WSO2 身份服务器以编程方式创建应用程序抛出 'Illegal Access Attempt' 警告

WSO2 Identity Server programmatically creating an application throwing 'Illegal Access Attempt' warning

我正在开发一个 Java 客户端,它将通过调用 OAuthAdminService 在 WSO2 Identity Server 中创建一个应用程序。经过一番挖掘,我发现 registerOAuthApplicationData() 方法是用于在 IS 中创建应用程序的方法。在调用该方法之前,我已经通过 AuthenticationAdminStub 类型的 login() 方法对管理员用户进行了身份验证。即使经过这样的身份验证,registerOAuthApplicationData() 方法也会使 IS 控制台打印

[2016-04-26 13:08:52,577] WARN {org.wso2.carbon.server.admin.module.handler.AuthenticationHandler} - Illegal access attempt at [2016-04-26 13:08:52,0577] from IP address 127.0.0.1 while trying to authenticate access to service OAuthAdminService

并且未在 IS 数据库中创建应用程序。

我试过的代码如下

import org.apache.axis2.context.ConfigurationContext;
import org.apache.axis2.context.ConfigurationContextFactory;
import org.apache.axis2.transport.http.HTTPConstants;
import org.wso2.carbon.authenticator.proxy.AuthenticationAdminStub;
import org.wso2.carbon.identity.oauth.OAuthAdminServicePortTypeProxy;
import org.wso2.carbon.identity.oauth.dto.xsd.OAuthConsumerAppDTO;

    public class IdentityClientOne {    


            private final static String SERVER_URL = "https://localhost:9443/services/";
            private final static String APP_ID = "myapp";

            /**
             * @param args
             */
            public static void main(String[] args) {

                AuthenticationAdminStub authstub = null;
                ConfigurationContext configContext = null;

                System.setProperty("javax.net.ssl.trustStore", "wso2carbon.jks");
                System.setProperty("javax.net.ssl.trustStorePassword", "wso2carbon");

                try {
                    configContext = ConfigurationContextFactory.createConfigurationContextFromFileSystem(
                            "repo", "repo/conf/client.axis2.xml");
                    authstub = new AuthenticationAdminStub(configContext, SERVER_URL
                            + "AuthenticationAdmin");

                    // Authenticates as a user having rights to add users.
                    if (authstub.login("admin", "admin", APP_ID)) {
                        System.out.println("admin authenticated");


                        OAuthConsumerAppDTO consumerApp = new OAuthConsumerAppDTO("Oauth-2.0",
                                "sample_app",
                                "",
                                "authorization_code implicit password client_credentials refresh_token urn:ietf:params:oauth:grant-type:saml2-bearer iwa:ntlm","","","");


                        OAuthAdminServicePortTypeProxy OAuthAdminProxy = new OAuthAdminServicePortTypeProxy();
                        OAuthAdminProxy.registerOAuthApplicationData(consumerApp);

                    }
                } catch (Exception e) {
                    e.printStackTrace();
                }
            }

    }

请问应该怎么做才对?

您必须通过经过身份验证的会话访问存根。

你能试试下面吗

public class Test {
    private final static String SERVER_URL = "https://localhost:9443/services/";

    public static void main(String[] args) throws RemoteException, OAuthAdminServiceException {

        OAuthAdminServiceStub stub = new OAuthAdminServiceStub(null, SERVER_URL + "OAuthAdminService");

        ServiceClient client = stub._getServiceClient();
        authenticate(client);

        OAuthConsumerAppDTO consumerAppDTO = new OAuthConsumerAppDTO();
        consumerAppDTO.setApplicationName("sample-app");
        consumerAppDTO.setCallbackUrl("http://localhost:8080/playground2/oauth2client");
        consumerAppDTO.setOAuthVersion("OAuth-2.0");
        consumerAppDTO.setGrantTypes("authorization_code implicit password client_credentials refresh_token "
                                     + "urn:ietf:params:oauth:grant-type:saml2-bearer iwa:ntlm");

        stub.registerOAuthApplicationData(consumerAppDTO);
    }

    public static void authenticate(ServiceClient client) {
        Options option = client.getOptions();
        HttpTransportProperties.Authenticator auth = new HttpTransportProperties.Authenticator();
        auth.setUsername("admin");
        auth.setPassword("admin");
        auth.setPreemptiveAuthentication(true);
        option.setProperty(org.apache.axis2.transport.http.HTTPConstants.AUTHENTICATE, auth);
        option.setManageSession(true);
    }
}