{"id":380081,"date":"2024-06-27T09:05:19","date_gmt":"2024-06-27T09:05:19","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=380081"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=380081","title":{"rendered":"<span>\u041a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 OpenAM \u0438 OpenIG<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0435\u043d\u0438\u0435\u043c \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/github.com\/OpenIdentityPlatform\/OpenAM\/wiki\/How-to-Add-Authorization-and-Protect-Your-Application-With-OpenAM-and-OpenIG-Stack\" rel=\"noopener noreferrer nofollow\">How to Add Authorization and Protect Your Application With OpenAM and OpenIG Stack<\/a>. \u041f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043e\u043f\u0438\u0441\u044b\u0432\u0430\u043b\u0430, \u043a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u043a\u043e\u043d\u0435\u0447\u043d\u044b\u0435 \u0442\u043e\u0447\u043a\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u043f\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u043c\u0443 HTTP \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0443. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043d\u0430 WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0447\u0435\u0440\u0435\u0437 OpenIG, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e OpenAM. \u0414\u043b\u044f \u0443\u043f\u0440\u043e\u0449\u0435\u043d\u0438\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0438 \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432, \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c Docker \u0438 Docker Compose.<\/p>\n<h2>\u0414\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 WebSocket \u0441\u0435\u0440\u0432\u0435\u0440<\/h2>\n<p>\u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 <a href=\"https:\/\/hub.docker.com\/r\/jmalloc\/echo-server\" rel=\"noopener noreferrer nofollow\">echo-server<\/a>. \u0427\u0442\u043e\u0431\u044b \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0438\u0441 \u0432 Docker, \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 <code>docker-compose.yaml<\/code> \u0444\u0430\u0439\u043b \u0438 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0432 \u043d\u0435\u0433\u043e echo-server.<\/p>\n<pre><code class=\"yaml\">services:   echo-server:     image: jmalloc\/echo-server     restart: always     ports:           - \"8082:8080\"     networks:       openam_network:         aliases:           - echo-server networks:   openam_network:     driver: bridge <\/code><\/pre>\n<p>\u0412\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u0443 <code>docker compose up<\/code> \u0438, \u043f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e, \u043a\u0430\u043a \u0441\u0435\u0440\u0432\u0435\u0440 \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u043f\u0443\u0449\u0435\u043d, \u0432\u044b \u0443\u0432\u0438\u0434\u0438\u0442\u0435 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u0438 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0435:<\/p>\n<pre><code>Echo server listening on port 8080.<\/code><\/pre>\n<h2>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f OpenIG<\/h2>\n<p>\u041d\u0430\u0441\u0442\u0440\u043e\u0438\u043c OpenIG \u0442\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u0448\u043b\u044e\u0437 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u043b \u0441\u0442\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e HTML \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0443 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435\u043c.<\/p>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0430\u043f\u043a\u0443 <code>openig-config<\/code> , \u043f\u0435\u0440\u0435\u0439\u0434\u0438\u0442\u0435 \u0432 \u043d\u0435\u0435 \u0438 \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0434\u0432\u0430 \u0444\u0430\u0439\u043b\u0430: <code>admin.json<\/code> \u0438 <code>config.json<\/code> \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c:<\/p>\n<p><code>admin.json<\/code> :<\/p>\n<pre><code class=\"json\">{   \"prefix\" : \"openig\",   \"mode\": \"PRODUCTION\" }<\/code><\/pre>\n<p><code>config.json<\/code> :<\/p>\n<pre><code class=\"json\">{   \"heap\": [],   \"handler\": {     \"type\": \"Chain\",     \"config\": {       \"filters\": [],       \"handler\": {         \"type\": \"Router\",         \"name\": \"_router\",         \"capture\": \"all\"       }     }   } } <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u0438\u043c \u0432 OpenIG \u0441\u0442\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e HTML \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0443 \u0441 UI \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u0441 WebSocket. \u0412 \u043f\u0430\u043f\u043a\u0435 <code>openig-config<\/code> \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e <code>static<\/code> \u0438 \u0432 \u043d\u0435\u0439 \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0444\u0430\u0439\u043b <code>ws-client.html<\/code> \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c:<\/p>\n<pre><code class=\"xml\">&lt;!DOCTYPE html> &lt;html lang='en'> &lt;head>     &lt;meta charset='UTF-8'>     &lt;title>WS-Client&lt;\/title>     &lt;style>         #log p {             margin: 0;         }         #log p.error {             color: red;         }     &lt;\/style> &lt;\/head> &lt;body>   &lt;div>     &lt;h1>WS-Client&lt;\/h1>       &lt;button id='connect' type='button'>Connect&lt;\/button>       &amp;nbsp;       &lt;button id='send' type='button'>Send Message&lt;\/button>       &lt;br>       &lt;label for='log'>Log:&lt;\/label>       &lt;div id='log'>&lt;\/div>   &lt;\/div>   &lt;script>       const connectBtn = document.getElementById('connect');       connectBtn.onclick = connect;       let socket;       function connect() {           appendToConsole('connecting...')           