Spring Security问题:访问.well-known/openid-configuration返回403
解决OIDC发现端点403禁止访问问题
你需要在Security配置的requestMatchers中添加OIDC发现端点的路径/.well-known/openid-configuration,将其设置为允许匿名访问——该端点属于OAuth2授权服务器的公开端点,无需认证即可访问。
修改后的Security配置代码如下:
@EnableWebSecurity @Configuration public class SecurityConfiguration { @Bean SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception { return http .csrf(csrfCustomizer -> csrfCustomizer.disable()) .authorizeHttpRequests( authorize -> authorize .requestMatchers( EndpointRequest.to(InfoEndpoint.class, HealthEndpoint.class, EnvironmentEndpoint.class, ConfigurationPropertiesReportEndpoint.class)) .permitAll() // 允许OIDC发现端点公开访问 .requestMatchers("/.well-known/openid-configuration").permitAll() .anyRequest().authenticated()) .formLogin(cr -> cr.disable()) .build(); } }
补充说明
如果后续需要开放其他OAuth2授权服务器的公开端点(比如授权端点/oauth2/authorize、令牌端点/oauth2/token等),也可以按照同样的方式添加到requestMatchers并设置permitAll。
内容的提问来源于stack exchange,提问作者Jordi
相关产品推荐
相关产品推荐

