KeyCloak重新添加Github身份提供商后触发IDENTITY_PROVIDER_LOGIN_ERROR,federatedIdentityModel为null问题排查求助
KeyCloak重新添加Github身份提供商后触发IDENTITY_PROVIDER_LOGIN_ERROR,federatedIdentityModel为null问题排查求助
大家好,我遇到了一个KeyCloak集成Github身份提供商的棘手问题,想请各位帮忙看看:
我在K3s集群中部署了KeyCloak作为身份管理服务,它和集群里的另一项服务都部署在Nginx反向代理之后。之前我成功配置过Github作为初始身份提供商,一切正常,但后来我把它删掉了,现在重新添加回来之后,却无法再通过Github完成认证了,页面只显示dashboard_error。我确认Github那边的OAuth应用配置是没问题的——毕竟之前用这套配置完全正常。
我通过kubectl logs [pod-name] -n [namespace]查看了KeyCloak所在命名空间的Pod日志,发现了以下关键错误:
2023-12-30 11:41:56,801 WARN [org.keycloak.events] (executor-thread-311) type=REFRESH_TOKEN_ERROR, realmId=fsome-realm-id, clientId=security-admin-console, userId=null, ipAddress=internal_api_address, error=invalid_token, grant_type=refresh_token, client_auth_method=client-secret 2023-12-30 18:07:29,073 ERROR [org.keycloak.broker.oidc.AbstractOAuth2IdentityProvider] (executor-thread-320) Failed to make identity provider oauth callback: java.lang.NullPointerException: Cannot invoke "org.keycloak.models.FederatedIdentityModel.getToken()" because "federatedIdentityModel" is null at org.keycloak.services.resources.IdentityBrokerService.updateToken(IdentityBrokerService.java:1046) at org.keycloak.services.resources.IdentityBrokerService.updateFederatedIdentity(IdentityBrokerService.java:1000) at org.keycloak.services.resources.IdentityBrokerService.authenticated(IdentityBrokerService.java:611) at org.keycloak.broker.oidc.AbstractOAuth2IdentityProvider$Endpoint.authResponse(AbstractOAuth2IdentityProvider.java:517) at jdk.internal.reflect.GeneratedMethodAccessor705.invoke(Unknown Source) at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.base/java.lang.reflect.Method.invoke(Method.java:568) at org.jboss.resteasy.core.MethodInjectorImpl.invoke(MethodInjectorImpl.java:154) at org.jboss.resteasy.core.MethodInjectorImpl.invoke(MethodInjectorImpl.java:118) at org.jboss.resteasy.core.ResourceMethodInvoker.internalInvokeOnTarget(ResourceMethodInvoker.java:560) at org.jboss.resteasy.core.ResourceMethodInvoker.invokeOnTargetAfterFilter(ResourceMethodInvoker.java:452) at org.jboss.resteasy.core.ResourceMethodInvoker.lambda$invokeOnTarget$2(ResourceMethodInvoker.java:413) at org.jboss.resteasy.core.interception.jaxrs.PreMatchContainerRequestContext.filter(PreMatchContainerRequestContext.java:321) at org.jboss.resteasy.core.ResourceMethodInvoker.invokeOnTarget(ResourceMethodInvoker.java:415) at org.jboss.resteasy.core.ResourceMethodInvoker.invoke(ResourceMethodInvoker.java:378) at org.jboss.resteasy.core.ResourceLocatorInvoker.invokeOnTargetObject(ResourceLocatorInvoker.java:174) at org.jboss.resteasy.core.ResourceLocatorInvoker.invoke(ResourceLocatorInvoker.java:142) at org.jboss.resteasy.core.ResourceLocatorInvoker.invokeOnTargetObject(ResourceLocatorInvoker.java:168) at org.jboss.resteasy.core.ResourceLocatorInvoker.invoke(ResourceLocatorInvoker.java:131) at org.jboss.resteasy.core.ResourceLocatorInvoker.invoke(ResourceLocatorInvoker.java:33) at org.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:429) at org.jboss.resteasy.core.SynchronousDispatcher.lambda$invoke$4(SynchronousDispatcher.java:240) at org.jboss.resteasy.core.SynchronousDispatcher.lambda$preprocess$0(SynchronousDispatcher.java:154) at org.jboss.resteasy.core.interception.jaxrs.PreMatchContainerRequestContext.filter(PreMatchContainerRequestContext.java:321) at org.jboss.resteasy.core.SynchronousDispatcher.preprocess(SynchronousDispatcher.java:157) at org.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:229) at io.quarkus.resteasy.runtime.standalone.RequestDispatcher.service(RequestDispatcher.java:82) at io.quarkus.resteasy.runtime.standalone.VertxRequestHandler.dispatch(VertxRequestHandler.java:147) at io.quarkus.resteasy.runtime.standalone.VertxRequestHandler.handle(VertxRequestHandler.java:84) at io.quarkus.resteasy.runtime.standalone.VertxRequestHandler.handle(VertxRequestHandler.java:44) at io.vertx.ext.web.impl.RouteState.handleContext(RouteState.java:1284) at io.vertx.ext.web.impl.RoutingContextImplBase.iterateNext(RoutingContextImplBase.java:177) at io.vertx.ext.web.impl.RoutingContextImpl.next(RoutingContextImpl.java:141) at io.quarkus.vertx.http.runtime.options.HttpServerCommonHandlers$1.handle(HttpServerCommonHandlers.java:58) at io.quarkus.vertx.http.runtime.options.HttpServerCommonHandlers$1.handle(HttpServerCommonHandlers.java:36) at io.vertx.ext.web.impl.RouteState.handleContext(RouteState.java:1284) at io.vertx.ext.web.impl.RoutingContextImplBase.iterateNext(RoutingContextImplBase.java:177) at io.vertx.ext.web.impl.RoutingContextImpl.next(RoutingContextImpl.java:141) at org.keycloak.quarkus.runtime.integration.web.QuarkusRequestFilter.lambda$createBlockingHandler$0(QuarkusRequestFilter.java:82) at io.quarkus.vertx.core.runtime.VertxCoreRecorder$14.runWith(VertxCoreRecorder.java:576) at org.jboss.threads.EnhancedQueueExecutor$Task.run(EnhancedQueueExecutor.java:2513) at org.jboss.threads.EnhancedQueueExecutor$ThreadBody.run(EnhancedQueueExecutor.java:1538) at org.jboss.threads.DelegatingRunnable.run(DelegatingRunnable.java:29) at org.jboss.threads.ThreadLocalResettingRunnable.run(ThreadLocalResettingRunnable.java:29) at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) at java.base/java.lang.Thread.run(Thread.java:840) 2023-12-30 18:07:29,074 WARN [org.keycloak.events] (executor-thread-320) type=IDENTITY_PROVIDER_LOGIN_ERROR, realmId=some_realm_id, clientId=dashboard, userId=null, ipAddress=some_api_address, error=identity_provider_login_failure, identity_provider=github, redirect_uri=https://actual_server_url/, identity_provider_identity=my_github_username, code_id=3c1460c4-10ad-4f4a-80db-2e93609e70db
预期的正常行为应该是:
- federatedIdentityModel不应该为null
- 能够正常通过Github完成身份认证
有没有朋友遇到过类似的问题?知道该怎么解决这个federatedIdentityModel为null的情况吗?
备注:内容来源于stack exchange,提问作者Lois
相关产品推荐
相关产品推荐