const endpoint = 'ws:\/\/' + location.host + '\/ws-handler';           socket = new WebSocket(endpoint);           socket.onmessage = function(event) {               appendToConsole('got response message from server: ' + event.data);           };           socket.onopen = function () {               appendToConsole('connected')           };           socket.onerror = function (e) {               appendToConsole('socket error occurred', true);           }           socket.onclose = function () {               appendToConsole('socket connection closed')           }       }   const sendBtn = document.getElementById('send');   sendBtn.onclick = function () {       if(socket.readyState !== WebSocket.OPEN) {           appendToConsole('socket is not open', true);           return;       }       appendToConsole('sending message...');       try {           socket.send('Test message');       } catch (e) {           appendToConsole('error sending message: ' + e.message, true)       }   }    function appendToConsole(message, error) {       let className = '';       if (error) {           console.error(message);           className = 'error';       } else {           console.log(message);       }       const log = document.getElementById('log');       const p = document.createElement('p');       p.innerText = message;       p.className = className;       log.append(p)   }  &lt;\/script> &lt;\/body> &lt;\/html> <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u044b OpenIG \u0434\u043b\u044f \u043a\u043e\u043d\u0435\u0447\u043d\u044b\u0445 \u0442\u043e\u0447\u0435\u043a UI \u0438 WebSocket. \u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0430\u043f\u043a\u0443 <code>routes<\/code> \u0432\u043d\u0443\u0442\u0440\u0438 \u043f\u0430\u043f\u043a\u0438 <code>openig-config<\/code>. \u0412\u043d\u0443\u0442\u0440\u0438 \u043f\u0430\u043f\u043a\u0438 <code>routes<\/code> \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0434\u0432\u0430 \u0444\u0430\u0439\u043b\u0430 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 <code>10-ui.json<\/code> \u0434\u043b\u044f UI \u0438 <code>10-websocket.json<\/code> \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b WebSocket, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e.<\/p>\n<p><code>10-ui.json<\/code> :<\/p>\n<pre><code class=\"json\">{     \"name\": \"${matches(request.uri.path, '^\/ui')}\",     \"condition\": \"${matches(request.uri.path, '^\/ui')}\",     \"monitor\": true,     \"timer\": true,     \"handler\": {        \"type\": \"Chain\",        \"config\": {           \"filters\": [],           \"handler\": \"WSClient\"        }     },     \"heap\": [        {          \"name\": \"WSClient\",          \"type\":\"StaticResponseHandler\",          \"config\": {             \"status\": 200,             \"entity\": \"${read(system['openig.base'].concat('\/config\/static\/ws-client.html'))}\"          }        }     ]  } <\/code><\/pre>\n<p><code>10-websocket.json<\/code>:<\/p>\n<pre><code class=\"json\">{   \"name\": \"${matches(request.uri.path, '^\/ws-handler')}\",   \"condition\": \"${matches(request.uri.path, '^\/ws-handler')}\",   \"monitor\": true,   \"timer\": true,   \"handler\": {     \"type\": \"Chain\",     \"config\": {       \"filters\": [         {           \"type\": \"HeaderFilter\",           \"config\": {             \"messageType\": \"REQUEST\",             \"add\": {               \"Host\": [                 \"${matchingGroups(system['ws.secured'],\\\\\"(http|https):\\\\\/\\\\\/(.[^\\\\\/]*)\\\\\")[2]}\"               ]             },             \"remove\": [               \"Sec-Websocket-Key\",               \"Sec-Websocket-Version\",               \"Host\",               \"Origin\"             ]           }         }       ],       \"handler\": \"EndpointHandler\"     }   },   \"heap\": [     {       \"name\": \"EndpointHandler\",       \"type\": \"DispatchHandler\",       \"config\": {         \"bindings\": [           {             \"handler\": \"ClientHandler\",             \"capture\": \"all\",             \"baseURI\": \"${system['ws.secured']}\"           }         ]       }     }   ] } <\/code><\/pre>\n<p>\u041e\u0431\u0440\u0430\u0442\u0438\u0442\u0435 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435, \u0447\u0442\u043e \u0432 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0435 \u0438\u0437 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0443\u0434\u0430\u043b\u044f\u044e\u0442\u0441\u044f HTTP \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0438 \u0434\u043b\u044f \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043e\u0442 \u0438\u043d\u0441\u0442\u0430\u043d\u0441\u0430 OpenIG \u0434\u043e \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 <code>echo-server<\/code> .<\/p>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441 OpenIG \u0432 \u0444\u0430\u0439\u043b <code>docker-compose.yml<\/code> :<\/p>\n<pre><code class=\"yaml\">...     openig:     image: openidentityplatform\/openig:latest     build: .     volumes:       - .