You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何禁用设备授权许可相关端点及移除OIDC配置中对应授权类型?

禁用设备授权许可及移除对应Grant Type的方法

Spring Security OAuth2(Spring Boot)场景

如果你的服务基于Spring Security OAuth2 Authorization Server,直接通过自定义配置就能搞定:

  • 写个SecurityFilterChain Bean,配置授权服务器时禁用设备授权端点,同时指定允许的Grant Type:
    @Bean
    public SecurityFilterChain authorizationServerSecurityFilterChain(HttpSecurity http) throws Exception {
        OAuth2AuthorizationServerConfigurer authServerConfig = new OAuth2AuthorizationServerConfigurer();
        
        // 关掉设备授权端点
        authServerConfig.deviceAuthorizationEndpoint(c -> c.disable());
        
        // 配置支持的Grant Type,排除设备授权的类型
        authServerConfig.oidc(Customizer.withDefaults())
            .providerSettings(settings -> 
                settings.grantTypesSupported(Set.of("authorization_code", "refresh_token"))
            );
        
        return http.apply(authServerConfig).and().build();
    }
    
    这样一来,设备授权的端点会被禁用,同时/.well-known/openid-configuration里的grant_types_supported也会自动剔除对应的项。

Keycloak场景

Keycloak的操作更直观,直接在控制台配置:

  • 进入目标Realm的Clients页面,找到你要配置的客户端(或者全局设置)
  • 切换到Capability Config标签,取消勾选Device Authorization Grant
  • 保存后,Keycloak会自动处理端点禁用和配置文档的更新。

自研/小众框架通用方案

如果是自己搭的服务或者用的小众框架没现成配置:

  • 先从路由里删掉设备授权相关的端点(比如/oauth2/device_authorization),同时在/oauth2/token的处理逻辑里拒绝device_code类型的请求
  • 生成/.well-known/openid-configuration响应时,手动把urn:ietf:params:oauth:grant-type:device_code从grant_types_supported数组里拿掉

要是用的是Auth0这类托管身份服务,直接去控制台的授权设置里找设备授权的开关关掉就行,大多平台都有可视化配置项。

内容的提问来源于stack exchange,提问作者larsw

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 05:52:41