Spring OAuth2访问令牌过期时未自动使用Refresh Token问题求助
Spring OAuth2 access token过期时未使用refresh token刷新的问题
环境配置
参考《Spring Boot集成Keycloak》教程搭建环境,Keycloak运行在localhost:8090,Spring Security配置如下:
// 此处保留原Java代码
因Keycloak未正确设置跨域头,自定义了授权重定向策略,将默认302改为2xx状态码并返回Location头,前端通过window.location跳转;自定义登出逻辑类似。
application.yml配置如下:
# 此处保留原YAML代码
问题现象
正常请求受保护资源时,跳转授权流程正常,登出功能也可正常销毁会话。但将Keycloak access token有效期设为10秒、Spring会话有效期设为15秒后,access token过期时,系统会重新触发完整授权流程(无需用户登录),Keycloak生成新access token,但未使用refresh token刷新。
调试发现:
- authorization_code授权正确返回access token和refresh token,但
RefreshTokenOAuth2AuthorizedClientProvider#authorize及DefaultRefreshTokenTokenResponseClient#getTokenResponse从未被调用; OAuth2LoginAuthenticationFilter#attemptAuthentication调用了saveAuthorizedClient保存令牌,但后续OAuth2AuthorizedClientRepository#loadAuthorizedClient从未触发加载refresh token。
恳请各位提供排查思路或解决方案,感谢支持!
内容的提问来源于stack exchange,提问作者grange
相关产品推荐
相关产品推荐