\/openig-config:\/usr\/local\/openig-config\/config:ro     ports:         - \"8081:8080\"       - \"8000:8000\"     environment:       CATALINA_OPTS: -Dopenig.base=\/usr\/local\/openig-config -Dsecured=http:\/\/echo-server:8080 -Dopenam=http:\/\/openam.example.org:8080\/openam -Dws.secured=ws:\/\/echo-server:8080 -Dorg.openidentityplatform.openig.websocket.ttl=180     networks:       openam_network:         aliases:           - openig.example.org ... <\/code><\/pre>\n<p>\u0421\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0435 \u0441\u0432\u043e\u0439\u0441\u0442\u0432\u0430 \u0438\u0437 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0432\u044b\u0448\u0435:<\/p>\n<div>\n<div class=\"table\">\n<table>\n<tbody>\n<tr>\n<th>\n<p>\u0421\u0432\u043e\u0439\u0441\u0442\u0432\u043e<\/p>\n<\/th>\n<th>\n<p>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435<\/p>\n<\/th>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">secured<\/p>\n<\/td>\n<td>\n<p align=\"left\">URL HTTP \u0441\u0435\u0440\u0432\u0438\u0441\u0430<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">ws.secured<\/p>\n<\/td>\n<td>\n<p align=\"left\">URL WebSocket \u0441\u0435\u0440\u0432\u0438\u0441\u0430<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">openam<\/p>\n<\/td>\n<td>\n<p align=\"left\">URL OpenAM (\u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0432 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0445 \u0440\u0430\u0437\u0434\u0435\u043b\u0430\u0445)<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">org.openidentityplatform.openig.websocket.ttl<\/p>\n<\/td>\n<td>\n<p align=\"left\">\u041f\u0435\u0440\u0438\u043e\u0434\u0438\u0447\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0432\u0430\u043b\u0438\u0434\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0441\u0441\u0438\u0438 \u0432 \u0441\u0435\u043a\u0443\u043d\u0434\u0430\u0445<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>\u0417\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439 <code>docker compose up<\/code> . \u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e, \u043a\u0430\u043a Docker \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u044b \u0441 OpenIG \u0438 echo-server \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u044b, \u043e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 URL <a href=\"http:\/\/localhost:8080\/ui\" rel=\"noopener noreferrer nofollow\">http:\/\/localhost:8080\/ui<\/a> . \u0412\u044b \u0441\u043c\u043e\u0436\u0435\u0442\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0438 \u0432\u0441\u0435 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 \u0431\u0443\u0434\u0435\u0442 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442\u044c \u0447\u0435\u0440\u0435\u0437 OpenIG.<\/p>\n<h2>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f OpenAM<\/h2>\n<p>\u0414\u043e\u0431\u0430\u0432\u0438\u043c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u0447\u0435\u0440\u0435\u0437 OpenAM \u0432 \u043d\u0430\u0448 \u0441\u0442\u0435\u043a. \u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441 OpenAM \u0432 \u0444\u0430\u0439\u043b <code>docker-compose.yaml<\/code><\/p>\n<pre><code class=\"yaml\">...   openam:     image: openidentityplatform\/openam     ports:         - \"8080:8080\"     networks:       openam_network:         aliases:           - openam.example.org ... <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0438\u043c\u0435\u043d\u0430 \u0445\u043e\u0441\u0442\u043e\u0432 OpenAM \u0438 OpenIG \u0432 \u0444\u0430\u0439\u043b\u00a0<code>hosts<\/code>, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440\u00a0<code>127.0.0.1 openam.example.org openig.example.org<\/code>\u00a0.<\/p>\n<p>\u0412 Windows \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0444\u0430\u0439\u043b\u00a0<code>hosts<\/code>\u00a0\u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443\u00a0<code>C:\\\\Windows\\\\System32\\\\drivers\\\\etc\\\\hosts<\/code>\u00a0, \u0432 Linux \u0438 Mac \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443\u00a0<code>\/etc\/hosts<\/code>.<\/p>\n<p>\u0417\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439 <code>docker compose up<\/code> , \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u0435 OpenAM, \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u0435 cookie domain \u0438 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 jwt endpoint \u043a\u0430\u043a \u043e\u043f\u0438\u0441\u0430\u043d\u043e \u0432 \u0441\u0442\u0430\u0442\u044c\u0435 \u00a0<a href=\"https:\/\/github.com\/OpenIdentityPlatform\/OpenAM\/wiki\/How-to-Add-Authorization-and-Protect-Your-Application-With-OpenAM-and-OpenIG-Stack#openam-installation\" rel=\"noopener noreferrer nofollow\">How to Add Authorization and Protect Your Application With OpenAM and OpenIG Stack<\/a>\u00a0.