【问题标题】:Full authentication is required to access this resource with Spring Security and Keycloak使用 Spring Security 和 Keycloak 访问此资源需要完全身份验证
【发布时间】:2018-03-04 19:06:37
【问题描述】:

我正在尝试使用 Keycloak 配置我的 Spring Security。我正在使用 Spring Boot。我的 pom 中有以下依赖项。

<dependency>
    <groupId>org.keycloak</groupId>
    <artifactId>keycloak-spring-boot-starter</artifactId>
</dependency>
<dependency>
    <groupId>org.keycloak</groupId>
    <artifactId>keycloak-spring-security-adapter</artifactId>
</dependency>
<dependency>
    <groupId>org.keycloak</groupId>
    <artifactId>keycloak-tomcat8-adapter</artifactId>
</dependency>

我用的是spring boot版本1.5.7.RELEASE。还有keycloak版本3.2.1.Final 以及我的 application.properties 中的以下属性:

keycloak.enabled=true
keycloak.realm=test
keycloak.auth-server-url=http://localhost:8080/auth
keycloak.ssl-required=external
keycloak.resource=rest
keycloak.bearer-only=true
keycloak.credentials.secret=<secret>
keycloak.principal-attribute=preferred_username
keycloak.security-constraints[0].authRoles[0]=application
keycloak.security-constraints[0].securityCollections[0].name=spring secured api
keycloak.security-constraints[0].securityCollections[0].patterns[0]=/api/**

management.security.enabled=false

我没有任何其他配置。对于我的端点,我使用 JAX-RS。 要请求我的令牌,我使用 Chrome 应用程序邮递员。这是请求:

POST /auth/realms/test/protocol/openid-connect/token HTTP/1.1
Host: localhost:8080
Cache-Control: no-cache
Postman-Token: <postman token>
Content-Type: application/x-www-form-urlencoded

grant_type=password&client_id=postman&username=root&password=12345678

还有我的申请要求:

GET /api/product HTTP/1.1
Host: localhost:18888
Authorization: Bearer <keycloak token from the request above>
Cache-Control: no-cache
Postman-Token: <postman token>

但我的回答是:

{
    "timestamp": <timestamp>,
    "status": 401,
    "error": "Unauthorized",
    "message": "Full authentication is required to access this resource",
    "path": "/api/product"
}

【问题讨论】:

    标签: java spring spring-boot spring-security keycloak


    【解决方案1】:

    这里没有用 Keycloak 配置 Spring Security,security-constraints 用于保护 servlet 容器,与 Spring Security 无关。使用 SpringSecurity 时不需要它,添加一个扩展 KeycloakWebSecurityConfigurerAdapter 的 Secuirty Config 类,查看这里:http://www.keycloak.org/docs/3.3/securing_apps/topics/oidc/java/spring-security-adapter.html

    【讨论】:

    • 感谢您的回答。我有一个问题,我宁愿使用“keycloak.json”而不是使用 Spring 属性文件。在加载应用程序时,会加载 keycloak.json。但是如果我尝试打一个休息电话,我会得到一个例外,我必须在配置中设置“领域”。你能帮帮我吗?
    • 在这种情况下,不要使用 Spring Boot 适配器而只使用 Spring Security 适配器,并确保在您的 keycloak.json th 领域中指定。
    猜你喜欢
    • 2016-11-11
    • 2015-01-08
    • 2016-10-03
    • 2017-08-14
    • 2018-09-11
    • 2019-01-01
    • 2020-11-21
    • 2020-03-30
    • 2022-01-03
    相关资源
    最近更新 更多