我正在努力寻找它,但我找不到解决方案。有人帮助我吗?
这是我的尝试。#1 首先找到 PAT (Protection API Token)
#4 这个错误的源代码,但我不熟悉源代码。
private PermissionTicketToken verifyPermissionTicket(KeycloakAuthorizationRequest request) {
String ticketString = request.getTicket();
PermissionTicketToken ticket = request.getKeycloakSession().tokens().decode(ticketString, PermissionTicketToken.class);
if (ticket == null) {
throw new CorsErrorResponseException(request.getCors(), "invalid_ticket", "Ticket verification failed", Status.FORBIDDEN);
}
它从第 670 行的源文件(AuthorizationTokenService.java)复制。
https://www.keycloak.org/docs/latest/authorization_services/#_service_overview