Spring Boot OAuth2授权码流配置:解决user-info-uri缺失报错(禁用OIDC)
问题:Spring Boot OAuth2授权码流配置报错(缺失user-info-uri)
我有一个使用Thymeleaf作为模板引擎的Spring Boot应用,需要按照OAuth 2.0 RFC 6749规范,通过**授权码流(Authorization Code Flow)**保护客户端应用。但遇到报错:
[missing_user_info_uri] Missing required UserInfo Uri in UserInfoEndpoint for Client Registration: custom
Spring框架要求配置user-info-uri,但该参数并未在RFC 6749中定义。
我的配置如下:
application.yml配置
security: oauth2: client: registration: custom: client-id: <my-client-id> client-secret: asdasd authorization-grant-type: authorization_code redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}" scope: email client-authentication-method: client_secret_post provider: custom: authorization-uri: <my-auth-url> token-uri: <my-token-url>
安全过滤器链配置
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(authorize -> authorize .anyRequest().authenticated() ) .oauth2Login(Customizer.withDefaults()).oauth2Client(Customizer.withDefaults()); return http.build(); }
依赖配置
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency>
授权服务器为自定义实现,且已通过Postman验证可用。多方文档内容不一致,查阅困难,请问如何配置才能仅支持OAuth2而非OpenID Connect?
解决方案
报错核心原因:默认的oauth2Login配置会按**OpenID Connect(OIDC)**流程处理认证,OIDC要求获取用户信息,因此需要user-info-uri。但我们仅需纯OAuth2授权码流,无需OIDC的用户信息获取步骤,需自定义配置跳过该环节。
1. 自定义OAuth2用户认证转换器
创建OAuth2UserService实现,跳过用户信息请求,直接基于访问令牌构建认证用户:
import org.springframework.security.core.authority.SimpleGrantedAuthority; import org.springframework.security.oauth2.client.userinfo.DefaultOAuth2UserService; import org.springframework.security.oauth2.client.userinfo.OAuth2UserRequest; import org.springframework.security.oauth2.core.OAuth2AuthenticationException; import org.springframework.security.oauth2.core.user.DefaultOAuth2User; import org.springframework.security.oauth2.core.user.OAuth2User; import java.util.Collections; public class CustomOAuth2UserService extends DefaultOAuth2UserService { @Override public OAuth2User loadUser(OAuth2UserRequest userRequest) throws OAuth2AuthenticationException { // 跳过调用user-info-uri,直接创建OAuth2User对象 return new DefaultOAuth2User( Collections.singletonList(new SimpleGrantedAuthority("ROLE_USER")), Collections.emptyMap(), "sub" // 字段名可随意填写,因无需实际用户信息返回 ); } }
2. 修改安全过滤器链配置
在filterChain中配置自定义的OAuth2UserService,禁用OIDC的用户信息端点自动处理:
import org.springframework.context.annotation.Bean; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.oauth2.client.userinfo.OAuth2UserService; import org.springframework.security.web.SecurityFilterChain; @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(authorize -> authorize .anyRequest().authenticated() ) .oauth2Login(oauth2 -> oauth2 .userInfoEndpoint(userInfo -> userInfo .userService(customOAuth2UserService()) ) ) .oauth2Client(Customizer.withDefaults()); return http.build(); } @Bean public OAuth2UserService customOAuth2UserService() { return new CustomOAuth2UserService(); } }
3. 可选:补充provider配置
若无需OIDC其他端点,可保持原provider配置不变,自定义UserService已跳过用户信息请求,无需额外配置无效URL。
内容的提问来源于stack exchange,提问作者Bioaim
相关产品推荐
相关产品推荐

