Spring Security OAuth2迁移至Spring Security 5+(Spring Boot 3.x)求助
Spring Boot 3.x 迁移 OAuth2 至 Spring Security 5.x+ 实用方案
一、核心依赖调整
- 移除旧的
spring-security-oauth2依赖,替换为Spring Security官方整合的OAuth2模块:<!-- Spring Security OAuth2 客户端 --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency> <!-- Spring Security OAuth2 资源服务器(如果是资源服务) --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-resource-server</artifactId> </dependency>
二、核心代码迁移示例
1. 客户端配置(替代原OAuth2ClientContext等旧类)
@Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .oauth2Login(oauth2 -> oauth2 .loginPage("/oauth2/authorization/custom-client") // 自定义登录页(可选) .userInfoEndpoint(userInfo -> userInfo .userService(customOAuth2UserService) // 自定义用户信息处理(可选) ) ) .oauth2Client(oauth2 -> oauth2 .clientRegistrationRepository(clientRegistrationRepository()) .authorizedClientService(authorizedClientService()) ); return http.build(); } // 客户端注册信息可通过application.yml配置,也可手动注入 @Bean public ClientRegistrationRepository clientRegistrationRepository() { return new InMemoryClientRegistrationRepository(customClientRegistration()); } private ClientRegistration customClientRegistration() { return ClientRegistration.withRegistrationId("custom-client") .clientId("your-client-id") .clientSecret("your-client-secret") .authorizationUri("https://auth-server.com/oauth2/authorize") .tokenUri("https://auth-server.com/oauth2/token") .userInfoUri("https://auth-server.com/oauth2/userinfo") .userNameAttributeName(IdTokenClaimNames.SUB) .redirectUri("{baseUrl}/login/oauth2/code/{registrationId}") .scope("read", "write") .authorizationGrantType(AuthorizationGrantType.AUTHORIZATION_CODE) .clientName("Custom Auth Server") .build(); } }
2. 资源服务器配置(替代原ResourceServerConfigurerAdapter)
@Configuration @EnableWebSecurity public class ResourceServerConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .oauth2ResourceServer(oauth2 -> oauth2 .jwt(jwt -> jwt .jwtAuthenticationConverter(jwtAuthenticationConverter()) // 自定义JWT转换(可选) ) ); return http.build(); } // 自定义JWT权限转换示例 private JwtAuthenticationConverter jwtAuthenticationConverter() { JwtGrantedAuthoritiesConverter grantedAuthoritiesConverter = new JwtGrantedAuthoritiesConverter(); grantedAuthoritiesConverter.setAuthorityPrefix("ROLE_"); grantedAuthoritiesConverter.setAuthoritiesClaimName("roles"); JwtAuthenticationConverter converter = new JwtAuthenticationConverter(); converter.setJwtGrantedAuthoritiesConverter(grantedAuthoritiesConverter); return converter; } }
三、替代方案推荐
- Spring Security OAuth2 Authorization Server:如果之前自建了授权服务器,官方推荐迁移到这个独立模块,它完全替代旧
spring-security-oauth2的授权服务功能,支持OAuth2.1和OpenID Connect 1.0。 - 第三方身份服务:若无需自建授权服务,可直接集成Auth0、Okta等成熟身份提供商,Spring Security提供开箱即用的客户端支持,仅需配置对应客户端信息即可。
四、关键注意事项
- 旧的
@EnableOAuth2Client、ResourceServerConfigurerAdapter、OAuth2ClientContext等类已移除,统一通过SecurityFilterChain配置。 - JWT处理统一使用
spring-security-oauth2-jose模块下的类,替代旧的JWT解析工具。 - 客户端注册信息优先通过
application.yml配置,减少硬编码:spring: security: oauth2: client: registration: custom-client: client-id: your-client-id client-secret: your-client-secret scope: read,write authorization-grant-type: authorization_code redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}" client-name: Custom Auth Server provider: custom-client: authorization-uri: https://auth-server.com/oauth2/authorize token-uri: https://auth-server.com/oauth2/token user-info-uri: https://auth-server.com/oauth2/userinfo user-name-attribute: sub
内容的提问来源于stack exchange,提问作者Eason-Manulife
相关产品推荐
相关产品推荐

