You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring OAuth2授权服务器注销成功后JWT仍可被校验/获取用户信息

问题:注销操作后access_token仍显示active: true

我已成功完成认证并获取access_token、refresh_token和id_token,测试过程如下:

  • 生成access_token后,调用userinfo或introspect接口,返回active: true;
  • 使用refresh_token获取新access_token后,用旧access_token调用/introspect接口返回active: false;
  • 使用id_token完成注销并成功跳转到post_logout_redirect_uri,但调用/introspect接口仍返回active: true及完整令牌信息。

第2点说明旧access_token在刷新后会失效,我预期注销操作同样会将令牌置为active: false,但实际并未生效。

以下是我的配置文件:

private final KeyManager keyManager;
private final DataSource dataSource;
private final CustomAuthenticationProvider customAuthenticationProvider;

@Bean
SecurityFilterChain oauthSecurityFilterChain(HttpSecurity httpSecurity) throws Exception {
    OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(httpSecurity);
    httpSecurity
        .getConfigurer(OAuth2AuthorizationServerConfigurer.class).oidc(
            customizer -> customizer.clientRegistrationEndpoint(
                clientRegistrationEndpoint -> clientRegistrationEndpoint.authenticationProviders(CustomClientMetadataConfig.configureCustomClientMetadataConverters())
            )
        )
        .registeredClientRepository(jdbcRegisteredClientRepository());

    httpSecurity
        .formLogin(Customizer.withDefaults())
        .oauth2ResourceServer(oauth2ResourceServer -> oauth2ResourceServer.jwt(Customizer.withDefaults()));
    return httpSecurity.build();
}

@Bean
JWKSource<SecurityContext> jwkSource() {
    ...
}

@Bean
JdbcTemplate jdbcTemplate() {
    ...
}

@Bean
JdbcRegisteredClientRepository jdbcRegisteredClientRepository() {
    ...
}

@Bean
RegisteredClient registeredClientRepository() {
    ...
}

@Bean
SecurityFilterChain securityFilterChain(HttpSecurity httpSecurity) throws Exception {
    httpSecurity
        .csrf(customizer -> customizer.disable())
        .authorizeHttpRequests(authorize -> 
            authorize
                .requestMatchers("/api-docs","/api-docs/*", "/swagger-ui/*").permitAll()
                .anyRequest().authenticated()
        )
        .formLogin(customizer -> Customizer.withDefaults())
        .logout(customizer -> Customizer.withDefaults())
        .authenticationProvider(customAuthenticationProvider);

    return httpSecurity.build();
}

@Bean
PasswordEncoder passwordEncoder() {
    ...
}

@Bean
OAuth2TokenCustomizer<JwtEncodingContext> jwtTokenCustomizer() { 
    ...
}

使用的依赖版本:

  • spring-boot-starter-security: 3.2.2
  • spring-security-oauth2-authorization-server: 1.2.1
  • spring-security-cas: 6.2.1

内容的提问来源于stack exchange,提问作者ridhopratama

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 03:57:21