<\/p>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0444\u0438\u043b\u044c\u0442\u0440 \u0432\u0430\u043b\u0438\u0434\u0430\u0446\u0438\u0438 \u0442\u043e\u043a\u0435\u043d\u0430 OpenAM \u0432 \u0444\u0430\u0439\u043b \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 OpenIG <code>10-websocket.json<\/code><\/p>\n<pre><code class=\"json\">{   \"type\": \"ConditionalFilter\",   \"config\": {     \"condition\": \"${empty contexts.sts.issuedToken and not empty request.cookies['iPlanetDirectoryPro'][0].value}\",     \"delegate\": {       \"type\": \"TokenTransformationFilter\",       \"config\": {         \"openamUri\": \"${system['openam']}\",         \"realm\": \"\/\",         \"instance\": \"jwt\",         \"from\": \"OPENAM\",         \"to\": \"OPENIDCONNECT\",         \"idToken\": \"${request.cookies['iPlanetDirectoryPro'][0].value}\"       }     }   } }, {   \"type\": \"ConditionalFilter\",   \"config\": {     \"condition\": \"${not empty contexts.sts.issuedToken}\",     \"delegate\": {       \"type\": \"HeaderFilter\",       \"config\": {         \"messageType\": \"REQUEST\",         \"remove\": [           \"Authorization\",           \"JWT\"         ],         \"add\": {           \"Authorization\": [             \"Bearer ${contexts.sts.issuedToken}\"           ]         }       }     }   } }, {   \"type\": \"ConditionEnforcementFilter\",   \"config\": {     \"condition\": \"${not empty contexts.sts.issuedToken}\",     \"failureHandler\": {       \"type\": \"StaticResponseHandler\",       \"config\": {         \"status\": 401,         \"reason\": \"Found\",         \"headers\": {           \"Content-Type\": [             \"application\/json\"           ],         },         \"entity\": \"{ \\\\\"Error\\\\\": \\\\\"Unauthorized\\\\\"}\"       }     }   } } <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0442\u0440\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0434\u0435\u043b\u0430\u044e\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435: \u041f\u0435\u0440\u0432\u044b\u0439 \u0444\u0438\u043b\u044c\u0442\u0440 \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u0438\u0440\u0443\u0435\u0442 \u0442\u043e\u043a\u0435\u043d OpenAM \u0432 JWT \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442 \u0435\u0433\u043e \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442 \u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u0412\u0442\u043e\u0440\u043e\u0439 \u0444\u0438\u043b\u044c\u0442\u0440 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 JWT \u0432 \u0437\u0430\u043f\u0440\u043e\u0441 \u043a \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u043e\u043c\u0443 \u0441\u0435\u0440\u0432\u0438\u0441\u0443. \u0422\u0440\u0435\u0442\u0438\u0439 \u0444\u0438\u043b\u044c\u0442\u0440 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442, \u0447\u0442\u043e \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0435\u0441\u0442\u044c \u0442\u043e\u043a\u0435\u043d JWT, \u0438, \u0435\u0441\u043b\u0438 \u0435\u0433\u043e \u043d\u0435\u0442, \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u043a\u043b\u0438\u0435\u043d\u0442\u0443 401 \u043e\u0448\u0438\u0431\u043a\u0443.<\/p>\n<h2>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0440\u0435\u0448\u0435\u043d\u0438\u044f<\/h2>\n<p>\u041e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 URL \u00a0<a href=\"http:\/\/openig.example.org:8081\/ui\" rel=\"noopener noreferrer nofollow\">http:\/\/openig.example.org:8081\/ui<\/a> \u0438 \u043d\u0430\u0436\u043c\u0438\u0442\u0435 \u043a\u043d\u043e\u043f\u043a\u0443 <code>Connect<\/code> . \u0412\u044b \u0443\u0432\u0438\u0434\u0438\u0442\u0435 \u043e\u0448\u0438\u0431\u043a\u0443 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f.<\/p>\n<pre><code>Log: connecting... socket error occurred socket connection closed <\/code><\/pre>\n<p>\u041e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 \u0435\u0449\u0435 \u043e\u0434\u043d\u0443 \u0432\u043a\u043b\u0430\u0434\u043a\u0443 \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 \u0438 \u043e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 URL OpenAM \u00a0<a href=\"http:\/\/openam.example.org:8080\/openam\" rel=\"noopener noreferrer nofollow\">http:\/\/openam.example.org:8080\/openam<\/a>.  \u0410\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u0439\u0442\u0435\u0441\u044c \u0432 OpenAM. \u0414\u043b\u044f \u0432\u0445\u043e\u0434\u0430 \u043c\u043e\u0436\u0435\u0442\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043b\u043e\u0433\u0438\u043d <code>demo<\/code> \u043f\u0430\u0440\u043e\u043b\u044c <code>changeit<\/code>. \u0412\u0435\u0440\u043d\u0438\u0442\u0435\u0441\u044c \u043d\u0430 \u0432\u043a\u043b\u0430\u0434\u043a\u0443 \u0441 URL <a href=\"http:\/\/openig.example.org:8081\/ui\" rel=\"noopener noreferrer nofollow\">http:\/\/openig.example.org:8081\/ui<\/a> \u0438 \u043f\u043e\u043f\u0440\u043e\u0431\u0443\u0439\u0442\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0438\u0442\u044c\u0441\u044f \u0441\u043d\u043e\u0432\u0430. \u0412\u044b \u0443\u0432\u0438\u0434\u0435\u0442\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435:<\/p>\n<pre><code>connecting... connected <\/code><\/pre>\n<p>\u041d\u0430\u0436\u043c\u0438\u0442\u0435 \u043a\u043d\u043e\u043f\u043a\u0443 <code>Send Message<\/code> . \u0412\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u0443\u0432\u0438\u0434\u0435\u0442\u044c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u044f:<\/p>\n<pre><code>sending message... got response message from server: Test message <\/code><\/pre>\n<p>\u0412\u044b\u0439\u0434\u0438\u0442\u0435 \u0438\u0437 OpenAM \u0438 \u0432\u0435\u0440\u043d\u0438\u0442\u0435\u0441\u044c \u043d\u0430 \u0432\u043a\u043b\u0430\u0434\u043a\u0443 \u00a0<a href=\"http:\/\/openig.example.org:8081\/ui\" rel=\"noopener noreferrer nofollow\">http:\/\/openig.example.org:8081\/ui<\/a>. \u041f\u043e\u0434\u043e\u0436\u0434\u0438\u0442\u0435 3 \u043c\u0438\u043d\u0443\u0442\u044b (\u043a\u0430\u043a \u0443\u043a\u0430\u0437\u0430\u043d\u043e \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 <code>org.openidentityplatform.openig.websocket.ttl<\/code>) \u0438 \u043f\u043e\u043f\u0440\u043e\u0431\u0443\u0439\u0442\u0435 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0435 \u0441\u043d\u043e\u0432\u0430. \u0412\u044b \u0443\u0432\u0438\u0434\u0438\u0442\u0435:<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/f90\/392\/cb0\/f90392cb082124d9a2597962d65b5409.png\" width=\"2000\" height=\"937\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f90\/392\/cb0\/f90392cb082124d9a2597962d65b5409.png\"\/><\/figure>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/823872\/\"> https:\/\/habr.com\/ru\/articles\/823872\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0435\u043d\u0438\u0435\u043c \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/github.com\/OpenIdentityPlatform\/OpenAM\/wiki\/How-to-Add-Authorization-and-Protect-Your-Application-With-OpenAM-and-OpenIG-Stack\" rel=\"noopener noreferrer nofollow\">How to Add Authorization and Protect Your Application With OpenAM and OpenIG Stack<\/a>. \u041f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043e\u043f\u0438\u0441\u044b\u0432\u0430\u043b\u0430, \u043a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u043a\u043e\u043d\u0435\u0447\u043d\u044b\u0435 \u0442\u043e\u0447\u043a\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u043f\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u043c\u0443 HTTP \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0443. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043d\u0430 WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0447\u0435\u0440\u0435\u0437 OpenIG, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e OpenAM. \u0414\u043b\u044f \u0443\u043f\u0440\u043e\u0449\u0435\u043d\u0438\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0438 \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432, \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c Docker \u0438 Docker Compose.<\/p>\n<h2>\u0414\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 WebSocket \u0441\u0435\u0440\u0432\u0435\u0440<\/h2>\n<p>\u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 <a href=\"https:\/\/hub.docker.com\/r\/jmalloc\/echo-server\" rel=\"noopener noreferrer nofollow\">echo-server<\/a>. \u0427\u0442\u043e\u0431\u044b \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0438\u0441 \u0432 Docker, \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 <code>docker-compose.yaml<\/code> \u0444\u0430\u0439\u043b \u0438 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0432 \u043d\u0435\u0433\u043e echo-server.<\/p>\n<pre><code class=\"yaml\">services:   echo-server:     image: jmalloc\/echo-server     restart: always     ports:           - \"8082:8080\"     networks:       openam_network:         aliases:           - echo-server networks:   openam_network:     driver: bridge <\/code><\/pre>\n<p>\u0412\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u0443 <code>docker compose up<\/code> \u0438, \u043f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e, \u043a\u0430\u043a \u0441\u0435\u0440\u0432\u0435\u0440 \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u043f\u0443\u0449\u0435\u043d, \u0432\u044b \u0443\u0432\u0438\u0434\u0438\u0442\u0435 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u0438 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0435:<\/p>\n<pre><code>Echo server listening on port 8080.<\/code><\/pre>\n<h2>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f OpenIG<\/h2>\n<p>\u041d\u0430\u0441\u0442\u0440\u043e\u0438\u043c OpenIG \u0442\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u0448\u043b\u044e\u0437 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u043b \u0441\u0442\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e HTML \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0443 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435\u043c.<\/p>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0430\u043f\u043a\u0443 <code>openig-config<\/code> , \u043f\u0435\u0440\u0435\u0439\u0434\u0438\u0442\u0435 \u0432 \u043d\u0435\u0435 \u0438 \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0434\u0432\u0430 \u0444\u0430\u0439\u043b\u0430: <code>admin.json<\/code> \u0438 <code>config.json<\/code> \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c:<\/p>\n<p><code>admin.json<\/code> :<\/p>\n<pre><code class=\"json\">{   \"prefix\" : \"openig\",   \"mode\": \"PRODUCTION\" }<\/code><\/pre>\n<p><code>config.json<\/code> :<\/p>\n<pre><code class=\"json\">{   \"heap\": [],   \"handler\": {     \"type\": \"Chain\",     \"config\": {       \"filters\": [],       \"handler\": {         \"type\": \"Router\",         \"name\": \"_router\",         \"capture\": \"all\"       }     }   } } <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u0438\u043c \u0432 OpenIG \u0441\u0442\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e HTML \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0443 \u0441 UI \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u0441 WebSocket. \u0412 \u043f\u0430\u043f\u043a\u0435 <code>openig-config<\/code> \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e <code>static<\/code> \u0438 \u0432 \u043d\u0435\u0439 \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0444\u0430\u0439\u043b <code>ws-client.html<\/code> \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c:<\/p>\n<pre><code class=\"xml\">&lt;!DOCTYPE html> &lt;html lang='en'> &lt;head>     &lt;meta charset='UTF-8'>     &lt;title>WS-Client&lt;\/title>     &lt;style>         #log p {             margin: 0;         }         #log p.error {             color: red;         }     &lt;\/style> &lt;\/head> &lt;body>   &lt;div>     &lt;h1>WS-Client&lt;\/h1>       &lt;button id='connect' type='button'>Connect&lt;\/button>       &amp;nbsp;       &lt;button id='send' type='button'>Send Message&lt;\/button>       &lt;br>       &lt;label for='log'>Log:&lt;\/label>       &lt;div id='log'>&lt;\/div>   &lt;\/div>   &lt;script>       const connectBtn = document.getElementById('connect');       connectBtn.onclick = connect;       let socket;       function connect() {           appendToConsole('connecting...')           