【发布时间】:2018-09-16 18:31:33
【问题描述】:
我一直使用 WSO2IS 作为 OIDC 提供商。我已经实现了一个自定义声明处理程序,它工作正常,并且在 WSO2 接收到 grant_type“Authorization_code”时被调用。当服务提供商使用grant_type=password 发送请求时,问题就开始了。在这种情况下,WSO2 成功验证了用户并返回了 JWT,但是......没有自定义声明,因为 WSO2 没有调用自定义声明处理程序。
这是我在文件<IS_HOME>/repository/conf/identity/application-authentication.xml 中为grant_type=authorization_code 调用的自定义声明处理程序所做的配置。
<ClaimHandler>com.wso2.carbon.identity.custom.claim.handler.CustomClaimHandler</ClaimHandler>
这是来自 WSO2 的调试日志:
TID:[-1234] [] [2018-04-06 11:34:38,199] 调试 {org.wso2.carbon.identity.auth.service.handler.HandlerManager} - 为 org.wso2.carbon.identity.auth.service.handler.HandlerManager TID: [-1234] [] [2018-04-06 11:34:38,200] 调试 {org.wso2.carbon.identity.auth.service.handler.HandlerManager} - 获取 给定处理程序列表的第一优先级处理程序。 TID:[-1234] [] [2018-04-06 11:34:38,200] 调试 {org.wso2.carbon.identity.auth.service.handler.HandlerManager} - 获取 第一优先级处理程序: DefaultAuthenticationManager(org.wso2.carbon.identity.auth.service.AuthenticationManager) TID:[-1234] [] [2018-04-06 11:34:38,205] 调试 {org.wso2.carbon.identity.oauth2.OAuth2Service} - 访问令牌 收到客户端 ID EjQvbCf0pclp6eVO5lxTq23_lxQa 的请求,用户 ID userldap, Scope : [ openid, email] 和 Grant Type : 密码 TID: [-1234] [] [2018-04-06 11:34:38,205] 调试 {org.wso2.carbon.identity.oauth2.token.handlers.clientauth.AbstractClientAuthHandler} - 可以使用客户端 ID 和 Secret 进行身份验证。客户端 ID:EjQvbCf0pclp6eVO5lxTq23_lxQa TID:[-1234] [] [2018-04-06 11:34:38,205] 调试 {org.wso2.carbon.identity.oauth2.token.handlers.clientauth.AbstractClientAuthHandler} - 授权类型:密码严格客户端验证设置为:空 TID:[-1234] [] [2018-04-06 11:34:38,206] DEBUG {org.wso2.carbon.identity.oauth2.util.OAuth2Util} - 客户端 凭据是从数据库中获取的。 TID:[-1234] [] [2018-04-06 11:34:38,206] 调试 {org.wso2.carbon.identity.oauth2.util.OAuth2Util} - 成功 使用客户端 ID 对客户端进行身份验证:EjQvbCf0pclp6eVO5lxTq23_lxQa TID:[-1234] [] [2018-04-06 11:34:38,207] 调试 {org.wso2.carbon.identity.oauth2.token.AccessTokenIssuer} - Oauth 应用 消费者密钥验证成功:EjQvbCf0pclp6eVO5lxTq23_lxQa TID:[-1234] [] [2018-04-06 11:34:38,209] 调试 {org.wso2.carbon.identity.governance.listener.IdentityMgtEventListener} - 在 IdentityMgtEventListener TID 中调用预验证器:[-1234] [] [2018-04-06 11:34:38,210] DEBUG {org.wso2.carbon.identity.claim.metadata.mgt.dao.CacheBackedLocalClaimDAO} - 租户本地声明列表的缓存命中:-1234 TID:[-1234] [] [2018-04-06 11:34:38,210] 调试 {org.wso2.carbon.identity.claim.metadata.mgt.DefaultClaimMetadataStore} - 分配的映射属性:来自用户存储域的引用:主要用于声明:http://wso2.org/claims/identity/accountDisabled 在租户中 :-1234 TID:[-1234] [] [2018-04-06 11:34:38,215] 调试 {org.wso2.carbon.identity.claim.metadata.mgt.dao.CacheBackedLocalClaimDAO} - 租户本地声明列表的缓存命中:-1234 TID:[-1234] [] [2018-04-06 11:34:38,215] 调试 {org.wso2.carbon.identity.governance.listener.IdentityMgtEventListener} - 在 IdentityMgtEventListener TID 中调用发布获取用户声明值:[-1234] [] [2018-04-06 11:34:38,215] DEBUG {org.wso2.carbon.identity.core.util.IdentityUtil} - 出错时 读取用户存储属性 CaseInsensitiveUsername。