cloudfoundry / cloudfoundry/cf-java-client

Authentication issues from Cloud foundry V2

Ouverte
#1,183 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Langage dominant
Java
Étoiles
334
Forks
319
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

Hello everyone, we are using the cloud foundry V2 client for creating/updating Hana Cloud service instances.

The error is

unauthorized: {"error":"invalid_grant","error_description":"User authentication failed: Unauthorized"}

We have a spring boot app and they way we initialize our CF client is with a @Configuration class on application start.

  @Bean
  public DefaultConnectionContext connectionContext() {
    String cfApi = CfToolsHelper.getCfApi();
    String host = cfApi.substring(cfApi.lastIndexOf("/") + 1);
    return DefaultConnectionContext.builder().apiHost(host).build();

  }

  @Bean
  CloudFoundryClient cloudFoundryClient(ConnectionContext connectionContext, TokenProvider tokenProvider) {
    return ReactorCloudFoundryClient.builder()
                                    .connectionContext(connectionContext)
                                    .tokenProvider(tokenProvider)
                                    .build();
  }

  @Bean
  ReactorDopplerClient dopplerClient(ConnectionContext connectionContext, TokenProvider tokenProvider) {
    return ReactorDopplerClient.builder().connectionContext(connectionContext).tokenProvider(tokenProvider).build();
  }

  @Bean
  ReactorUaaClient uaaClient(ConnectionContext connectionContext, TokenProvider tokenProvider) {
    return ReactorUaaClient.builder().connectionContext(connectionContext).tokenProvider(tokenProvider).build();
  }

We have a technical user and for the authentication we user username and x509 certificate. With it we create a one-time, 5 minute-living passcode with which we create initialize a bean of PasswordGrantTokenProvider:

return PasswordGrantTokenProvider.builder().password(passcode).username(username).build();

which is used for the init of the client above. After that we do not re-initialize PasswordGrantTokenProvider during the lifetime of the app.

We haven't seen any concrete dependency on why and when the error is thrown. E.g. after application start there can be multiple successful executions in the timespan of several hours, but after that it start failing(here I cannot say if from this point on it fails every time or if there can still be successful executions after the first failure, but for sure it fails more than not).

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez par les méthodes @Bean qui créent DefaultConnectionContext, CloudFoundryClient, ReactorDopplerClient, ReactorUaaClient et PasswordGrantTokenProvider. Suivez la manière dont le code d’accès de cinq minutes et le fournisseur de jetons sont utilisés lors des requêtes ultérieures, puis reproduisez l’échec d’authentification différé. Le travail est terminé lorsque la cause liée au cycle de vie ou au renouvellement est identifiée et qu’une résolution fiable est documentée ou validée.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
java, spring-boot
Domaine
authentication, cloud
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.