const endpoint = 'ws:\/\/' + location.host + '\/ws-handler';           socket = new WebSocket(endpoint);           socket.onmessage = function(event) {               appendToConsole('got response message from server: ' + event.data);           };           socket.onopen = function () {               appendToConsole('connected')           };           socket.onerror = function (e) {               appendToConsole('socket error occurred', true);           }           socket.onclose = function () {               appendToConsole('socket connection closed')           }       }   const sendBtn = document.getElementById('send');   sendBtn.onclick = function () {       if(socket.readyState !== WebSocket.OPEN) {           appendToConsole('socket is not open', true);           return;       }       appendToConsole('sending message...');       try {           socket.send('Test message');       } catch (e) {           appendToConsole('error sending message: ' + e.message, true)       }   }    function appendToConsole(message, error) {       let className = '';       if (error) {           console.error(message);           className = 'error';       } else {           console.log(message);       }       const log = document.getElementById('log');       const p = document.createElement('p');       p.innerText = message;       p.className = className;       log.append(p)   }  &lt;\/script> &lt;\/body> &lt;\/html> <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u044b OpenIG \u0434\u043b\u044f \u043a\u043e\u043d\u0435\u0447\u043d\u044b\u0445 \u0442\u043e\u0447\u0435\u043a UI \u0438 WebSocket. \u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0430\u043f\u043a\u0443 <code>routes<\/code> \u0432\u043d\u0443\u0442\u0440\u0438 \u043f\u0430\u043f\u043a\u0438 <code>openig-config<\/code>. \u0412\u043d\u0443\u0442\u0440\u0438 \u043f\u0430\u043f\u043a\u0438 <code>routes<\/code> \u0441\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u0434\u0432\u0430 \u0444\u0430\u0439\u043b\u0430 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 <code>10-ui.json<\/code> \u0434\u043b\u044f UI \u0438 <code>10-websocket.json<\/code> \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b WebSocket, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e.<\/p>\n<p><code>10-ui.json<\/code> :<\/p>\n<pre><code class=\"json\">{     \"name\": \"${matches(request.uri.path, '^\/ui')}\",     \"condition\": \"${matches(request.uri.path, '^\/ui')}\",     \"monitor\": true,     \"timer\": true,     \"handler\": {        \"type\": \"Chain\",        \"config\": {           \"filters\": [],           \"handler\": \"WSClient\"        }     },     \"heap\": [        {          \"name\": \"WSClient\",          \"type\":\"StaticResponseHandler\",          \"config\": {             \"status\": 200,             \"entity\": \"${read(system['openig.base'].concat('\/config\/static\/ws-client.html'))}\"          }        }     ]  } <\/code><\/pre>\n<p><code>10-websocket.json<\/code>:<\/p>\n<pre><code class=\"json\">{   \"name\": \"${matches(request.uri.path, '^\/ws-handler')}\",   \"condition\": \"${matches(request.uri.path, '^\/ws-handler')}\",   \"monitor\": true,   \"timer\": true,   \"handler\": {     \"type\": \"Chain\",     \"config\": {       \"filters\": [         {           \"type\": \"HeaderFilter\",           \"config\": {             \"messageType\": \"REQUEST\",             \"add\": {               \"Host\": [                 \"${matchingGroups(system['ws.secured'],\\\\\"(http|https):\\\\\/\\\\\/(.[^\\\\\/]*)\\\\\")[2]}\"               ]             },             \"remove\": [               \"Sec-Websocket-Key\",               \"Sec-Websocket-Version\",               \"Host\",               \"Origin\"             ]           }         }       ],       \"handler\": \"EndpointHandler\"     }   },   \"heap\": [     {       \"name\": \"EndpointHandler\",       \"type\": \"DispatchHandler\",       \"config\": {         \"bindings\": [           {             \"handler\": \"ClientHandler\",             \"capture\": \"all\",             \"baseURI\": \"${system['ws.secured']}\"           }         ]       }     }   ] } <\/code><\/pre>\n<p>\u041e\u0431\u0440\u0430\u0442\u0438\u0442\u0435 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435, \u0447\u0442\u043e \u0432 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0435 \u0438\u0437 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0443\u0434\u0430\u043b\u044f\u044e\u0442\u0441\u044f HTTP \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0438 \u0434\u043b\u044f \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043e\u0442 \u0438\u043d\u0441\u0442\u0430\u043d\u0441\u0430 OpenIG \u0434\u043e \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 <code>echo-server<\/code> .