考虑为 区分大小写。 TID:[-1234] [] [2018-04-06 11:34:38,215] 调试 {org.wso2.carbon.identity.governance.store.InMemoryIdentityDataStore} - 从缓存中为用户加载 UserIdentityClaimsDO:userldap 声明:{} TID:[-1234] [] [2018-04-06 11:34:38,215] 调试 {org.wso2.carbon.identity.recovery.handler.AdminForcedPasswordResetHandler} - 处理事件:PRE_AUTHENTICATION TID:[-1234] [] [2018-04-06 11:34:38,215] DEBUG {org.wso2.carbon.identity.recovery.handler.AdminForcedPasswordResetHandler} - PreAuthenticate - AdminForcedPasswordResetHandler 用户:userldap@carbon.super TID:[-1234] [] [2018-04-06 11:34:38,215] 调试 {org.wso2.carbon.identity.core.util.IdentityUtil} - 出错时 读取用户存储属性 CaseInsensitiveUsername。考虑为 区分大小写。 TID:[-1234] [] [2018-04-06 11:34:38,216] 调试 {org.wso2.carbon.identity.recovery.handler.AccountConfirmationValidationHandler} - 预验证 TID:[-1234] [] [2018-04-06 11:34:38,216] 调试 {org.wso2.carbon.identity.claim.metadata.mgt.dao.CacheBackedLocalClaimDAO} - 缓存命中租户的本地声明列表:-1234 TID:[-1234] [] [2018-04-06 11:34:38,217] 调试 {org.wso2.carbon.identity.claim.metadata.mgt.DefaultClaimMetadataStore} - 分配的映射属性:来自用户存储域的 accountLock:主要用于声明:http://wso2.org/claims/identity/accountLocked in 租户:-1234 TID:[-1234] [] [2018-04-06 11:34:38,218] 调试 {org.wso2.carbon.identity.claim.metadata.mgt.dao.CacheBackedLocalClaimDAO} - 缓存命中租户的本地声明列表:-1234 TID:[-1234] [] [2018-04-06 11:34:38,218] 调试 {org.wso2.carbon.identity.governance.listener.IdentityMgtEventListener} - 在 IdentityMgtEventListener TID 中调用发布获取用户声明值:[-1234] [] [2018-04-06 11:34:38,218] 调试 {org.wso2.carbon.identity.core.util.IdentityUtil} - 出错时 读取用户存储属性 CaseInsensitiveUsername。考虑为 区分大小写。 TID:[-1234] [] [2018-04-06 11:34:38,218] 调试 {org.wso2.carbon.identity.governance.store.InMemoryIdentityDataStore} - 从缓存中为用户加载 UserIdentityClaimsDO:userldap 声明:{} TID:[-1234] [] [2018-04-06 11:34:38,218] 调试 {org.wso2.carbon.identity.application.common.processors.RandomPasswordProcessor} - 找不到随机密码容器 TID 的缓存密钥:[-1234] [] [2018-04-06 11:34:38,222] 调试 {org.wso2.carbon.identity.governance.listener.IdentityMgtEventListener} - 在 IdentityMgtEventListener TID 中调用后验证器:[-1234] [] [2018-04-06 11:34:38,222] DEBUG {org.wso2.carbon.identity.application.common.processors.RandomPasswordProcessor} - 找不到随机密码容器 TID 的缓存密钥:[-1234] [] [2018-04-06 11:34:38,223] 调试 {org.wso2.carbon.identity.application.common.processors.RandomPasswordProcessor} - 找不到随机密码容器 TID 的缓存密钥:[-1234] [] [2018-04-06 11:34:38,223] 调试 {org.wso2.carbon.identity.oauth2.token.handlers.grant.PasswordGrantHandler} - 收到带有密码授予类型的令牌请求。