2016-02-07 26 views
2

我正在使用Jersey構建Java REST API。 Tomcat是我的Web服務器。對於用戶帳戶和OAuth2密鑰管理,我使用的是Stormpath的Java SDK。我有一個樣本用戶已經通過網站創建的,我每次張貼該帳戶,以我的應用程序在郵差v1/token端點的JSON的用戶名/密碼請求的時候,我得到這個異常和堆棧跟蹤:爲什麼在嘗試從Stormpath獲取OAuth2密鑰時收到com.stormpath.sdk.lang.InstantiationException?

com.stormpath.sdk.lang.InstantiationException: Unable to instantiate instance with constructor [public com.stormpath.sdk.impl.oauth.DefaultAccessToken(com.stormpath.sdk.impl.ds.InternalDataStore,java.util.Map)] 
    at com.stormpath.sdk.lang.Classes.instantiate(Classes.java:191) 
    at com.stormpath.sdk.impl.ds.DefaultResourceFactory.instantiate(DefaultResourceFactory.java:65) 
    at com.stormpath.sdk.impl.ds.DefaultDataStore.instantiate(DefaultDataStore.java:170) 
    at com.stormpath.sdk.impl.oauth.DefaultGrantAuthenticationToken.getAsAccessToken(DefaultGrantAuthenticationToken.java:79) 
    at com.stormpath.sdk.impl.oauth.DefaultOauthGrantAuthenticationResultBuilder.build(DefaultOauthGrantAuthenticationResultBuilder.java:87) 
    at com.stormpath.sdk.impl.oauth.DefaultOauthGrantAuthenticationResultBuilder.build(DefaultOauthGrantAuthenticationResultBuilder.java:24) 
    at com.stormpath.sdk.impl.oauth.DefaultPasswordGrantAuthenticator.authenticate(DefaultPasswordGrantAuthenticator.java:56) 
    at com.stormpath.sdk.impl.oauth.DefaultPasswordGrantAuthenticator.authenticate(DefaultPasswordGrantAuthenticator.java:28) 
    at com.ficcy.api.services.AuthService.getToken(AuthService.java:33) 
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) 
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) 
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) 
    at java.lang.reflect.Method.invoke(Method.java:497) 
    at org.glassfish.jersey.server.model.internal.ResourceMethodInvocationHandlerFactory$1.invoke(ResourceMethodInvocationHandlerFactory.java:81) 
    at org.glassfish.jersey.server.model.internal.AbstractJavaResourceMethodDispatcher$1.run(AbstractJavaResourceMethodDispatcher.java:144) 
    at org.glassfish.jersey.server.model.internal.AbstractJavaResourceMethodDispatcher.invoke(AbstractJavaResourceMethodDispatcher.java:161) 
    at org.glassfish.jersey.server.model.internal.JavaResourceMethodDispatcherProvider$TypeOutInvoker.doDispatch(JavaResourceMethodDispatcherProvider.java:205) 
    at org.glassfish.jersey.server.model.internal.AbstractJavaResourceMethodDispatcher.dispatch(AbstractJavaResourceMethodDispatcher.java:99) 
    at org.glassfish.jersey.server.model.ResourceMethodInvoker.invoke(ResourceMethodInvoker.java:389) 
    at org.glassfish.jersey.server.model.ResourceMethodInvoker.apply(ResourceMethodInvoker.java:347) 
    at org.glassfish.jersey.server.model.ResourceMethodInvoker.apply(ResourceMethodInvoker.java:102) 
    at org.glassfish.jersey.server.ServerRuntime$2.run(ServerRuntime.java:326) 
    at org.glassfish.jersey.internal.Errors$1.call(Errors.java:271) 
    at org.glassfish.jersey.internal.Errors$1.call(Errors.java:267) 
    at org.glassfish.jersey.internal.Errors.process(Errors.java:315) 
    at org.glassfish.jersey.internal.Errors.process(Errors.java:297) 
    at org.glassfish.jersey.internal.Errors.process(Errors.java:267) 
    at org.glassfish.jersey.process.internal.RequestScope.runInScope(RequestScope.java:317) 
    at org.glassfish.jersey.server.ServerRuntime.process(ServerRuntime.java:305) 
    at org.glassfish.jersey.server.ApplicationHandler.handle(ApplicationHandler.java:1154) 
    at org.glassfish.jersey.servlet.WebComponent.serviceImpl(WebComponent.java:471) 
    at org.glassfish.jersey.servlet.WebComponent.service(WebComponent.java:425) 
    at org.glassfish.jersey.servlet.ServletContainer.service(ServletContainer.java:383) 
    at org.glassfish.jersey.servlet.ServletContainer.service(ServletContainer.java:336) 
    at org.glassfish.jersey.servlet.ServletContainer.service(ServletContainer.java:223) 
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:291) 
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) 
    at org.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52) 
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:239) 
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) 
    at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:219) 
    at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:106) 
    at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:502) 
    at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:142) 
    at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:79) 
    at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:88) 
    at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:518) 
    at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1091) 
    at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:668) 
    at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1521) 
    at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.run(NioEndpoint.java:1478) 
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) 
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617) 
    at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61) 
    at java.lang.Thread.run(Thread.java:745) 
Caused by: java.lang.reflect.InvocationTargetException 
    at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) 
    at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) 
    at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) 
    at java.lang.reflect.Constructor.newInstance(Constructor.java:422) 
    at com.stormpath.sdk.lang.Classes.instantiate(Classes.java:188) 
    ... 54 more 
Caused by: io.jsonwebtoken.JwtException: JWT failed validation; it cannot be trusted. 
    at com.stormpath.sdk.impl.oauth.DefaultAccessToken.ensureAccessToken(DefaultAccessToken.java:56) 
    at com.stormpath.sdk.impl.oauth.DefaultAccessToken.<init>(DefaultAccessToken.java:35) 
    ... 59 more 

