You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6中Nimbus生成的JWT在jwt.io显示签名无效求助

问题:Spring Security 6 + Nimbus JWT签名在jwt.io验证无效

我的实现代码

安全配置类

@Bean
public JwtDecoder jwtDecoder() {
    return NimbusJwtDecoder.withPublicKey( jwtConfigProperties.getPublicKey()).build();
} 

@Bean 
public JwtEncoder jwtEncoder(){ 
    JWK jwk = new RSAKey.Builder( jwtConfigProperties.getPublicKey()).privateKey(jwtConfigProperties.getPrivateKey()).build(); 
    JWKSource<SecurityContext> jwks = new ImmutableJWKSet<>(new JWKSet(jwk));
    return new NimbusJwtEncoder(jwks);
}

RSA密钥配置类

public class RsaKeyProperties {

    private RSAPrivateKey privateKey;
    
    private RSAPublicKey publicKey;
    
    @Autowired
    KeyGeneratorUtility keygen;

    @PostConstruct
    public void init() {
        KeyPair keyPair = keygen.generateKey();
        
        this.privateKey = (RSAPrivateKey) keyPair.getPrivate();
        System.out.println("rsa private key : "+privateKey);
        this.publicKey = (RSAPublicKey) keyPair.getPublic();
        System.out.println("rsa public key : "+publicKey);
    }
}

RSA密钥生成工具类

public class KeyGeneratorUtility {
    
    public KeyPair generateKey() {
        
        KeyPair keyPair;

        try{
            KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA");
            keyPairGenerator.initialize(2048);
            keyPair = keyPairGenerator.generateKeyPair();
        } catch(Exception e){
            throw new IllegalStateException();
        }

        return keyPair;
    }
}

Token生成代码

public String generateToken(ProductUser produser) {
        Instant now = Instant.now();
        String scope = produser.getAuthorities().stream().map(GrantedAuthority::getAuthority).collect(Collectors.joining(" "));
        
        JwtClaimsSet claims = JwtClaimsSet.builder()
                .issuer("self")
                .issuedAt(now)
                .expiresAt(now.plus(1, ChronoUnit.HOURS))
                .subject(produser.getUsername())
                .claim("scope", scope)
                .build();
        
        return this.encoder.encode(JwtEncoderParameters.from(claims)).getTokenValue();
    }

问题现象

通过Postman调用接口能正常返回200 OK,生成的Token如下:

eyJhbGciOiJSUzI1NiJ9.eyJpc3MiOiJzZWxmIiwic3ViIjoic2F5YW50YW51c2VyIiwiZXhwIjoxNjkyNzY1MTU5LCJpYXQiOjE2OTI3NjE1NTksInNjb3BlIjoidXNlcjpjcmVhdGUgdXNlcjpkZWxldGUgdXNlcjp1cGRhdGUgdXNlcjpyZWFkIFJPTEVfVVNFUiJ9.LtLP0YcniqgKbhqMkTOWtBMqGLKP1nk5xKWZhELmsISCFTPmMbCVCAPikJqz9psW3QjoMWgbOoia3_saohrbPI1EfTIYb_P0K5bh3eD2StIK0B4ywf39-ENvzE9Zt9GuRTWHQ7tk1cBJv9YhqZxDzmFbZdPDBB1ZWYXGLxBhKec8vVlidGA0UqPKNiZhSFoop3mjmzu2N4kah7WZ__q20ccFeS52icKXyw8kpFbxiasouWRLPjy75nwgcYhXASKfs5TSYPyzppCTE1cqQ3CzVOv21xpzK6QjD9hnTz8aqrsz8mFTFxd0VRqenwLx1s9SiHldfG0DK_umd9w_83muoQ

但将该Token粘贴到jwt.io时显示签名无效,请问哪里操作有误?实现方式是否不正确?恳请帮忙排查解决。

内容的提问来源于stack exchange,提问作者Sayantan Chatterjee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 22:05:54