You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Spring Authorization Server实现Opaque Token数据库存储与验证

基于spring-boot-starter-oauth2-authorization-server实现凭证数据库存储与验证

1. 引入依赖

在pom.xml(Maven)或对应Gradle配置中添加核心依赖:

<!-- OAuth2授权服务器核心依赖 -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-oauth2-authorization-server</artifactId>
</dependency>
<!-- Spring Data JPA用于数据库操作 -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-data-jpa</artifactId>
</dependency>
<!-- 数据库驱动(以MySQL为例) -->
<dependency>
    <groupId>com.mysql</groupId>
    <artifactId>mysql-connector-j</artifactId>
    <scope>runtime</scope>
</dependency>

2. 配置数据库连接

在application.yml中配置数据库连接参数:

spring:
  datasource:
    url: jdbc:mysql://localhost:3306/oauth2_db?useSSL=false&serverTimezone=UTC
    username: root
    password: your_db_password
  jpa:
    hibernate:
      ddl-auto: update # 首次运行可设为create,生产环境建议改为none
    show-sql: true
    database-platform: org.hibernate.dialect.MySQL8Dialect

3. 初始化OAuth2数据库表

执行以下SQL创建授权服务器所需的核心表(MySQL为例):

-- 存储授权凭证(含access token、refresh token、authorization code)
CREATE TABLE oauth2_authorization (
    id VARCHAR(100) NOT NULL PRIMARY KEY,
    registered_client_id VARCHAR(100) NOT NULL,
    principal_name VARCHAR(200) NOT NULL,
    authorization_grant_type VARCHAR(100) NOT NULL,
    authorized_scopes VARCHAR(1000) DEFAULT NULL,
    attributes TEXT DEFAULT NULL,
    state VARCHAR(500) DEFAULT NULL,
    authorization_code_value TEXT DEFAULT NULL,
    authorization_code_issued_at TIMESTAMP DEFAULT NULL,
    authorization_code_expires_at TIMESTAMP DEFAULT NULL,
    access_token_value TEXT DEFAULT NULL,
    access_token_issued_at TIMESTAMP DEFAULT NULL,
    access_token_expires_at TIMESTAMP DEFAULT NULL,
    access_token_type VARCHAR(100) DEFAULT NULL,
    refresh_token_value TEXT DEFAULT NULL,
    refresh_token_issued_at TIMESTAMP DEFAULT NULL,
    refresh_token_expires_at TIMESTAMP DEFAULT NULL,
    FOREIGN KEY (registered_client_id) REFERENCES oauth2_client(id)
);

-- 存储客户端授权同意记录
CREATE TABLE oauth2_authorization_consent (
    registered_client_id VARCHAR(100) NOT NULL,
    principal_name VARCHAR(200) NOT NULL,
    authorities VARCHAR(1000) NOT NULL,
    PRIMARY KEY (registered_client_id, principal_name)
);

-- 若未实现客户端数据库存储,可使用此表(已实现则忽略)
CREATE TABLE oauth2_client (
    id VARCHAR(100) NOT NULL PRIMARY KEY,
    client_id VARCHAR(100) NOT NULL,
    client_secret VARCHAR(200) DEFAULT NULL,
    client_name VARCHAR(200) NOT NULL,
    authorization_grant_types VARCHAR(1000) NOT NULL,
    redirect_uris VARCHAR(1000) DEFAULT NULL,
    scopes VARCHAR(1000) NOT NULL
);

4. 替换默认内存存储为JDBC存储

创建授权服务器配置类,注册JDBC实现的存储Bean,覆盖默认内存存储:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.oauth2.server.authorization.JdbcOAuth2AuthorizationConsentService;
import org.springframework.security.oauth2.server.authorization.JdbcOAuth2AuthorizationService;
import org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationConsentService;
import org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService;
import org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository;

import javax.sql.DataSource;

@Configuration
public class OAuth2AuthorizationServerConfig {

    // 若你已自定义RegisteredClientRepository(动态从数据库取客户端),直接注入你的Bean即可
    @Bean
    public OAuth2AuthorizationService authorizationService(DataSource dataSource, RegisteredClientRepository registeredClientRepository) {
        return new JdbcOAuth2AuthorizationService(dataSource, registeredClientRepository);
    }

    @Bean
    public OAuth2AuthorizationConsentService authorizationConsentService(DataSource dataSource, RegisteredClientRepository registeredClientRepository) {
        return new JdbcOAuth2AuthorizationConsentService(dataSource, registeredClientRepository);
    }
}

5. 凭证验证自动生效

完成配置后,授权服务器会自动完成以下操作:

  • 生成authorization code、access token、refresh token时,自动写入oauth2_authorization表
  • 处理token校验(如refresh token刷新、资源服务器调用 introspect 接口)时,自动从数据库查询凭证信息验证合法性

注意事项

  • 若自定义了RegisteredClientRepository,确保在配置上述Bean时传入你的自定义实现
  • 生产环境建议关闭JPA的ddl-auto,手动维护数据库表结构
  • 如需自定义token序列化逻辑,可通过扩展JdbcOAuth2AuthorizationService的AuthorizationRowMapper实现

内容的提问来源于stack exchange,提问作者NewbSS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 23:43:20