: "0.0.0.0" module: ejabberd_http request_handlers: "/oauth": ejabberd_oauth # Add this line # Keep any existing handlers like "/web_admin" if you have them
Step 2: Configure OAuth Settings
Add this top-level section to your config to define allowed clients, scopes, and access rules:
oauth: access: all # Adjust this to restrict access if needed allowed_scopes: - "ejabberd:admin" # For admin-level actions - "ejabberd:user" # For user-specific actions clients: - id: "your_client_id" # Replace with a unique client ID secret: "your_client_secret" # Replace with a secure secret trusted: true # Allows this client to request tokens
Step 3: Set Access Rules for OAuth
Add an access rule to let OAuth requests pass through:
access_rules: oauth: - allow: all # Or restrict to specific users/admins
Step 4: Test Token Generation
Restart ejabberd first:
sudo systemctl restart ejabberd
Then use curl to generate a token (replace placeholders with your actual values):
# Password grant flow (for user-specific tokens) curl -X POST http://your-server-ip:5280/oauth/token \ -d "grant_type=password" \ -d "username=your_username" \ -d "password=your_password" \ -d "client_id=your_client_id" \ -d "client_secret=your_client_secret" \ -d "scope=ejabberd:user" # Client credentials flow (for admin-level tokens) curl -X POST http://your-server-ip:5280/oauth/token \ -d "grant_type=client_credentials" \ -d "client_id=your_client_id" \ -d "client_secret=your_client_secret" \ -d "scope=ejabberd:admin"
2. Enabling Ejabberd REST API Support
REST API relies on mod_http_api and mod_rest modules, which need explicit configuration:
Step 1: Add REST Handlers to HTTP Listener
Update the same port 5280 listen block to include REST handlers:
listen: - port: 4560 module: ejabberd_xmlrpc access_commands: {} - port: 5280 ip: "0.0.0.0" module: ejabberd_http request_handlers: "/oauth": ejabberd_oauth "/api": mod_http_api # Add this for raw API endpoints "/rest": mod_rest # Add this for REST-formatted endpoints
Step 2: Enable Required Modules
Add these modules to the modules section of your config:
modules: # Keep your existing modules here (like mod_roster, mod_muc, etc.) mod_http_api: {} mod_rest: {}
Step 3: Configure API Access Rules
Ensure your access_rules include permissions for API requests (you can use OAuth tokens for authentication here):
access_rules: oauth: - allow: all api: - allow: admin # Allow admin users - allow: oauth # Allow requests authenticated via OAuth tokens
Step 4: Test the REST API
Use your OAuth token to make a test request, e.g., list users on your domain:
curl -H "Authorization: Bearer YOUR_GENERATED_OAUTH_TOKEN" \ http://your-server-ip:5280/rest/users/your-xmpp-domain
Note: Since you’re on Ubuntu 16.04, the default ejabberd version is older (around 16.02). Some REST API features may be limited compared to newer releases—if you hit roadblocks, you may need to reference the config documentation specific to that version.
内容的提问来源于stack exchange,提问作者Sanjay Sahu

