Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[BUG] - 服务间认证,消费方多实例时,服务方认证鉴权会失败

Open
#5,139 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
java

Research direction

Start by reading the token-generation logic in ConsumerTokenManager and the consumer public-key lookup in ProviderTokenManager. Reproduce the failure with multiple consumer instances on ServiceComb 3.3.0 and trace how applicationName, serviceName, and instance-specific key pairs are used. Done means every consumer instance can authenticate and pass provider authorization successfully.

Written by the indexing model from the issue text.

Description

bug
Steps to Reproduce

1、ConsumerTokenManager 生成的逻辑中,token拼接使用的 applicationName 和 serviceName,但是用于签名的公私钥对是每个微服务实例生成的。

2、ProviderTokenManager 去取消费方微服务的公钥时,默认取的实例组中的 get(0) 对应的公钥,就会导致多消费实例时,其他消费方认证失败

Expected Behavior

No response

Servicecomb Version

3.3.0

Additional Context

No response

Dominant language
Java
Stars
1.9k
Forks
813
Avg merge
8d 23h
Merged PRs (30d)
1

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/servicecomb-java-chassis

All issues in apache/servicecomb-java-chassis

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.