You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security OAuth2迁移至Spring Security 5+(Spring Boot 3.x)求助

Spring Boot 3.x 迁移 OAuth2 至 Spring Security 5.x+ 实用方案

一、核心依赖调整

  • 移除旧的spring-security-oauth2依赖,替换为Spring Security官方整合的OAuth2模块:
    <!-- Spring Security OAuth2 客户端 -->
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-oauth2-client</artifactId>
    </dependency>
    <!-- Spring Security OAuth2 资源服务器(如果是资源服务) -->
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
    </dependency>
    

二、核心代码迁移示例

1. 客户端配置(替代原OAuth2ClientContext等旧类)

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .oauth2Login(oauth2 -> oauth2
                .loginPage("/oauth2/authorization/custom-client") // 自定义登录页(可选)
                .userInfoEndpoint(userInfo -> userInfo
                    .userService(customOAuth2UserService) // 自定义用户信息处理(可选)
                )
            )
            .oauth2Client(oauth2 -> oauth2
                .clientRegistrationRepository(clientRegistrationRepository())
                .authorizedClientService(authorizedClientService())
            );
        return http.build();
    }

    // 客户端注册信息可通过application.yml配置,也可手动注入
    @Bean
    public ClientRegistrationRepository clientRegistrationRepository() {
        return new InMemoryClientRegistrationRepository(customClientRegistration());
    }

    private ClientRegistration customClientRegistration() {
        return ClientRegistration.withRegistrationId("custom-client")
            .clientId("your-client-id")
            .clientSecret("your-client-secret")
            .authorizationUri("https://auth-server.com/oauth2/authorize")
            .tokenUri("https://auth-server.com/oauth2/token")
            .userInfoUri("https://auth-server.com/oauth2/userinfo")
            .userNameAttributeName(IdTokenClaimNames.SUB)
            .redirectUri("{baseUrl}/login/oauth2/code/{registrationId}")
            .scope("read", "write")
            .authorizationGrantType(AuthorizationGrantType.AUTHORIZATION_CODE)
            .clientName("Custom Auth Server")
            .build();
    }
}

2. 资源服务器配置(替代原ResourceServerConfigurerAdapter)

@Configuration
@EnableWebSecurity
public class ResourceServerConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwt -> jwt
                    .jwtAuthenticationConverter(jwtAuthenticationConverter()) // 自定义JWT转换(可选)
                )
            );
        return http.build();
    }

    // 自定义JWT权限转换示例
    private JwtAuthenticationConverter jwtAuthenticationConverter() {
        JwtGrantedAuthoritiesConverter grantedAuthoritiesConverter = new JwtGrantedAuthoritiesConverter();
        grantedAuthoritiesConverter.setAuthorityPrefix("ROLE_");
        grantedAuthoritiesConverter.setAuthoritiesClaimName("roles");

        JwtAuthenticationConverter converter = new JwtAuthenticationConverter();
        converter.setJwtGrantedAuthoritiesConverter(grantedAuthoritiesConverter);
        return converter;
    }
}

三、替代方案推荐

  • Spring Security OAuth2 Authorization Server:如果之前自建了授权服务器,官方推荐迁移到这个独立模块,它完全替代旧spring-security-oauth2的授权服务功能,支持OAuth2.1和OpenID Connect 1.0。
  • 第三方身份服务:若无需自建授权服务,可直接集成Auth0、Okta等成熟身份提供商,Spring Security提供开箱即用的客户端支持,仅需配置对应客户端信息即可。

四、关键注意事项

  • 旧的@EnableOAuth2Client、ResourceServerConfigurerAdapter、OAuth2ClientContext等类已移除,统一通过SecurityFilterChain配置。
  • JWT处理统一使用spring-security-oauth2-jose模块下的类,替代旧的JWT解析工具。
  • 客户端注册信息优先通过application.yml配置,减少硬编码:
    spring:
      security:
        oauth2:
          client:
            registration:
              custom-client:
                client-id: your-client-id
                client-secret: your-client-secret
                scope: read,write
                authorization-grant-type: authorization_code
                redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
                client-name: Custom Auth Server
            provider:
              custom-client:
                authorization-uri: https://auth-server.com/oauth2/authorize
                token-uri: https://auth-server.com/oauth2/token
                user-info-uri: https://auth-server.com/oauth2/userinfo
                user-name-attribute: sub
    

内容的提问来源于stack exchange,提问作者Eason-Manulife

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 19:52:14