Spring Boot 3授权服务器:基于H2与JdbcRegisteredClientRepository验证client_id
Spring Boot 3.0 授权服务器 + H2 数据库客户端存储实现
1. 依赖配置
在pom.xml中添加必要依赖:
<dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-authorization-server</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-jdbc</artifactId> </dependency> <dependency> <groupId>com.h2database</groupId> <artifactId>h2</artifactId> <scope>runtime</scope> </dependency> </dependencies>
2. H2 数据库配置
在application.yml中配置H2连接和控制台:
spring: datasource: url: jdbc:h2:mem:auth-server-db username: sa password: driver-class-name: org.h2.Driver h2: console: enabled: true path: /h2-console sql: init: mode: always schema-locations: classpath:org/springframework/security/oauth2/server/authorization/jdbc/oauth2-authorization-schema.sql
注:
schema-locations指定的是Spring Authorization Server内置的JDBC schema脚本,会自动创建客户端存储所需的表结构。
3. 初始化测试客户端数据
创建src/main/resources/data.sql,插入测试客户端信息:
INSERT INTO oauth2_registered_client ( id, client_id, client_id_issued_at, client_secret, client_secret_expires_at, client_name, client_authentication_methods, authorization_grant_types, redirect_uris, scopes, client_settings, token_settings ) VALUES ( '1', 'test-client', CURRENT_TIMESTAMP, '{bcrypt}$2a$10$GRLdNijSQMUvl/au9ofL.eDwmoohzzS7.rmNSJZ.0FxO/BTk76klW', NULL, 'Test Client', 'client_secret_basic', 'authorization_code,refresh_token', 'http://localhost:8080/login/oauth2/code/test-client', 'openid,profile', '{"@class":"org.springframework.security.oauth2.server.authorization.settings.ClientSettings","requireAuthorizationConsent":false}', '{"@class":"org.springframework.security.oauth2.server.authorization.settings.TokenSettings","accessTokenTimeToLive":"PT1H"}' );
这里的
client_secret是明文test-secret经过BCrypt加密后的结果,你可以自行生成新的加密值替换。
4. 授权服务器配置类
替换原有的InMemoryRegisteredClientRepository,直接使用官方提供的JdbcRegisteredClientRepository:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.oauth2.server.authorization.JdbcOAuth2AuthorizationConsentService; import org.springframework.security.oauth2.server.authorization.JdbcOAuth2AuthorizationService; import org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationConsentService; import org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService; import org.springframework.security.oauth2.server.authorization.client.JdbcRegisteredClientRepository; import org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository; import org.springframework.security.oauth2.server.authorization.config.annotation.web.configuration.OAuth2AuthorizationServerConfiguration; import org.springframework.security.oauth2.server.authorization.config.annotation.web.configurers.OAuth2AuthorizationServerConfigurer; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint; import javax.sql.DataSource; @Configuration @EnableWebSecurity public class AuthorizationServerConfig { @Bean public RegisteredClientRepository registeredClientRepository(DataSource dataSource) { // 直接使用Spring官方封装的JDBC实现,无需自行编写Repository逻辑 return new JdbcRegisteredClientRepository(dataSource); } @Bean public OAuth2AuthorizationService authorizationService(DataSource dataSource, RegisteredClientRepository registeredClientRepository) { return new JdbcOAuth2AuthorizationService(dataSource, registeredClientRepository); } @Bean public OAuth2AuthorizationConsentService authorizationConsentService(DataSource dataSource, RegisteredClientRepository registeredClientRepository) { return new JdbcOAuth2AuthorizationConsentService(dataSource, registeredClientRepository); } @Bean public SecurityFilterChain authorizationServerSecurityFilterChain(HttpSecurity http) throws Exception { OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(http); http.getConfigurer(OAuth2AuthorizationServerConfigurer.class) .oidc(oidc -> oidc.enable(true)); // 可选:开启OIDC支持 // 未登录时跳转至Spring默认登录页 http.exceptionHandling(exceptions -> exceptions .authenticationEntryPoint(new LoginUrlAuthenticationEntryPoint("/login"))); return http.build(); } }
关键说明
- 无需手动从请求中提取
client_id调用findByClientId:Spring Authorization Server的内部流程会自动调用RegisteredClientRepository的方法完成客户端验证,你只需要正确配置JdbcRegisteredClientRepository即可。 JdbcRegisteredClientRepository是Spring官方实现的JDBC版本客户端仓库,已封装所有CRUD和查询逻辑,无需自行编写。- 启动项目后,访问
http://localhost:8080/h2-console,用配置的JDBC URL连接数据库,可查看oauth2_registered_client表中的客户端数据。
内容的提问来源于stack exchange,提问作者Abhi
相关产品推荐
相关产品推荐

