Spring Boot3.2升级后WebClient OAuth2令牌复用失败重复认证问题
问题:Spring Boot 3.2迁移后WebClient无法复用Salesforce OAuth2令牌
环境信息
- Spring Boot 3.2
- Spring Security 6
- Java 21
- 应用类型:代理服务,需调用Salesforce API
问题描述
从Spring Boot 2.6迁移到3.2后,替换弃用的RestTemplate为WebClient,出现以下异常:
- 每次调用Salesforce API都会触发多次认证,无法复用未过期的access token,仅在token过期时才会刷新
- 日志显示请求处于
AnonymousUser状态,认证信息未被存储
验证信息
Salesforce令牌接口无问题,用Postman可正常获取token:
请求
curl -X POST -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=client_credentials&client_id=secret-placeholder&client_secret=secret-placeholder" \ "https://my.salesforce.com/services/oauth2/token"
响应
{"access_token":"{TOKEN_VALUE}","signature":"{SIGNATURE_VALUE}","scope":"api id","instance_url":"https://my.salesforce.com","id":"https://test.salesforce.com/id/{ID_VALUE}","token_type":"Bearer","issued_at":"{EPOCH_VALUE}"}
排查动作
已尝试使用AuthorizedClientServiceOAuth2AuthorizedClientManager解决HTTP会话上下文依赖问题,但未解决。
日志片段(permitAll()模式)
2024-01-29T15:59:11.615-08:00 INFO 53077 --- [crm-proxy] [oundedElastic-1] [ ] c.s.c.c.s.c.SalesforceWebClientFactory : Authorization successful for clientRegistrationId=salesforce, tokenUri=https://my.salesforce.com/services/oauth2/token 2024-01-29T15:59:12.610-08:00 DEBUG 53077 --- [crm-proxy] [nio-8080-exec-1] [65b83bcea50539ad048191ae13ee2d26-a244a0c27369d291] c.s.c.c.s.client.SalesforceClient : took 2096ms to successfully GET to 'https://my.salesforce.com/services/data/v52.0/query? 2024-01-29T15:59:12.615-08:00 DEBUG 53077 --- [crm-proxy] [nio-8080-exec-1] [65b83bcea50539ad048191ae13ee2d26-a244a0c27369d291] c.s.c.c.s.client.SalesforceClient : Security Context: SecurityContextImpl [Authentication=AnonymousAuthenticationToken [Principal=anonymousUser, Credentials=[PROTECTED], Authenticated=true, Details=WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=null], Granted Authorities=[ROLE_ANONYMOUS]]]
旧版本代码(Spring Boot 2.6)
@Component public class SalesforceOAuth2RestTemplateFactory { public RestOperations generateOAuth2RestTemplate(SalesforceProperties salesforceProperties) { ResourceOwnerPasswordResourceDetails resource = new ResourceOwnerPasswordResourceDetails(); resource.setAccessTokenUri(salesforceProperties.getAccessTokenUri()); resource.setClientId(salesforceProperties.getClientId()); resource.setAuthenticationScheme(AuthenticationScheme.header); resource.setClientAuthenticationScheme(AuthenticationScheme.form); resource.setClientSecret(salesforceProperties.getClientSecret()); resource.setGrantType("password"); resource.setUsername(salesforceProperties.getUsername()); resource.setPassword(salesforceProperties.getPassword()); OAuth2RestTemplate oAuth2RestTemplate = new OAuth2RestTemplate( resource, new DefaultOAuth2ClientContext(new DefaultAccessTokenRequest())); oAuth2RestTemplate.setRetryBadAccessTokens(true); oAuth2RestTemplate.setErrorHandler(new SalesforceOAuth2ErrorHandler(resource)); return oAuth2RestTemplate; } }
当前版本代码说明
激活环境:local,环境名:dev01,包含SalesforceWebClientFactory.java、SalesforceClient.java等文件。
内容的提问来源于stack exchange,提问作者masvg
相关产品推荐
相关产品推荐

