如何将基于spring-security-jwt的旧代码迁移至Spring Security 6?
Spring Security 6 迁移:替换旧JWT解析代码
原问题与旧代码
旧依赖
implementation 'org.springframework.security:spring-security-jwt:1.1.1.RELEASE' implementation 'org.springframework.security.oauth:spring-security-oauth2:2.5.2.RELEASE'
旧代码实现
import org.springframework.security.jwt.Jwt; import org.springframework.security.jwt.JwtHelper; import org.springframework.security.oauth2.common.util.JsonParser; import org.springframework.security.oauth2.common.util.JsonParserFactory; private String extractCredentials(String accessTokenCookieValue) { Jwt jwt = JwtHelper.decode(accessTokenCookieValue); JsonParser objectMapper = JsonParserFactory.create(); return objectMapper.parseMap(jwt.getClaims()).get("credentials").toString(); }
迁移时尝试使用新导入但无法找到JwtHelper和JsonParserFactory的替代类,以下是完整迁移方案:
迁移步骤
1. 替换依赖(移除旧依赖,添加新依赖)
Spring Security 6已弃用原有的spring-security-jwt和spring-security-oauth2模块,改用官方整合的OAuth2资源服务器依赖。如果使用Spring Boot,直接引入以下starter即可:
Gradle 配置
implementation 'org.springframework.boot:spring-boot-starter-security' implementation 'org.springframework.boot:spring-boot-starter-oauth2-resource-server'
Maven 配置
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-resource-server</artifactId> </dependency>
2. 修改代码实现
Spring Security 6提供了JwtDecoder接口处理JWT解析,且Jwt对象已内置claims解析能力,无需额外JSON解析工具。
场景1:保持原行为(仅解码JWT,不验证签名)
适合开发测试场景,生产环境不建议使用:
import org.springframework.security.oauth2.jwt.Jwt; import org.springframework.security.oauth2.jwt.JwtDecoder; import org.springframework.security.oauth2.jwt.NimbusJwtDecoder; import com.nimbusds.jose.proc.SecurityContext; private JwtDecoder createUnvalidatingJwtDecoder() { // 创建不验证签名的解码器,与原JwtHelper.decode行为一致 return NimbusJwtDecoder.withJwtProcessor((jwt, context) -> jwt).build(); } private String extractCredentials(String accessTokenCookieValue) { JwtDecoder decoder = createUnvalidatingJwtDecoder(); Jwt jwt = decoder.decode(accessTokenCookieValue); // 直接从Jwt对象获取指定claim return jwt.getClaim("credentials").toString(); }
场景2:生产环境(启用JWT签名验证)
以对称密钥验证为例(根据实际签名算法调整):
import org.springframework.security.oauth2.jwt.Jwt; import org.springframework.security.oauth2.jwt.JwtDecoder; import org.springframework.security.oauth2.jwt.NimbusJwtDecoder; import javax.crypto.spec.SecretKeySpec; private JwtDecoder createValidatingJwtDecoder() { // 替换为实际的签名密钥,算法需与JWT生成时一致(如HS256) String secretKey = "your-actual-signing-secret"; SecretKeySpec secret = new SecretKeySpec(secretKey.getBytes(), "HS256"); return NimbusJwtDecoder.withSecretKey(secret).build(); } private String extractCredentials(String accessTokenCookieValue) { JwtDecoder decoder = createValidatingJwtDecoder(); Jwt jwt = decoder.decode(accessTokenCookieValue); return jwt.getClaim("credentials").toString(); }
关键说明
- 移除旧的导入类:
org.springframework.security.jwt.Jwt、JwtHelper、JsonParser、JsonParserFactory - 新的
Jwt类直接提供getClaim()方法获取声明,无需手动解析JSON - 生产环境必须启用签名验证,避免伪造JWT带来的安全风险
内容的提问来源于stack exchange,提问作者Peter Penzov
相关产品推荐
相关产品推荐

