使用自定义Scope时Azure AD登录失败:用户信息响应无效
Azure AD切换自定义Scope后登录失败问题
原正常配置
以下Azure AD登录配置可正常运行:
security: oauth2: client: provider: azure-active-directory: issuer-uri: ${OAUTH2_ISSUER} registration: api-gateway: provider: azure-active-directory authorization-grant-type: authorization_code redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}" client-id: ${OAUTH2_CLIENT_ID} client-secret: ${OAUTH2_CLIENT_SECRET} scope: openid
问题触发操作
将配置中的scope替换为Azure AD中新建的自定义Scope:
scope: api://my-id-removed/jango-test-api
错误现象
- 登录后自动跳转至
login?error路由 - 应用日志显示用户信息端点读取异常:
2023-10-10T00:51:24.151+02:00 DEBUG 50489 --- [ctor-http-nio-7] athPatternParserServerWebExchangeMatcher : 检查请求匹配:'/login/oauth2/code/azure';匹配路径'/login/oauth2/code/{registrationId}' 2023-10-10T00:51:25.078+02:00 DEBUG 50489 --- [ctor-http-nio-6] o.s.s.w.s.a.AuthenticationWebFilter : 认证失败:[invalid_user_info_response] 读取UserInfo响应时发生错误:[invalid_user_info_response]
- 直接访问用户信息端点返回如下错误:
{ "error": { "code": "InvalidAuthenticationToken", "message": "访问令牌为空。", "innerError": { "date": "2023-10-09T22:58:11", "request-id": "7e7a3bc8-7fb5-4bdb-a648-bfd4bf6f2dc8", "client-request-id": "7e7a3bc8-7fb5-4bdb-a648-bfd4bf6f2dc8" } } }
内容的提问来源于stack exchange,提问作者user5228754
相关产品推荐
相关产品推荐

