You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security问题:访问.well-known/openid-configuration返回403

解决OIDC发现端点403禁止访问问题

你需要在Security配置的requestMatchers中添加OIDC发现端点的路径/.well-known/openid-configuration,将其设置为允许匿名访问——该端点属于OAuth2授权服务器的公开端点,无需认证即可访问。

修改后的Security配置代码如下:

@EnableWebSecurity
@Configuration
public class SecurityConfiguration {

  @Bean
  SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception {
    return http
        .csrf(csrfCustomizer -> csrfCustomizer.disable())
        .authorizeHttpRequests(
            authorize -> authorize
                .requestMatchers(
                    EndpointRequest.to(InfoEndpoint.class, HealthEndpoint.class, EnvironmentEndpoint.class,
                        ConfigurationPropertiesReportEndpoint.class))
                .permitAll()
                // 允许OIDC发现端点公开访问
                .requestMatchers("/.well-known/openid-configuration").permitAll()
                .anyRequest().authenticated())
        .formLogin(cr -> cr.disable())
        .build();
  }
}

补充说明

如果后续需要开放其他OAuth2授权服务器的公开端点(比如授权端点/oauth2/authorize、令牌端点/oauth2/token等),也可以按照同样的方式添加到requestMatchers并设置permitAll。

内容的提问来源于stack exchange,提问作者Jordi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 03:11:15