You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring OAuth2访问令牌过期时未自动使用Refresh Token问题求助

Spring OAuth2 access token过期时未使用refresh token刷新的问题

环境配置

参考《Spring Boot集成Keycloak》教程搭建环境,Keycloak运行在localhost:8090,Spring Security配置如下:

// 此处保留原Java代码

因Keycloak未正确设置跨域头,自定义了授权重定向策略,将默认302改为2xx状态码并返回Location头,前端通过window.location跳转;自定义登出逻辑类似。

application.yml配置如下:

# 此处保留原YAML代码

问题现象

正常请求受保护资源时,跳转授权流程正常,登出功能也可正常销毁会话。但将Keycloak access token有效期设为10秒、Spring会话有效期设为15秒后,access token过期时,系统会重新触发完整授权流程(无需用户登录),Keycloak生成新access token,但未使用refresh token刷新。

调试发现:

  • authorization_code授权正确返回access token和refresh token,但RefreshTokenOAuth2AuthorizedClientProvider#authorize及DefaultRefreshTokenTokenResponseClient#getTokenResponse从未被调用;
  • OAuth2LoginAuthenticationFilter#attemptAuthentication调用了saveAuthorizedClient保存令牌,但后续OAuth2AuthorizedClientRepository#loadAuthorizedClient从未触发加载refresh token。

恳请各位提供排查思路或解决方案,感谢支持!

内容的提问来源于stack exchange,提问作者grange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 23:40:56