我试图使用资源令牌连接到Azure Cosmos DB中的Gremlin集合。我从这里修改了文档(主要针对C#):https://docs.microsoft.com/en-us/azure/cosmos-db/how-to-use-resource-tokens-gremlin
问题是,一旦我试图访问数据,令牌的日期标头似乎无效:
Exception in thread "main" java.util.concurrent.CompletionException: org.apache.tinkerpop.gremlin.driver.exception.ResponseException:
ActivityId : 00000000-0000-0000-0000-000000000000
ExceptionType : UnauthorizedException
ExceptionMessage :
The input date header is invalid format. Please pass in RFC 1123 style date format.
ActivityId: 755ab024-fc79-47a3-bc44-3231b2db7dc1, documentdb-dotnet-sdk/2.7.0 Host/64-bit MicrosoftWindowsNT/6.2.9200.0
Source : Microsoft.Azure.Documents.ClientThe input date header is invalid format. Please pass in RFC 1123 style date format.
ActivityId: 755ab024-fc79-47a3-bc44-3231b2db7dc1, documentdb-dotnet-sdk/2.7.0 Host/64-bit MicrosoftWindowsNT/6.2.9200.0
BackendStatusCode : Unauthorized
BackendActivityId : 755ab024-fc79-47a3-bc44-3231b2db7dc1
HResult : 0x80131500
有人知道怎么解决吗?通过-duser.timezone=GMT
将JVM设置为GMT
...
import com.microsoft.azure.documentdb.DocumentClient;
import com.microsoft.azure.documentdb.DocumentClientException;
import com.microsoft.azure.documentdb.FeedResponse;
import com.microsoft.azure.documentdb.Permission;
import com.microsoft.azure.documentdb.PermissionMode;
import com.microsoft.azure.documentdb.ResourceResponse;
import com.microsoft.azure.documentdb.User;
...
public class TokenGenerator {
private String USER_ID = "demo-1";
public String generateToken(CmdLineConfiguration cfg) throws DocumentClientException {
try (DocumentClient client = Utilities.documentClientFrom(cfg)) {
String databaseLink = String.format("/dbs/%s", cfg.getDatabaseId());
String collectionLink = String.format("/dbs/%s/colls/%s", cfg.getDatabaseId(), cfg.getCollectionId());
// get all users within database
FeedResponse<User> queryResults = client.readUsers(databaseLink, null);
List<User> onlineUsers = queryResults.getQueryIterable().toList();
// if a user exists, grab the first one, if not create it
User user;
Optional<User> onlineUser = onlineUsers.stream().filter(u -> u.getId().equals(USER_ID)).findFirst();
if (onlineUser.isPresent()) {
user = onlineUser.get();
} else {
User u = new User();
u.setId(USER_ID);
ResourceResponse<User> generatedUser = client.createUser(databaseLink, u, null);
user = generatedUser.getResource();
}
// read permissions, if existent use, else create
FeedResponse<Permission> permissionResponse = client.readPermissions(user.getSelfLink(), null);
List<Permission> onlinePermissions = permissionResponse.getQueryIterable().toList();
Permission permission;
if (onlinePermissions.size() == 0) {
Permission p = new Permission();
p.setPermissionMode(PermissionMode.Read);
p.setId(USER_ID + "_READ");
p.setResourceLink(collectionLink);
ResourceResponse<Permission> generatedPermission = client.createPermission(user.getSelfLink(), p, null);
permission = generatedPermission.getResource();
} else {
permission = onlinePermissions.get(0);
}
// return the token
return permission.getToken();
}
}
}
连接并查询Gremlin:
...
import org.apache.tinkerpop.gremlin.driver.AuthProperties;
import org.apache.tinkerpop.gremlin.driver.AuthProperties.Property;
import org.apache.tinkerpop.gremlin.driver.Client;
import org.apache.tinkerpop.gremlin.driver.Cluster;
import org.apache.tinkerpop.gremlin.driver.ResultSet;
...
Cluster cluster;
String collectionLink = String.format("/dbs/%s/colls/%s", cfg.getDatabaseId(), cfg.getCollectionId());
TokenGenerator tg = new TokenGenerator();
String token = tg.generateToken(cfg);
Cluster.Builder builder = Cluster.build(new File("src/remote.yaml"));
AuthProperties authenticationProperties = new AuthProperties();
authenticationProperties.with(AuthProperties.Property.USERNAME, collectionLink);
authenticationProperties.with(Property.PASSWORD, token);
builder.authProperties(authenticationProperties);
cluster = builder.create();
Client client = cluster.connect();
ResultSet results = client.submit("g.V().limit(1)");
// the following call fails
results.stream().forEach(System.out::println);
client.close();
cluster.close();
}
src/remote.yml
hosts: [COSMOSNAME.gremlin.cosmosdb.azure.com]
port: 443
username: /dbs/DBNAME/colls/COLLECTIONNAME
connectionPool: { enableSsl: true}
serializer: { className: org.apache.tinkerpop.gremlin.driver.ser.GraphSONMessageSerializerV2d0, config: { serializeResultToString: true }}
我不能在我这边重现你的问题。我尝试为Java扩展这个cosmos graph demo,在这个demo中使用了主密钥,所以我遵循您的部分代码和官方示例,使用资源令牌访问graph db。
您与db的连接代码似乎很有效。我的主类如下所示,与您的类似:
import org.apache.tinkerpop.gremlin.driver.*;
import org.apache.tinkerpop.gremlin.driver.exception.ResponseException;
import java.io.File;
import java.io.FileNotFoundException;
import java.io.IOException;
import java.util.List;
import java.util.Map;
import java.util.concurrent.CompletableFuture;
import java.util.concurrent.ExecutionException;
public class Program
{
static final String gremlinQueries[] = new String[] {"g.V().limit(1)"};
public static void main( String[] args ) throws ExecutionException, InterruptedException {
String token = "***";
Cluster cluster;
Client client;
try {
Cluster.Builder builder = Cluster.build(new File("src/remote.yaml"));
// Cluster.Builder builder = Cluster.build();
AuthProperties authenticationProperties = new AuthProperties();
authenticationProperties.with(AuthProperties.Property.USERNAME,
String.format("/dbs/%s/colls/%s", "db", "coll"));
// The format of the token is "type=resource&ver=1&sig=<base64 string>;<base64 string>;".
