基于Spring Authorization Server实现Opaque Token数据库存储与验证
1. 引入依赖
在pom.xml(Maven)或对应Gradle配置中添加核心依赖:
<!-- OAuth2授权服务器核心依赖 --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-authorization-server</artifactId> </dependency> <!-- Spring Data JPA用于数据库操作 --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <!-- 数据库驱动(以MySQL为例) --> <dependency> <groupId>com.mysql</groupId> <artifactId>mysql-connector-j</artifactId> <scope>runtime</scope> </dependency>
2. 配置数据库连接
在application.yml中配置数据库连接参数:
spring: datasource: url: jdbc:mysql://localhost:3306/oauth2_db?useSSL=false&serverTimezone=UTC username: root password: your_db_password jpa: hibernate: ddl-auto: update # 首次运行可设为create,生产环境建议改为none show-sql: true database-platform: org.hibernate.dialect.MySQL8Dialect
3. 初始化OAuth2数据库表
执行以下SQL创建授权服务器所需的核心表(MySQL为例):
-- 存储授权凭证(含access token、refresh token、authorization code) CREATE TABLE oauth2_authorization ( id VARCHAR(100) NOT NULL PRIMARY KEY, registered_client_id VARCHAR(100) NOT NULL, principal_name VARCHAR(200) NOT NULL, authorization_grant_type VARCHAR(100) NOT NULL, authorized_scopes VARCHAR(1000) DEFAULT NULL, attributes TEXT DEFAULT NULL, state VARCHAR(500) DEFAULT NULL, authorization_code_value TEXT DEFAULT NULL, authorization_code_issued_at TIMESTAMP DEFAULT NULL, authorization_code_expires_at TIMESTAMP DEFAULT NULL, access_token_value TEXT DEFAULT NULL, access_token_issued_at TIMESTAMP DEFAULT NULL, access_token_expires_at TIMESTAMP DEFAULT NULL, access_token_type VARCHAR(100) DEFAULT NULL, refresh_token_value TEXT DEFAULT NULL, refresh_token_issued_at TIMESTAMP DEFAULT NULL, refresh_token_expires_at TIMESTAMP DEFAULT NULL, FOREIGN KEY (registered_client_id) REFERENCES oauth2_client(id) ); -- 存储客户端授权同意记录 CREATE TABLE oauth2_authorization_consent ( registered_client_id VARCHAR(100) NOT NULL, principal_name VARCHAR(200) NOT NULL, authorities VARCHAR(1000) NOT NULL, PRIMARY KEY (registered_client_id, principal_name) ); -- 若未实现客户端数据库存储,可使用此表(已实现则忽略) CREATE TABLE oauth2_client ( id VARCHAR(100) NOT NULL PRIMARY KEY, client_id VARCHAR(100) NOT NULL, client_secret VARCHAR(200) DEFAULT NULL, client_name VARCHAR(200) NOT NULL, authorization_grant_types VARCHAR(1000) NOT NULL, redirect_uris VARCHAR(1000) DEFAULT NULL, scopes VARCHAR(1000) NOT NULL );
4. 替换默认内存存储为JDBC存储
创建授权服务器配置类,注册JDBC实现的存储Bean,覆盖默认内存存储:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.oauth2.server.authorization.JdbcOAuth2AuthorizationConsentService; import org.springframework.security.oauth2.server.authorization.JdbcOAuth2AuthorizationService; import org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationConsentService; import org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService; import org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository; import javax.sql.DataSource; @Configuration public class OAuth2AuthorizationServerConfig { // 若你已自定义RegisteredClientRepository(动态从数据库取客户端),直接注入你的Bean即可 @Bean public OAuth2AuthorizationService authorizationService(DataSource dataSource, RegisteredClientRepository registeredClientRepository) { return new JdbcOAuth2AuthorizationService(dataSource, registeredClientRepository); } @Bean public OAuth2AuthorizationConsentService authorizationConsentService(DataSource dataSource, RegisteredClientRepository registeredClientRepository) { return new JdbcOAuth2AuthorizationConsentService(dataSource, registeredClientRepository); } }
5. 凭证验证自动生效
完成配置后,授权服务器会自动完成以下操作:
- 生成authorization code、access token、refresh token时,自动写入
oauth2_authorization表 - 处理token校验(如refresh token刷新、资源服务器调用 introspect 接口)时,自动从数据库查询凭证信息验证合法性
注意事项
- 若自定义了
RegisteredClientRepository,确保在配置上述Bean时传入你的自定义实现 - 生产环境建议关闭JPA的
ddl-auto,手动维护数据库表结构 - 如需自定义token序列化逻辑,可通过扩展
JdbcOAuth2AuthorizationService的AuthorizationRowMapper实现
内容的提问来源于stack exchange,提问作者NewbSS
相关产品推荐
相关产品推荐

