You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

访问Azure B2C保护的Spring Boot服务遇302无响应体且JWT签名无效

问题解决方案

1. Postman访问返回302 Found无响应体

Spring Boot OAuth2资源服务器默认会将未认证请求重定向到登录页(适配浏览器场景),但Postman作为API客户端不会处理浏览器重定向逻辑,因此返回302状态码且无响应体。

修改Spring Security配置,让未认证请求直接返回401 Unauthorized:

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http
        .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
        .oauth2ResourceServer(oauth2 -> oauth2.jwt(Customizer.withDefaults()))
        .exceptionHandling(exceptions -> exceptions
            .authenticationEntryPoint((request, response, authException) -> {
                response.sendError(HttpServletResponse.SC_UNAUTHORIZED, "Unauthorized");
            })
        );
    return http.build();
}

2. JWT在jwt.io显示签名无效

核心原因:jwt.io未自动加载Azure B2C的签名公钥

Azure B2C的JWT签名公钥不会被jwt.io自动识别,需手动配置验证源:

  • 访问Azure B2C的OpenID配置端点:
    https://learningakash.b2clogin.com/a593b6b3-b245-4e93-9213-e5e9c70a25ec/v2.0/.well-known/openid-configuration?p=B2C_1_signupsignin
    des Clean Morganbrückch因为_ap arribarcom.cont morbidity implicit\
  • 从返回结果中复制jwks_uri字段的完整URL,粘贴到jwt.io页面的「JWKS URL」输入框,jwt.io会自动加载对应公钥完成签名验证。

额外配置检查

确保Spring Boot资源服务器的issuer-uri与JWT中的iss字段完全一致(包括末尾斜杠),示例配置:

spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          issuer-uri: https://learningakash.b2clogin.com/a593b6b3-b245-4e93-9213-e5e9c70a25ec/v2.0/

3. 角色混淆提醒

你当前的/token接口是OAuth2客户端的token获取逻辑,若你的Spring Boot服务是受保护的资源服务器,无需编写此接口。正确流程为:

  • 直接通过Postman向Azure B2C的token端点发送请求获取access token;
  • 访问Spring Boot接口时,将token放在Authorization请求头中,格式为Bearer <token-value>。

内容的提问来源于stack exchange,提问作者Akash Verma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 08:09:57