<\/p>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441 OpenIG \u0432 \u0444\u0430\u0439\u043b <code>docker-compose.yml<\/code> :<\/p>\n<pre><code class=\"yaml\">...     openig:     image: openidentityplatform\/openig:latest     build: .     volumes:       - .\/openig-config:\/usr\/local\/openig-config\/config:ro     ports:         - \"8081:8080\"       - \"8000:8000\"     environment:       CATALINA_OPTS: -Dopenig.base=\/usr\/local\/openig-config -Dsecured=http:\/\/echo-server:8080 -Dopenam=http:\/\/openam.example.org:8080\/openam -Dws.secured=ws:\/\/echo-server:8080 -Dorg.openidentityplatform.openig.websocket.ttl=180     networks:       openam_network:         aliases:           - openig.example.org ... <\/code><\/pre>\n<p>\u0421\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0435 \u0441\u0432\u043e\u0439\u0441\u0442\u0432\u0430 \u0438\u0437 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0432\u044b\u0448\u0435:<\/p>\n<div>\n<div class=\"table\">\n<table>\n<tbody>\n<tr>\n<th>\n<p>\u0421\u0432\u043e\u0439\u0441\u0442\u0432\u043e<\/p>\n<\/th>\n<th>\n<p>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435<\/p>\n<\/th>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">secured<\/p>\n<\/td>\n<td>\n<p align=\"left\">URL HTTP \u0441\u0435\u0440\u0432\u0438\u0441\u0430<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">ws.secured<\/p>\n<\/td>\n<td>\n<p align=\"left\">URL WebSocket \u0441\u0435\u0440\u0432\u0438\u0441\u0430<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">openam<\/p>\n<\/td>\n<td>\n<p align=\"left\">URL OpenAM (\u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0432 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0445 \u0440\u0430\u0437\u0434\u0435\u043b\u0430\u0445)<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p align=\"left\">org.openidentityplatform.openig.websocket.ttl<\/p>\n<\/td>\n<td>\n<p align=\"left\">\u041f\u0435\u0440\u0438\u043e\u0434\u0438\u0447\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0432\u0430\u043b\u0438\u0434\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0441\u0441\u0438\u0438 \u0432 \u0441\u0435\u043a\u0443\u043d\u0434\u0430\u0445<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>\u0417\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439 <code>docker compose up<\/code> . \u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e, \u043a\u0430\u043a Docker \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u044b \u0441 OpenIG \u0438 echo-server \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u044b, \u043e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 URL <a href=\"http:\/\/localhost:8080\/ui\" rel=\"noopener noreferrer nofollow\">http:\/\/localhost:8080\/ui<\/a> . \u0412\u044b \u0441\u043c\u043e\u0436\u0435\u0442\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c WebSocket \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0438 \u0432\u0441\u0435 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 \u0431\u0443\u0434\u0435\u0442 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442\u044c \u0447\u0435\u0440\u0435\u0437 OpenIG.<\/p>\n<h2>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f OpenAM<\/h2>\n<p>\u0414\u043e\u0431\u0430\u0432\u0438\u043c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u0447\u0435\u0440\u0435\u0437 OpenAM \u0432 \u043d\u0430\u0448 \u0441\u0442\u0435\u043a. \u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441 OpenAM \u0432 \u0444\u0430\u0439\u043b <code>docker-compose.yaml<\/code><\/p>\n<pre><code class=\"yaml\">...   openam:     image: openidentityplatform\/openam     ports:         - \"8080:8080\"     networks:       openam_network:         aliases:           - openam.example.org ... <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0438\u043c\u0435\u043d\u0430 \u0445\u043e\u0441\u0442\u043e\u0432 OpenAM \u0438 OpenIG \u0432 \u0444\u0430\u0439\u043b\u00a0<code>hosts<\/code>, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440\u00a0<code>127.0.0.1 openam.example.org openig.example.org<\/code>\u00a0.<\/p>\n<p>\u0412 Windows \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0444\u0430\u0439\u043b\u00a0<code>hosts<\/code>\u00a0\u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443\u00a0<code>C:\\\\Windows\\\\System32\\\\drivers\\\\etc\\\\hosts<\/code>\u00a0, \u0432 Linux \u0438 Mac \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443\u00a0<code>\/etc\/hosts<\/code>.<\/p>\n<p>\u0417\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439 <code>docker compose up<\/code> , \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u0435 OpenAM, \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u0435 cookie domain \u0438 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 jwt endpoint \u043a\u0430\u043a \u043e\u043f\u0438\u0441\u0430\u043d\u043e \u0432 \u0441\u0442\u0430\u0442\u044c\u0435 \u00a0<a href=\"https:\/\/github.com\/OpenIdentityPlatform\/OpenAM\/wiki\/How-to-Add-Authorization-and-Protect-Your-Application-With-OpenAM-and-OpenIG-Stack#openam-installation\" rel=\"noopener noreferrer nofollow\">How to Add Authorization and Protect Your Application With OpenAM and OpenIG Stack<\/a>\u00a0.