authenticationProperties.with(AuthProperties.Property.PASSWORD, token);
builder.authProperties(authenticationProperties);
// Attempt to create the connection objects
cluster = builder.create();
// cluster = Cluster.build(new File("src/remote.yaml")).create();
client = cluster.connect();
} catch (Exception e) {
// Handle file errors.
System.out.println("Couldn't find the configuration file.");
e.printStackTrace();
return;
}
// After connection is successful, run all the queries against the server.
for (String query : gremlinQueries) {
System.out.println("\nSubmitting this Gremlin query: " + query);
// Submitting remote query to the server.
ResultSet results = client.submit(query);
CompletableFuture<List<Result>> completableFutureResults;
CompletableFuture<Map<String, Object>> completableFutureStatusAttributes;
List<Result> resultList;
Map<String, Object> statusAttributes;
try{
completableFutureResults = results.all();
completableFutureStatusAttributes = results.statusAttributes();
resultList = completableFutureResults.get();
statusAttributes = completableFutureStatusAttributes.get();
}
catch(ExecutionException | InterruptedException e){
e.printStackTrace();
break;
}
catch(Exception e){
ResponseException re = (ResponseException) e.getCause();
// Response status codes. You can catch the 429 status code response and work on retry logic.
System.out.println("Status code: " + re.getStatusAttributes().get().get("x-ms-status-code"));
System.out.println("Substatus code: " + re.getStatusAttributes().get().get("x-ms-substatus-code"));
// If error code is 429, this value will inform how many milliseconds you need to wait before retrying.
System.out.println("Retry after (ms): " + re.getStatusAttributes().get().get("x-ms-retry-after"));
// Total Request Units (RUs) charged for the operation, upon failure.
System.out.println("Request charge: " + re.getStatusAttributes().get().get("x-ms-total-request-charge"));
// ActivityId for server-side debugging
System.out.println("ActivityId: " + re.getStatusAttributes().get().get("x-ms-activity-id"));
throw(e);
}
for (Result result : resultList) {
System.out.println("\nQuery result:");
System.out.println(result.toString());
}
// Status code for successful query. Usually HTTP 200.
System.out.println("Status: " + statusAttributes.get("x-ms-status-code").toString());
// Total Request Units (RUs) charged for the operation, after a successful run.
System.out.println("Total charge: " + statusAttributes.get("x-ms-total-request-charge").toString());
}
System.out.println("Demo complete!\n Press Enter key to continue...");
try{
System.in.read();
} catch (IOException e){
e.printStackTrace();
return;
}
// Properly close all opened clients and the cluster
cluster.close();
System.exit(0);
}
}
yaml文件:
hosts: [***.gremlin.cosmosdb.azure.com]
port: 443
username: /dbs/db/colls/coll
connectionPool: {
enableSsl: true}
serializer: { className: org.apache.tinkerpop.gremlin.driver.ser.GraphSONMessageSerializerV2d0, config: { serializeResultToString: true }}
问题内容: 我正在尝试在我的项目中实现csrf保护,但无法使其与jQuery Ajax一起使用。(不过,它适用于普通的帖子请求) 如果在发送表单之前使用chrome开发工具篡改令牌,则仍会看到“正在处理数据”文本,而不是错误。 app.js send.jade test.js 问题答案: 在有效负载消息中发送CSRF令牌: 为了简化您的工作,我认为您可以创建一个Jquery插件来执行此操作,如下所
我有一个基于网站的网络应用程序,通过AAD登录验证用户。成功的登录会将用户重定向回带有访问令牌的应用程序(这部分都是使用adal_angular.js/adal.js完成的) 然后将令牌传递给一个基于站点的api,该api代表用户获得一个新的令牌来调用下游api,如本例(https://github.com/azure-samples/active-directory-dotnet-webapi-
我试图创建spring rest服务,它是由我自己的oauth2资源服务器自动引诱的。我创建了资源服务器: {“error”:“server_error”,“error_description”:“java.io.NotSerializableException:org.springframework.security.crypto.bcrypt.bcryptPasswordenCoder”} 在
此查询引发异常: 我尝试用_: Ucanaccess抛出了一个新的错误: null 请参见执行查询的以下代码: 第一个查询成功执行,但第二个查询失败。
application.yml:
如果你需要更多的细节,请让我知道。