You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将WSO2 API Manager的Basic Auth用户名传递至后端端点

WSO2 API Manager 4.4.x 传递客户端Basic Auth信息至后端的实现方案

针对你需要将客户端Basic Auth用户名传递到后端的需求,以下是两种可行的实现方式:

一、直接传递客户端的Basic Auth请求头到后端

默认情况下WSO2 APIM会移除客户端的认证请求头,可通过自定义出站调解序列保留该头:

  • 登录API Publisher,打开目标API的Runtime Configurations标签页
  • 在Message Mediation区域,点击Add Out Sequence创建新序列,填入以下调解代码:
    <sequence xmlns="http://ws.apache.org/ns/synapse" name="PreserveClientAuthHeader">
        <!-- 复制客户端的Authorization请求头到出站消息 -->
        <header name="Authorization" action="copy" scope="transport" expression="$trp:Authorization"/>
        <!-- 保留APIM配置的后端端点认证头(若需同时传递) -->
        <property name="OUT_AUTHORIZATION" expression="$ctx:OUT_AUTHORIZATION" scope="axis2"/>
    </sequence>
    
  • 将该序列设置为API的出站序列,保存并重新发布API

二、将客户端Basic Auth用户名添加为后端查询参数

如果不需要传递完整的Auth头,可提取用户名作为查询参数传递:

  • 同样在API Publisher的Runtime Configurations -> Message Mediation中创建出站序列
  • 填入以下代码(若客户端Basic Auth已通过APIM验证,可直接用内置属性获取用户名,无需手动解码):
    <sequence xmlns="http://ws.apache.org/ns/synapse" name="AddClientUsernameParam">
        <!-- 直接获取APIM已验证的客户端用户名(更安全可靠) -->
        <property name="clientUsername" expression="$ctx:api.ut.userName" scope="default"/>
        <!-- 将用户名追加为查询参数 -->
        <property name="REST_URL_POSTFIX" expression="fn:concat($ctx:REST_URL_POSTFIX, '?clientUsername=', $ctx:clientUsername)" scope="axis2"/>
    </sequence>
    
  • 若客户端Basic Auth未通过APIM用户存储验证,需手动解码Auth头提取用户名,替换上述代码中的用户名提取部分:
    <property name="clientAuthHeader" expression="$trp:Authorization"/>
    <property name="encodedCredentials" expression="substring-after($ctx:clientAuthHeader, 'Basic ')"/>
    <property name="decodedCredentials" expression="base64Decode($ctx:encodedCredentials)"/>
    <property name="clientUsername" expression="substring-before($ctx:decodedCredentials, ':')"/>
    
  • 将序列设为API的出站序列,保存发布即可

内容的提问来源于stack exchange,提问作者Atanas Matev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 08:12:37