<\/p>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0444\u0438\u043b\u044c\u0442\u0440 \u0432\u0430\u043b\u0438\u0434\u0430\u0446\u0438\u0438 \u0442\u043e\u043a\u0435\u043d\u0430 OpenAM \u0432 \u0444\u0430\u0439\u043b \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 OpenIG <code>10-websocket.json<\/code><\/p>\n<pre><code class=\"json\">{   \"type\": \"ConditionalFilter\",   \"config\": {     \"condition\": \"${empty contexts.sts.issuedToken and not empty request.cookies['iPlanetDirectoryPro'][0].value}\",     \"delegate\": {       \"type\": \"TokenTransformationFilter\",       \"config\": {         \"openamUri\": \"${system['openam']}\",         \"realm\": \"\/\",         \"instance\": \"jwt\",         \"from\": \"OPENAM\",         \"to\": \"OPENIDCONNECT\",         \"idToken\": \"${request.cookies['iPlanetDirectoryPro'][0].value}\"       }     }   } }, {   \"type\": \"ConditionalFilter\",   \"config\": {     \"condition\": \"${not empty contexts.sts.issuedToken}\",     \"delegate\": {       \"type\": \"HeaderFilter\",       \"config\": {         \"messageType\": \"REQUEST\",         \"remove\": [           \"Authorization\",           \"JWT\"         ],         \"add\": {           \"Authorization\": [             \"Bearer ${contexts.sts.issuedToken}\"           ]         }       }     }   } }, {   \"type\": \"ConditionEnforcementFilter\",   \"config\": {     \"condition\": \"${not empty contexts.sts.issuedToken}\",     \"failureHandler\": {       \"type\": \"StaticResponseHandler\",       \"config\": {         \"status\": 401,         \"reason\": \"Found\",         \"headers\": {           \"Content-Type\": [             \"application\/json\"           ],         },         \"entity\": \"{ \\\\\"Error\\\\\": \\\\\"Unauthorized\\\\\"}\"       }     }   } } <\/code><\/pre>\n<p>\u0414\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0442\u0440\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u0434\u0435\u043b\u0430\u044e\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435: \u041f\u0435\u0440\u0432\u044b\u0439 \u0444\u0438\u043b\u044c\u0442\u0440 \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u0438\u0440\u0443\u0435\u0442 \u0442\u043e\u043a\u0435\u043d OpenAM \u0432 JWT \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442 \u0435\u0433\u043e \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442 \u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u0412\u0442\u043e\u0440\u043e\u0439 \u0444\u0438\u043b\u044c\u0442\u0440 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 JWT \u0432 \u0437\u0430\u043f\u0440\u043e\u0441 \u043a \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u043e\u043c\u0443 \u0441\u0435\u0440\u0432\u0438\u0441\u0443. \u0422\u0440\u0435\u0442\u0438\u0439 \u0444\u0438\u043b\u044c\u0442\u0440 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442, \u0447\u0442\u043e \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0435\u0441\u0442\u044c \u0442\u043e\u043a\u0435\u043d JWT, \u0438, \u0435\u0441\u043b\u0438 \u0435\u0433\u043e \u043d\u0435\u0442, \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u043a\u043b\u0438\u0435\u043d\u0442\u0443 401 \u043e\u0448\u0438\u0431\u043a\u0443.<\/p>\n<h2>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0440\u0435\u0448\u0435\u043d\u0438\u044f<\/h2>\n<p>\u041e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 URL \u00a0<a href=\"http:\/\/openig.example.org:8081\/ui\" rel=\"noopener noreferrer nofollow\">http:\/\/openig.example.org:8081\/ui<\/a> \u0438 \u043d\u0430\u0436\u043c\u0438\u0442\u0435 \u043a\u043d\u043e\u043f\u043a\u0443 <code>Connect<\/code> . \u0412\u044b \u0443\u0432\u0438\u0434\u0438\u0442\u0435 \u043e\u0448\u0438\u0431\u043a\u0443 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f.<\/p>\n<pre><code>Log: connecting... socket error occurred socket connection closed <\/code><\/pre>\n<p>\u041e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 \u0435\u0449\u0435 \u043e\u0434\u043d\u0443 \u0432\u043a\u043b\u0430\u0434\u043a\u0443 \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 \u0438 \u043e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 URL OpenAM \u00a0<a href=\"http:\/\/openam.example.org:8080\/openam\" rel=\"noopener noreferrer nofollow\">http:\/\/openam.example.org:8080\/openam<\/a>.  \u0410\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u0439\u0442\u0435\u0441\u044c \u0432 OpenAM. \u0414\u043b\u044f \u0432\u0445\u043e\u0434\u0430 \u043c\u043e\u0436\u0435\u0442\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043b\u043e\u0433\u0438\u043d <code>demo<\/code> \u043f\u0430\u0440\u043e\u043b\u044c <code>changeit<\/code>. \u0412\u0435\u0440\u043d\u0438\u0442\u0435\u0441\u044c \u043d\u0430 \u0432\u043a\u043b\u0430\u0434\u043a\u0443 \u0441 URL <a href=\"http:\/\/openig.example.org:8081\/ui\" rel=\"noopener noreferrer nofollow\">http:\/\/openig.example.org:8081\/ui<\/a> \u0438 \u043f\u043e\u043f\u0440\u043e\u0431\u0443\u0439\u0442\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0438\u0442\u044c\u0441\u044f \u0441\u043d\u043e\u0432\u0430. \u0412\u044b \u0443\u0432\u0438\u0434\u0435\u0442\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435:<\/p>\n<pre><code>connecting... <\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-380081","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/380081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=380081"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/380081\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=380081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=380081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=380081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}