用户名:userldap@carbon.superScope:电子邮件 openid,身份验证状态: 真实 TID:[-1234] [] [2018-04-06 11:34:38,223] 调试 {org.wso2.carbon.identity.oauth.callback.OAuthCallbackHandlerRegistry} - 为回调找到 OAuthCallbackHandler。类名:org.wso2.carbon.identity.oauth.callback.DefaultCallbackHandler 资源所有者:userldap@carbon.super 客户 ID: EjQvbCf0pclp6eVO5lxTq23_lxQa 范围:电子邮件 openid TID:[-1234] [] [2018-04-06 11:34:38,223] 调试 {org.wso2.carbon.identity.oauth.callback.OAuthCallbackHandlerRegistry} - 为回调找到 OAuthCallbackHandler。类名:org.wso2.carbon.identity.oauth.callback.DefaultCallbackHandler 资源所有者:userldap@carbon.super 客户 ID: EjQvbCf0pclp6eVO5lxTq23_lxQa 范围:电子邮件 openid TID:[-1234] [] [2018-04-06 11:34:38,223] 调试 {org.wso2.carbon.identity.oauth2.util.OAuth2Util} - 添加 OAuthTokenReqMessageContext 到线程本地 TID:[-1234] [] [2018-04-06 11:34:38,223] 调试 {org.wso2.carbon.identity.core.util.IdentityUtil} - 出错时 读取用户存储属性 CaseInsensitiveUsername。考虑为 区分大小写。 TID:[-1234] [] [2018-04-06 11:34:38,223] 调试 {org.wso2.carbon.identity.oauth2.util.OAuth2Util} - SP 明智的令牌 到期时间功能适用于租户 ID:-1234 和消费者密钥: EjQvbCf0pclp6eVO5lxTq23_lxQa TID:[-1234] [] [2018-04-06 11:34:38,224] 调试 {org.wso2.carbon.identity.oauth2.token.handlers.grant.AbstractAuthorizationGrantHandler} - 为应用程序启用服务提供商特定的到期时间:EjQvbCf0pclp6eVO5lxTq23_lxQa。应用程序访问令牌到期时间: null,用户访问令牌到期时间:null,刷新令牌到期时间 :空 TID:[-1234] [] [2018-04-06 11:34:38,224] 调试 {org.wso2.carbon.identity.oauth2.token.handlers.grant.AbstractAuthorizationGrantHandler} - OAuth 应用程序 ID:EjQvbCf0pclp6eVO5lxTq23_lxQa,访问令牌有效时间(以毫秒为单位):3600000 TID:[-1234] [] [2018-04-06 11:34:38,224] 调试 {org.wso2.carbon.identity.core.util.IdentityUtil} - 读取用户存储属性 CaseInsensitiveUsername 时出错。考虑区分大小写。 TID: [-1234] [] [2018-04-06 11:34:38,230] 调试 {org.wso2.carbon.identity.oauth2.token.handlers.grant.AbstractAuthorizationGrantHandler} - 无限期访问令牌 e88de89f-70d4-33d5-b447-5cd0135fd682 在缓存 TID 中找到:[-1234] [] [2018-04-06 11:34:38,230] 调试 {org.wso2.carbon.identity.oauth2.util.OAuth2Util} - 清除 OAuthTokenReqMessageContext TID:[-1234] [] [2018-04-06 11:34:38,230] 调试 {org.wso2.carbon.identity.oauth2.token.AccessTokenIssuer} - 颁发给客户端 ID 的访问令牌:EjQvbCf0pclp6eVO5lxTq23_lxQa 用户名:userldap@carbon.super 和范围:电子邮件 openid TID: [-1234] [] [2018-04-06 11:34:38,230] 调试 {org.wso2.carbon.identity.oauth2.token.AccessTokenIssuer} - 发行 客户端的 ID 令牌:EjQvbCf0pclp6eVO5lxTq23_lxQa TID:[-1234] [] [2018-04-06 11:34:38,230] 调试 {org.wso2.carbon.identity.application.common.processors.RandomPasswordProcessor} - 找不到随机密码容器 TID 的缓存密钥:[-1234] [] [2018-04-06 11:34:38,232] 调试 {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 加载AdministradorOmnicanalidad TID的基本应用数据:[-1234] [] [2018-04-06 11:34:38,232] DEBUG {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - ApplicationID: 21 ApplicationName: AdministradorOmnicanalidad UserName: userldap TenantDomain: carbon.super TID: [-1234] [] [2018-04-06 11:34:38,232] 调试 {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序 21 TID 的客户端:[-1234] [] [2018-04-06 11:34:38,233] DEBUG {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序 21 TID 的步骤:[-1234] [] [2018-04-06 11:34:38,236] DEBUG {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序 21 TID 的声明映射:[-1234] [] [2018-04-06 11:34:38,237] 调试 {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序 21 TID 的角色映射:[-1234] [] [2018-04-06 11:34:38,241] DEBUG {org.wso2.carbon.identity.core.util.IdentityUtil} - 读取用户存储属性 CaseInsensitiveUsername 时出错。考虑区分大小写。 TID: [-1234] [] [2018-04-06 11:34:38,241] 调试 {org.wso2.carbon.identity.oauth2.dao.TokenMgtDAO} - 检索 tokenId 的访问令牌:e88de89f-70d4-33d5-b447-5cd0135fd682 带有标志 includeExpired: false TID:[-1234] [] [2018-04-06 11:34:38,244] 调试 {org.wso2.carbon.identity.openidconnect.DefaultIDTokenBuilder} - 使用 issuer https://localhost:9445/oauth2/token Subject userldap ID 令牌生命周期 3600 当前时间 1523032478 Nonce 值 null 签名算法 RS256 TID:[-1234] [] [2018-04-06 11:34:38,244] 调试 {org.wso2.carbon.identity.openidconnect.SAMLAssertionClaimsCallback} - 将用户 userldap@carbon.super 的声明添加到 id 令牌。时间: [-1234] [] [2018-04-06 11:34:38,247] 调试 {org.wso2.carbon.identity.openidconnect.SAMLAssertionClaimsCallback} - 在缓存中找不到用户属性。试图检索属性 用户 userldap@carbon.super TID:[-1234] [] [2018-04-06 11:34:38,249] 调试 {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 加载AdministradorOmnicanalidad TID的基本应用数据:[-1234] [] [2018-04-06 11:34:38,251] DEBUG {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - ApplicationID: 21 ApplicationName: AdministradorOmnicanalidad UserName: userldap TenantDomain: carbon.super TID: [-1234] [] [2018-04-06 11:34:38,251] 调试 {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序 21 TID 的客户端:[-1234] [] [2018-04-06 11:34:38,251] DEBUG {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序 21 TID 的步骤:[-1234] [] [2018-04-06 11:34:38,255] DEBUG {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序 21 TID 的声明映射:[-1234] [] [2018-04-06 11:34:38,256] 调试 {org.wso2.carbon.identity.application.mgt.dao.impl.ApplicationDAOImpl} - 读取应用程序的角色映射21
如果有人能指出我错过了什么,或者我还能尝试什么,那将是一个很大的帮助。
谢谢。
【问题讨论】: