Spring OAuth示例文档含过时类,求替代方案及报错解决
Spring Boot OAuth2 授权码模式客户端替换方案及报错解决
核心问题原因
OAuth2AuthorizationCodeGrantRequestEntityConverter和DefaultAuthorizationCodeTokenResponseClient在Spring Security 6.x+版本中已被标记为过时,官方推荐的替代类DefaultOAuth2TokenRequestParametersConverter和RestClientAuthorizationCodeTokenResponseClient的API设计与旧类差异较大,直接替换会因泛型要求、方法名变更触发报错。
正确替代实现步骤
1. 替换客户端类与处理方法
旧类的setRequestEntityConverter方法已被移除,新的RestClientAuthorizationCodeTokenResponseClient通过配置RestClient来处理请求逻辑,参数转换默认由DefaultOAuth2TokenRequestParametersConverter完成,无需手动绑定转换器(无自定义需求时)。
2. 解决类型推断报错
DefaultOAuth2TokenRequestParametersConverter是泛型类,必须明确指定泛型类型为OAuth2AuthorizationCodeGrantRequest,否则会触发「Not enough information to infer type variable T」错误。
完整示例代码
import org.springframework.security.oauth2.client.endpoint.DefaultOAuth2TokenRequestParametersConverter; import org.springframework.security.oauth2.client.endpoint.OAuth2AuthorizationCodeGrantRequest; import org.springframework.security.oauth2.client.endpoint.RestClientAuthorizationCodeTokenResponseClient; import org.springframework.security.oauth2.client.registration.ClientRegistration; import org.springframework.security.oauth2.core.endpoint.OAuth2AuthorizationExchange; import org.springframework.security.oauth2.core.endpoint.OAuth2AuthorizationRequest; import org.springframework.security.oauth2.core.endpoint.OAuth2AuthorizationResponse; import org.springframework.web.client.RestClient; // 构建客户端注册信息(实际项目中可从配置文件读取) ClientRegistration clientRegistration = ClientRegistration.withRegistrationId("your-reg-id") .clientId("your-client-id") .clientSecret("your-client-secret") .authorizationUri("https://auth-server.com/oauth2/authorize") .tokenUri("https://auth-server.com/oauth2/token") .redirectUri("https://your-app.com/login/oauth2/code/your-reg-id") .authorizationGrantType(org.springframework.security.oauth2.core.AuthorizationGrantType.AUTHORIZATION_CODE) .scope("openid", "profile", "email") .build(); // 初始化参数转换器,指定泛型类型 DefaultOAuth2TokenRequestParametersConverter<OAuth2AuthorizationCodeGrantRequest> parametersConverter = new DefaultOAuth2TokenRequestParametersConverter<>(); // 初始化新的Token响应客户端 RestClientAuthorizationCodeTokenResponseClient tokenResponseClient = new RestClientAuthorizationCodeTokenResponseClient(); // 如需自定义请求配置(如添加自定义头),通过RestClient构建器设置 tokenResponseClient.setRestClient(RestClient.builder() .defaultHeader("X-Custom-Header", "custom-value") .build()); // 构建授权码请求并获取Token响应 OAuth2AuthorizationRequest authRequest = OAuth2AuthorizationRequest.builder( clientRegistration.getAuthorizationGrantType(), clientRegistration.getClientId() ) .redirectUri(clientRegistration.getRedirectUri()) .scope(clientRegistration.getScopes()) .build(); OAuth2AuthorizationExchange authExchange = new OAuth2AuthorizationExchange( authRequest, OAuth2AuthorizationResponse.success("authorization-code-value") .redirectUri(clientRegistration.getRedirectUri()) .build() ); OAuth2AuthorizationCodeGrantRequest grantRequest = new OAuth2AuthorizationCodeGrantRequest( clientRegistration, authExchange ); tokenResponseClient.getTokenResponse(grantRequest);
关键变化说明
- 旧类的请求实体转换逻辑被拆分,参数转换由
DefaultOAuth2TokenRequestParametersConverter负责,请求发送由RestClient处理,无需手动绑定转换器。 - 必须为
DefaultOAuth2TokenRequestParametersConverter指定泛型参数,否则无法完成类型推断。
额外注意事项
- 确保项目使用Spring Security 6.0及以上版本,新类是6.x版本才引入的。
- 如需自定义参数转换逻辑,可继承
DefaultOAuth2TokenRequestParametersConverter并重写convert方法,或通过RestClient拦截器修改请求参数。
内容的提问来源于stack exchange,提问作者Jackie
相关产品推荐
相关产品推荐