我的JSON:

{ 
    "login": "**EMAIL**", 
    "password": "**PASSWORD**" 
} 

exception的文檔中沒有任何內容。這是我的終端/服務。 (我開始抓所有的異常,這樣我可以看看發生了什麼事也,AuthRequest是在登錄名和密碼字段不空約束一個簡單的bean):

package com.ficcy.api.services; 
//truncated imports 

@Path("/token") 
public class AuthService { 

    @POST 
    @Consumes(MediaType.APPLICATION_JSON) 
    @Produces(MediaType.APPLICATION_JSON) 
    public AccessToken getToken(AuthRequest ar) { 

     AccessToken rtn = null; 

     try { 

      PasswordGrantRequest pgr = Oauth2Requests.PASSWORD_GRANT_REQUEST.builder().setLogin(ar.getLogin()) 
        .setPassword(ar.getPassword()).build(); 

      OauthGrantAuthenticationResult authResult = Authenticators.PASSWORD_GRANT_AUTHENTICATOR 
        .forApplication(Config.getApplication()).authenticate(pgr); 
      rtn = authResult.getAccessToken(); 

     } catch (Exception e) { 
      System.err.println(e.getMessage()); 
      e.printStackTrace(); 
     } 

     return rtn; 
    } 

} 

編輯:這是我的配置類,在那裏我存儲我的Stormpath應用:

package com.ficcy.api.config; 
//truncated imports 

public class Config { 
    private static Client client = Clients.builder().build(); 
    private static Application application; 

    static { 

     Tenant tenant = client.getCurrentTenant(); 
     ApplicationList applications = tenant 
       .getApplications(Applications.where(Applications.name().eqIgnoreCase("ficcy-api"))); 

     application = applications.iterator().next(); 

    } 

    public static Client getClient() { 
     return client; 
    } 

    public static Application getApplication() { 
     return application; 
    } 

    public static Hashids getHashid(String salt) { 
     return new Hashids(salt, 6); 
    } 

} 

而且的build.gradle:

repositories { 
    mavenCentral() 
} 

apply plugin: 'java' 
apply plugin: 'war' 
apply plugin: 'eclipse-wtp' 
apply from: 'https://raw.github.com/akhikhl/gretty/master/pluginScripts/gretty.plugin' 

dependencies { 

    compile 'org.glassfish.jersey.core:jersey-server:2.22.1' 
    compile 'org.glassfish.jersey.containers:jersey-container-servlet-core:2.22.1' 
    compile 'org.glassfish.jersey.core:jersey-client:2.22.1' 
    compile 'org.glassfish.jersey.containers:jersey-container-servlet:2.22.1' 
    compile 'org.glassfish.jersey.security:oauth1-client:2.22.1' 
    compile 'org.glassfish.jersey.media:jersey-media-json-jackson:2.22.1' 

    compile 'mysql:mysql-connector-java:5.1.38' 

    compile 'com.stormpath.sdk:stormpath-sdk-api:1.0.RC8.3' 

    compile 'junit:junit-dep:4.+'  
    compile 'org.hashids:hashids:1.0.1' 

    testCompile 'junit:junit-dep:4.+' 

    runtime 'com.stormpath.sdk:stormpath-sdk-impl:1.0.RC8.3' 
    runtime 'com.stormpath.sdk:stormpath-sdk-httpclient:1.0.RC8.3' 

    } 

gretty { 
    port = 8080 
    servletContainer = 'tomcat8' 
    fastReload = true 
    contextPath = '/' 
    httpsEnabled = true 

} 
+0

您使用Java SDK版本「1.0.RC8.3」嗎?你的代碼中的哪一行會得到異常?在執行您在'AuthService#getToken(AuthRequest)' – mario

+0

中顯示的代碼時,我無法重現您的錯誤。我正在使用Java 8'1.0.66'。幾分鐘前,我改變了我的build.gradle使用'1.0.RC8.2'和'1.0.RC8.3'來爲所有Stormpath庫提供響應,並且一切正常。我剛回到'1.0.RC8.3',它又失敗了。編輯:該錯誤是33行 – psamp

回答

1

確定創建當你收到這個錯誤3210?我懷疑你基本上試圖驗證錯誤的access_token。你可以嘗試重新創建它,然後重新執行拋出Exception的代碼段,但是這次使用新生成的access_token

+0

是的,我相信是這樣,它拋出的錯誤33,在這裏: OauthGrantAuthenticationResult authResult = Authenticators.PASSWORD_GRANT_AUTHENTICATOR .forApplication(Config.getApplication())驗證(PGR);」 – psamp

+0

當我使用'1.0.RC8.2'而不是'1.0.RC8.3'進行編譯時,一切都按預期工作。上面引用的行在我使用'1.0.RC8.3'時失敗。 – psamp

+0

在'1.0.RC8.3'中,整個令牌管理方法發生了變化。我相信你正在使用舊的令牌。如果你創建一個新的access_token,事情應該可以正常工作。 – mario

1

這是Stormpath SDK中的一個錯誤,當您將刷新令牌過期(生存時間)設置爲0時,訪問令牌無法驗證,即您不想發佈它們。這導致JWT中的rti聲明爲零,並且訪問令牌驗證失敗。快速修復如果將刷新標記ttl設置爲0以外的其他東西。我會將該錯誤報告給Stormpath。

相關問題