You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JHipster v8.1.0如何通过Cookie实现请求认证?

在JHipster v8.1.0中实现Cookie解析JWT认证

JHipster v8基于Spring Security 6重构了认证流程,原7.x版本中的JWTFilter已被整合到Spring Security的OAuth2资源服务器组件中。要实现从Cookie解析JWT的逻辑,你可以通过以下两种方式完成:

方式一:自定义BearerTokenResolver

BearerTokenResolver负责从请求中提取Token,我们可以实现该接口同时支持Header和Cookie两种来源:

import jakarta.servlet.http.Cookie;
import jakarta.servlet.http.HttpServletRequest;
import org.springframework.security.oauth2.server.resource.web.BearerTokenResolver;
import org.springframework.util.StringUtils;
import org.springframework.web.util.WebUtils;

public class CookieAwareBearerTokenResolver implements BearerTokenResolver {
    // 替换为你实际使用的Header和Cookie名称
    private static final String AUTHORIZATION_HEADER = "Authorization";
    private static final String AUTHORIZATION_COOKIE = "JWT_AUTH";

    @Override
    public String resolve(HttpServletRequest request) {
        // 优先从请求头提取Token
        String token = resolveFromHeader(request);
        if (token == null) {
            // 头中无Token则从Cookie提取
            token = resolveFromCookie(request);
        }
        return token;
    }

    private String resolveFromHeader(HttpServletRequest request) {
        String bearerToken = request.getHeader(AUTHORIZATION_HEADER);
        if (StringUtils.hasText(bearerToken) && bearerToken.startsWith("Bearer ")) {
            return bearerToken.substring(7);
        }
        return null;
    }

    private String resolveFromCookie(HttpServletRequest request) {
        Cookie authCookie = WebUtils.getCookie(request, AUTHORIZATION_COOKIE);
        if (authCookie != null && StringUtils.hasText(authCookie.getValue())) {
            return authCookie.getValue();
        }
        return null;
    }
}

然后在Security配置类中替换默认的Resolver:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
public class SecurityConfiguration {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // 保留你原有的其他配置(如CSRF、权限规则等)
            .oauth2ResourceServer(oauth2 -> oauth2
                .bearerTokenResolver(new CookieAwareBearerTokenResolver())
                .jwt(jwt -> jwt
                    // 配置JWT验证逻辑(如签名密钥、转换器等)
                )
            );
        return http.build();
    }
}

方式二:自定义AuthenticationConverter

如果需要更灵活的认证对象转换逻辑,可以实现AuthenticationConverter接口:

import jakarta.servlet.http.Cookie;
import jakarta.servlet.http.HttpServletRequest;
import org.springframework.security.core.Authentication;
import org.springframework.security.oauth2.jwt.Jwt;
import org.springframework.security.oauth2.jwt.JwtAuthenticationToken;
import org.springframework.security.web.authentication.AuthenticationConverter;
import org.springframework.util.StringUtils;
import org.springframework.web.util.WebUtils;

public class CookieAndHeaderJwtAuthenticationConverter implements AuthenticationConverter {
    private static final String AUTHORIZATION_HEADER = "Authorization";
    private static final String AUTHORIZATION_COOKIE = "JWT_AUTH";

    @Override
    public Authentication convert(HttpServletRequest request) {
        String token = resolveToken(request);
        if (token == null) {
            return null;
        }
        // 生成JWT认证Token,可根据需求扩展自定义逻辑
        Jwt jwt = Jwt.withTokenValue(token).build();
        return new JwtAuthenticationToken(jwt);
    }

    private String resolveToken(HttpServletRequest request) {
        String bearerToken = request.getHeader(AUTHORIZATION_HEADER);
        if (StringUtils.hasText(bearerToken) && bearerToken.startsWith("Bearer ")) {
            return bearerToken.substring(7);
        }
        Cookie authCookie = WebUtils.getCookie(request, AUTHORIZATION_COOKIE);
        if (authCookie != null && StringUtils.hasText(authCookie.getValue())) {
            return authCookie.getValue();
        }
        return null;
    }
}

在Security配置中配置该Converter:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.authentication.AuthenticationConverter;

@Configuration
public class SecurityConfiguration {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwt -> jwt
                    .jwtAuthenticationConverter(cookieAndHeaderJwtAuthenticationConverter())
                )
            );
        return http.build();
    }

    @Bean
    public AuthenticationConverter cookieAndHeaderJwtAuthenticationConverter() {
        return new CookieAndHeaderJwtAuthenticationConverter();
    }
}

注意事项

  1. 替换代码中AUTHORIZATION_COOKIE的值为你实际使用的Cookie名称;
  2. 如果是JHipster生成的项目,默认已有SecurityConfiguration类,直接修改其中的oauth2ResourceServer配置即可;
  3. 确保JWT的验证逻辑(如签名密钥、过期时间校验等)已正确配置,可沿用JHipster默认的JWT配置。

内容的提问来源于stack exchange,提问作者Soroush Shemshadi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 22:50:19