You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot OAuth2授权码流配置:解决user-info-uri缺失报错(禁用OIDC)

问题:Spring Boot OAuth2授权码流配置报错(缺失user-info-uri)

我有一个使用Thymeleaf作为模板引擎的Spring Boot应用,需要按照OAuth 2.0 RFC 6749规范,通过**授权码流(Authorization Code Flow)**保护客户端应用。但遇到报错:

[missing_user_info_uri] Missing required UserInfo Uri in UserInfoEndpoint for Client Registration: custom 

Spring框架要求配置user-info-uri,但该参数并未在RFC 6749中定义。

我的配置如下:

application.yml配置

security:
 oauth2:
  client:
    registration:
      custom:
        client-id: <my-client-id>
        client-secret: asdasd
        authorization-grant-type: authorization_code
        redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
        scope: email
        client-authentication-method: client_secret_post
    provider:
      custom:
          authorization-uri: <my-auth-url>
          token-uri: <my-token-url>

安全过滤器链配置

public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
    http
        .authorizeHttpRequests(authorize -> authorize
            .anyRequest().authenticated()
        )
        .oauth2Login(Customizer.withDefaults()).oauth2Client(Customizer.withDefaults());
    return http.build();
}

依赖配置

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-oauth2-client</artifactId>
</dependency>

授权服务器为自定义实现,且已通过Postman验证可用。多方文档内容不一致,查阅困难,请问如何配置才能仅支持OAuth2而非OpenID Connect?


解决方案

报错核心原因:默认的oauth2Login配置会按**OpenID Connect(OIDC)**流程处理认证,OIDC要求获取用户信息,因此需要user-info-uri。但我们仅需纯OAuth2授权码流,无需OIDC的用户信息获取步骤,需自定义配置跳过该环节。

1. 自定义OAuth2用户认证转换器

创建OAuth2UserService实现,跳过用户信息请求,直接基于访问令牌构建认证用户:

import org.springframework.security.core.authority.SimpleGrantedAuthority;
import org.springframework.security.oauth2.client.userinfo.DefaultOAuth2UserService;
import org.springframework.security.oauth2.client.userinfo.OAuth2UserRequest;
import org.springframework.security.oauth2.core.OAuth2AuthenticationException;
import org.springframework.security.oauth2.core.user.DefaultOAuth2User;
import org.springframework.security.oauth2.core.user.OAuth2User;
import java.util.Collections;

public class CustomOAuth2UserService extends DefaultOAuth2UserService {
    @Override
    public OAuth2User loadUser(OAuth2UserRequest userRequest) throws OAuth2AuthenticationException {
        // 跳过调用user-info-uri,直接创建OAuth2User对象
        return new DefaultOAuth2User(
                Collections.singletonList(new SimpleGrantedAuthority("ROLE_USER")),
                Collections.emptyMap(),
                "sub" // 字段名可随意填写,因无需实际用户信息返回
        );
    }
}

2. 修改安全过滤器链配置

在filterChain中配置自定义的OAuth2UserService,禁用OIDC的用户信息端点自动处理:

import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.oauth2.client.userinfo.OAuth2UserService;
import org.springframework.security.web.SecurityFilterChain;

@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(authorize -> authorize
                .anyRequest().authenticated()
            )
            .oauth2Login(oauth2 -> oauth2
                .userInfoEndpoint(userInfo -> userInfo
                    .userService(customOAuth2UserService())
                )
            )
            .oauth2Client(Customizer.withDefaults());
        return http.build();
    }

    @Bean
    public OAuth2UserService customOAuth2UserService() {
        return new CustomOAuth2UserService();
    }
}

3. 可选:补充provider配置

若无需OIDC其他端点,可保持原provider配置不变,自定义UserService已跳过用户信息请求,无需额外配置无效URL。


内容的提问来源于stack exchange,提问作者Bioaim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 20:11:29