【问题标题】:spring-boot, Jetty setup results in authenticated failed for username Already authenticated as UNAUTHENTICATEDspring-boot,Jetty 设置导致用户名的身份验证失败已经验证为 UNAUTHENTICATED
【发布时间】:2021-08-17 13:14:48
【问题描述】:

我正在从 jboss 迁移到码头,并且在登录期间失败,请参阅最后的堆栈跟踪。

我在调用 request.login(requestEksternSsoToken, null); 时使用了 OncePerRequestFilter;

然后它说我已经通过身份验证为 UNAUTHENTICATED。有什么问题,我该如何解决?

14:05:05.602 [qtp1288135425-15] DEBUG n.n.m.s.filter.OpenAMLoginFilter - Login failed.
org.eclipse.jetty.server.Authentication$Failed: Authenticated failed for username 'AQIC5wjhfjsdhfjksdhfjadshfjdhssjdfhasdkhf'. Already authenticated as UNAUTHENTICATED
        at org.eclipse.jetty.server.Request.login(Request.java:2530)
        at xx.xxxx.xxxx.security.filter.OpenAMLoginFilter.login(OpenAMLoginFilter.java:165)
        at xx.xxx.xxxx.security.filter.OpenAMLoginFilter.handleNoExistingLogin(OpenAMLoginFilter.java:95)
        at xx.xxxxx.xxxxx.security.filter.OpenAMLoginFilter.doFilterInternal(OpenAMLoginFilter.java:71)
        at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
        at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:193)
        at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1601)
        at org.springframework.web.filter.RequestContextFilter.doFilterInternal(RequestContextFilter.java:100)
        at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
        at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:193)
        at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1601)
        at org.eclipse.jetty.servlet.ServletHandler.doHandle(ServletHandler.java:548)
        at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:143)
        at org.eclipse.jetty.security.SecurityHandler.handle(SecurityHandler.java:602)
        at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:127)
        at org.eclipse.jetty.server.handler.ScopedHandler.nextHandle(ScopedHandler.java:235)
        at org.eclipse.jetty.server.session.SessionHandler.doHandle(SessionHandler.java:1624)
        at org.eclipse.jetty.server.handler.ScopedHandler.nextHandle(ScopedHandler.java:233)
        at org.eclipse.jetty.server.handler.ContextHandler.doHandle(ContextHandler.java:1435)
        at org.eclipse.jetty.server.handler.ScopedHandler.nextScope(ScopedHandler.java:188)
        at org.eclipse.jetty.servlet.ServletHandler.doScope(ServletHandler.java:501)
        at org.eclipse.jetty.server.session.SessionHandler.doScope(SessionHandler.java:1594)
        at org.eclipse.jetty.server.handler.ScopedHandler.nextScope(ScopedHandler.java:186)
        at org.eclipse.jetty.server.handler.ContextHandler.doScope(ContextHandler.java:1350)
        at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:141)
        at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:127)
        at org.eclipse.jetty.server.Server.handle(Server.java:516)
        at org.eclipse.jetty.server.HttpChannel.lambda$handle$1(HttpChannel.java:388)
        at org.eclipse.jetty.server.HttpChannel.dispatch(HttpChannel.java:633)
        at org.eclipse.jetty.server.HttpChannel.handle(HttpChannel.java:380)
        at org.eclipse.jetty.server.HttpConnection.onFillable(HttpConnection.java:277)
        at org.eclipse.jetty.io.AbstractConnection$ReadCallback.succeeded(AbstractConnection.java:311)
        at org.eclipse.jetty.io.FillInterest.fillable(FillInterest.java:105)
        at org.eclipse.jetty.io.ChannelEndPoint$1.run(ChannelEndPoint.java:104)
        at org.eclipse.jetty.util.thread.QueuedThreadPool.runJob(QueuedThreadPool.java:882)
        at org.eclipse.jetty.util.thread.QueuedThreadPool$Runner.run(QueuedThreadPool.java:1036)
        at java.base/java.lang.Thread.run(Thread.java:829)

更新:

在这里,我编写了一个 Jetty 配置,我在其中配置安全约束,但当我尝试调用登录时,它仍然在我的过滤器中抛出相同的错误。

@Configuration
public class JettyConfig {
    private static final Logger logger = getLogger(JettyConfig.class);

    
    @Bean
    WebServerFactoryCustomizer embeddedServletContainerCustomizer(final JettyServerCustomizer jettyServerCustomizer) {
    
        return container -> {
            if (container instanceof JettyServletWebServerFactory) {
                logger.info("Adding jetty server customizer");
                ((JettyServletWebServerFactory) container).addServerCustomizers(jettyServerCustomizer);
            }
        };
    }

    @Bean
    JettyServerCustomizer jettyServerCustomizer(final LoginService loginService,ConstraintSecurityHandler constraintSecurityHandler) {
        return server -> {
            logger.info("Setting loginService");
            ((WebAppContext) server.getHandler()).setSecurityHandler(constraintSecurityHandler);
        };// .setSecurityHandler(constraintSecurityHandler);
    }

    @Bean
    ConstraintSecurityHandler constraintSecurityHandler(final LoginService loginService) {
        final ConstraintSecurityHandler securityHandler = new ConstraintSecurityHandler();

        securityHandler.setLoginService(loginService);
        
       Constraint constraint = new Constraint();
       constraint.setName("Auth");
       ConstraintMapping mapping = new ConstraintMapping();
       mapping.setPathSpec("/*");
       mapping.setConstraint(constraint);
       securityHandler.addConstraintMapping(mapping);
       securityHandler.setLoginService(loginService);
      

        return securityHandler;
    }
   
    
    @Bean
    LoginService loginService()  {
        JAASLoginService jaas = new JAASLoginService("OpenAM Realm");
        jaas.setLoginModuleName("openam");
        return jaas;
    }

【问题讨论】:

  • 这意味着您的Request.getAuthentication() 设置不正确,这是由您的SecurityHandler.getAuthenticator() 设置的,似乎尚未设置。 (您的描述符中是否设置了安全约束?)
  • 不,我没有。我明天试试。谢谢!
  • Hei @JoakimErdfelt 你能看看发布的代码吗?我确实配置了安全约束。我提醒您从 OpenAM 获取令牌,然后我使用过滤器以使用已获得的令牌调用登录。我在这里想念什么?我还设置了 System.setProperty("java.security.auth.login.config", loginConfFile);
  • 如果这仍然是一个问题,请您在github.com/eclipse/jetty.project/issues提出问题
  • 只要 jaas 配置在 Spring Boot 应用程序的 Jar 外部,它就可以工作。当 conf 包含在 jar 中时,使用嵌入式码头的相同设置在没有弹簧引导的情况下工作。我猜 Spring Boot 中的资源丢失有所不同但我不能说是什么。

标签: spring-boot security authentication jetty openam


【解决方案1】:

我能够自己找到问题所在。与 Embeded Jetty 部署相比,webapp/web-inf 目录没有被扩展,然后 spring boot 无法找到 jaas login.conf 文件,并且无法静默加载登录模块。从某个位置显式设置配置可以解决问题:

JAASLoginService jaas = new JAASLoginService("OpenAM Realm");
        jaas.setLoginModuleName("openam");
        final String loginConfFile = "/app/login.conf";//Applcation.class.getClassLoader().getResource("login.conf").getFile();
        logger.info("login.conf file location is " + loginConfFile);
        File file = (new File(loginConfFile));
        logger.info("uri is " + file.toURI());
        ConfigFile configfile = new ConfigFile(file.toURI());
        jaas.setConfiguration(configfile);

【讨论】:

    猜你喜欢
    • 2021-06-24
    • 2018-03-16
    • 2017-07-31
    • 2022-08-16
    • 2015-03-13
    • 2019-01-06
    • 1970-01-01
    • 2018-10-09
    • 2012-07-05
    相关资源
    最近更新 更多