Java REST API使用OpenAM令牌来确定用户?

iam*_*10k 2 java rest openam

我无法使用OpenAM验证用户令牌.特别是我应该创建什么类型的代理.有人可以推荐一个解决方案吗?

本质上,REST API将读取用户OpenAM tokenid并使用OpenAM验证令牌,然后OpenAM将返回包含用户名的数据.可以在REST API方法中使用该用户名来标识正在访问该方法的用户.

更简化的是如何使用OpenAM令牌获取OpenAM用户信息.

谢谢!

小智 5

您可以使用以下端点:

  1. 验证用户:

    curl --request POST --header "X-OpenAM-Username: demo" \
    --header "X-OpenAM-Password: changeit" \
    --header "Content-Type: application/json"      
    "http://openam.example.com:8080/sso/json/authenticate"
    
    {"tokenId":"AQIC5wM2LY4SfcyTReB5nbrLt3QaH-7GhPuU2-uK2k5tJsA.*AAJTSQACMDEAAlNLABMyOTUxODgxODAwOTE0MTA4NDE3*","successUrl":"/sso/console"}
    
    Run Code Online (Sandbox Code Playgroud)
  2. 验证令牌:

    curl --request POST \
    --header "Content-Type: application/json" \
    "http://openam.example.com:8080/sso/json/sessions/AQIC5wM2LY4SfczadxSebQWi9UEyd2ZDnz_io0Pe6NDgMhY.*AAJTSQACMDEAAlNLABM3MTMzMTYwMzM1NjE4NTE4NTMx*?_action=validate"
    
    {"valid":true,"uid":"demo","realm":"/"}
    
    Run Code Online (Sandbox Code Playgroud)
  3. 获取个人资料属性

    curl --request GET \
    --header "iPlanetDirectoryPro: AQIC5wM2LY4SfczadxSebQWi9UEyd2ZDnz_io0Pe6NDgMhY.*AAJTSQACMDEAAlNLABM3MTMzMTYwMzM1NjE4NTE4NTMx*" \
    "http://openam.example.com:8080/sso/json/users/demo"
    
    {"username":"demo","realm":"/","uid":["demo"],"userPassword":["{SSHA}cIgTNGHWd4t4Ff3SHa6a9pjMyn/Z3e3EOp5mrA=="],"sn":["demo"],"createTimestamp":["20160406210602Z"],"cn":["demo"],"givenName":["demo"],"inetUserStatus":["Active"],"dn":["uid=demo,ou=people,dc=example,dc=com"],"objectClass":["devicePrintProfilesContainer","person","sunIdentityServerLibertyPPService","inetorgperson","sunFederationManagerDataStore","iPlanetPreferences","iplanet-am-auth-configuration-service","organizationalperson","sunFMSAML2NameIdentifier","oathUser","inetuser","forgerock-am-dashboard-service","iplanet-am-managed-person","iplanet-am-user-service","sunAMAuthAccountLockout","top"],"universalid":["id=demo,ou=user,dc=openamcfg,dc=example,dc=com"]}
    
    Run Code Online (Sandbox Code Playgroud)