Spring Security集成Google登录失败:invalid_token_response错误排查
解决方案
使用Spring内置Google提供商配置,避免手动端点错误
Spring Security已内置Google OAuth2的标准端点配置,手动指定authorizationUri、tokenUri等字段易出现不匹配问题。修改googleClientRegistration()方法,只保留必要配置:private ClientRegistration googleClientRegistration() { return ClientRegistration.withRegistrationId("google") .clientId("yyy") .clientSecret("xxx") .redirectUri("{baseUrl}/login/oauth2/code/{registrationId}") .scope("openid", "email", "profile") .authorizationGrantType(AuthorizationGrantType.AUTHORIZATION_CODE) .clientAuthenticationMethod(ClientAuthenticationMethod.CLIENT_SECRET_POST) .build(); }更推荐通过
application.yml简化配置:spring: security: oauth2: client: registration: google: client-id: yyy client-secret: xxx scope: openid,email,profile检查重定向URI一致性
确保Google开发者控制台中配置的重定向URI与代码/配置文件中的完全一致,若应用上下文路径为/app,需确认server.servlet.context-path=/app已配置。修复响应字段不匹配问题
你调试看到的是令牌自省接口的返回结果,而非OAuth2授权码流程的标准响应(标准响应需包含access_token、token_type、id_token等字段),使用内置提供商配置可自动解决端点匹配错误。升级Spring Security版本
若使用旧版本,可能存在Google OAuth2响应格式兼容性问题,建议升级到Spring Security 5.7+或6.x稳定版本。启用详细日志定位问题
在application.yml中添加OAuth2日志配置,查看具体解析错误:logging: level: org.springframework.security.oauth2: DEBUG
内容的提问来源于stack exchange,提问作者YoavKlein
相关产品推荐
相关产品推荐

