2017-08-29 339 views
2

我正在使用https://github.com/thomasdarimont/spring-boot-keycloak-server-example来运行keycloak实例。我试图从H2切换到PostgreSQL,会出现管理员帐户创建屏幕,但在创建初始管理员帐户失败:Keycloak/Liquibase:错误:列“salt”的类型为oid,但表达式的类型为bytea

Hibernate: 
insert 
into 
    CREDENTIAL 
    (ALGORITHM, COUNTER, CREATED_DATE, DEVICE, DIGITS, HASH_ITERATIONS, PERIOD, SALT, TYPE, USER_ID, VALUE, ID) 
values 
    (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?) 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [1] as [VARCHAR] - [pbkdf2-sha256] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [2] as [INTEGER] - [0] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [3] as [BIGINT] - [1504025461373] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [4] as [VARCHAR] - [null] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [5] as [INTEGER] - [0] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [6] as [INTEGER] - [27500] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [7] as [INTEGER] - [0] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [8] as [VARBINARY] - [[[email protected]] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [9] as [VARCHAR] - [password] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [10] as [VARCHAR] - [32e0eb33-091b-4791-a923-4cc9fc976371] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [11] as [VARCHAR] - [CBJ4e+h56g1I0uxyexae7p5xJ2xLILGh8Hkx4t/jGSZ74XHbqDmGLW2vfPyIUl17puB+hihu3OpwNJSjT+LRgw==] 
2017-08-29 18:51:01.482 TRACE 7020 --- [io-20909-exec-2] o.h.type.descriptor.sql.BasicBinder  : binding parameter [12] as [VARCHAR] - [738017b1-ff7b-47cf-a2e9-7c9f6055f0aa] 
2017-08-29 18:51:01.498 WARN 7020 --- [io-20909-exec-2] o.h.engine.jdbc.spi.SqlExceptionHelper : SQL Error: 0, SQLState: 42804 
2017-08-29 18:51:01.498 ERROR 7020 --- [io-20909-exec-2] o.h.engine.jdbc.spi.SqlExceptionHelper : ERROR: column "salt" is of type oid but expression is of type bytea 
Hint: You will need to rewrite or cast the expression. 
Position: 168 

我已经适应如下的keycloak-server.json的connectionsJpa设置:

"connectionsJpa": { 
    "provider": "default", 
    "default": { 
     "url": "${env.KEYCLOAK_DATABASE_URL:jdbc:postgresql://server/testdb}", 
     "driver": "${keycloak.connectionsJpa.driver:org.postgresql.Driver}", 
     "driverDialect": "${keycloak.connectionsJpa.driverDialect:org.hibernate.dialect.PostgreSQLDialect}", 
     "user": "${keycloak.connectionsJpa.user:user}", 
     "password": "${keycloak.connectionsJpa.password:password}", 
     "initializeEmpty": true, 
     "migrationStrategy": "update", 
     "showSql": "${keycloak.connectionsJpa.showSql:true}", 
     "formatSql": "${keycloak.connectionsJpa.formatSql:true}", 
     "globalStatsInterval": "${keycloak.connectionsJpa.globalStatsInterval:-1}" 
    } 
}, 

看来,自Liquibase 3.5.2以来,blob类型生成PostgreSQL类型的oid,而不是bytea了。请参阅CORE-1863

任何有解决方案的人?

+0

我在此期间创建了https://issues.jboss.org/browse/KEYCLOAK-5396。 – Bernd

回答

1

问题似乎是,Liquibase 3.5.2或更高版本将导致public.credential.salt列使用oid类型创建,而Keycloak期望它是bytea。

解决方案是恢复到早期版本的Liquibase(我推荐3.4.1,因为这是Keycloak通常使用的版本)。您可以通过在项目的主pom.xml中

<properties> 
    ...... 
    <liquibase.version>3.4.1</liquibase.version> 
</properties> 

添加liquibase版本的版本属性在此之后不要忘记删除旧Keycloak数据库,以便Keycloak可以用适当的盐类型时创建它这样做你重新开始。

+0

真棒,工作。非常感谢! – Bernd

相关问题