Spring OAuth2授权服务器注销成功后JWT仍可被校验/获取用户信息
问题:注销操作后access_token仍显示active: true
我已成功完成认证并获取access_token、refresh_token和id_token,测试过程如下:
- 生成
access_token后,调用userinfo或introspect接口,返回active: true; - 使用
refresh_token获取新access_token后,用旧access_token调用/introspect接口返回active: false; - 使用
id_token完成注销并成功跳转到post_logout_redirect_uri,但调用/introspect接口仍返回active: true及完整令牌信息。
第2点说明旧access_token在刷新后会失效,我预期注销操作同样会将令牌置为active: false,但实际并未生效。
以下是我的配置文件:
private final KeyManager keyManager; private final DataSource dataSource; private final CustomAuthenticationProvider customAuthenticationProvider; @Bean SecurityFilterChain oauthSecurityFilterChain(HttpSecurity httpSecurity) throws Exception { OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(httpSecurity); httpSecurity .getConfigurer(OAuth2AuthorizationServerConfigurer.class).oidc( customizer -> customizer.clientRegistrationEndpoint( clientRegistrationEndpoint -> clientRegistrationEndpoint.authenticationProviders(CustomClientMetadataConfig.configureCustomClientMetadataConverters()) ) ) .registeredClientRepository(jdbcRegisteredClientRepository()); httpSecurity .formLogin(Customizer.withDefaults()) .oauth2ResourceServer(oauth2ResourceServer -> oauth2ResourceServer.jwt(Customizer.withDefaults())); return httpSecurity.build(); } @Bean JWKSource<SecurityContext> jwkSource() { ... } @Bean JdbcTemplate jdbcTemplate() { ... } @Bean JdbcRegisteredClientRepository jdbcRegisteredClientRepository() { ... } @Bean RegisteredClient registeredClientRepository() { ... } @Bean SecurityFilterChain securityFilterChain(HttpSecurity httpSecurity) throws Exception { httpSecurity .csrf(customizer -> customizer.disable()) .authorizeHttpRequests(authorize -> authorize .requestMatchers("/api-docs","/api-docs/*", "/swagger-ui/*").permitAll() .anyRequest().authenticated() ) .formLogin(customizer -> Customizer.withDefaults()) .logout(customizer -> Customizer.withDefaults()) .authenticationProvider(customAuthenticationProvider); return httpSecurity.build(); } @Bean PasswordEncoder passwordEncoder() { ... } @Bean OAuth2TokenCustomizer<JwtEncodingContext> jwtTokenCustomizer() { ... }
使用的依赖版本:
- spring-boot-starter-security: 3.2.2
- spring-security-oauth2-authorization-server: 1.2.1
- spring-security-cas: 6.2.1
内容的提问来源于stack exchange,提问作者ridhopratama
相关产品推荐
相关产品推荐

