You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将基于spring-security-jwt的旧代码迁移至Spring Security 6?

Spring Security 6 迁移:替换旧JWT解析代码

原问题与旧代码

旧依赖

implementation 'org.springframework.security:spring-security-jwt:1.1.1.RELEASE'
implementation 'org.springframework.security.oauth:spring-security-oauth2:2.5.2.RELEASE'

旧代码实现

import org.springframework.security.jwt.Jwt;
import org.springframework.security.jwt.JwtHelper;
import org.springframework.security.oauth2.common.util.JsonParser;
import org.springframework.security.oauth2.common.util.JsonParserFactory;

private String extractCredentials(String accessTokenCookieValue) {
  Jwt jwt = JwtHelper.decode(accessTokenCookieValue);
  JsonParser objectMapper = JsonParserFactory.create();
  return objectMapper.parseMap(jwt.getClaims()).get("credentials").toString();
}

迁移时尝试使用新导入但无法找到JwtHelper和JsonParserFactory的替代类,以下是完整迁移方案:


迁移步骤

1. 替换依赖(移除旧依赖,添加新依赖)

Spring Security 6已弃用原有的spring-security-jwt和spring-security-oauth2模块,改用官方整合的OAuth2资源服务器依赖。如果使用Spring Boot,直接引入以下starter即可:

Gradle 配置

implementation 'org.springframework.boot:spring-boot-starter-security'
implementation 'org.springframework.boot:spring-boot-starter-oauth2-resource-server'

Maven 配置

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
</dependency>

2. 修改代码实现

Spring Security 6提供了JwtDecoder接口处理JWT解析,且Jwt对象已内置claims解析能力,无需额外JSON解析工具。

场景1:保持原行为(仅解码JWT,不验证签名)

适合开发测试场景,生产环境不建议使用:

import org.springframework.security.oauth2.jwt.Jwt;
import org.springframework.security.oauth2.jwt.JwtDecoder;
import org.springframework.security.oauth2.jwt.NimbusJwtDecoder;
import com.nimbusds.jose.proc.SecurityContext;

private JwtDecoder createUnvalidatingJwtDecoder() {
    // 创建不验证签名的解码器,与原JwtHelper.decode行为一致
    return NimbusJwtDecoder.withJwtProcessor((jwt, context) -> jwt).build();
}

private String extractCredentials(String accessTokenCookieValue) {
    JwtDecoder decoder = createUnvalidatingJwtDecoder();
    Jwt jwt = decoder.decode(accessTokenCookieValue);
    // 直接从Jwt对象获取指定claim
    return jwt.getClaim("credentials").toString();
}

场景2:生产环境(启用JWT签名验证)

以对称密钥验证为例(根据实际签名算法调整):

import org.springframework.security.oauth2.jwt.Jwt;
import org.springframework.security.oauth2.jwt.JwtDecoder;
import org.springframework.security.oauth2.jwt.NimbusJwtDecoder;
import javax.crypto.spec.SecretKeySpec;

private JwtDecoder createValidatingJwtDecoder() {
    // 替换为实际的签名密钥,算法需与JWT生成时一致(如HS256)
    String secretKey = "your-actual-signing-secret";
    SecretKeySpec secret = new SecretKeySpec(secretKey.getBytes(), "HS256");
    return NimbusJwtDecoder.withSecretKey(secret).build();
}

private String extractCredentials(String accessTokenCookieValue) {
    JwtDecoder decoder = createValidatingJwtDecoder();
    Jwt jwt = decoder.decode(accessTokenCookieValue);
    return jwt.getClaim("credentials").toString();
}

关键说明

  • 移除旧的导入类:org.springframework.security.jwt.Jwt、JwtHelper、JsonParser、JsonParserFactory
  • 新的Jwt类直接提供getClaim()方法获取声明,无需手动解析JSON
  • 生产环境必须启用签名验证,避免伪造JWT带来的安全风险

内容的提问来源于stack exchange,提问作者Peter Penzov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 17:25:13