使用自定义JwtAuthenticationConverter替代已废弃的jwt()方法
解决方案
直接通过jwt()的重载方法传入Lambda配置JwtConfigurer,在Lambda内部设置自定义的JwtAuthenticationConverter即可,无需手动创建JwtConfigurer实例。修改后的代码如下:
http.oauth2ResourceServer(server -> server.jwt(jwtConfigurer -> jwtConfigurer.jwtAuthenticationConverter(jwtAuthenticationConverter()) ) );
你的JwtAuthenticationConverter Bean定义可以保持不变:
@Bean public JwtAuthenticationConverter jwtAuthenticationConverter() { // 保留你的自定义逻辑,比如配置权限映射器等 JwtAuthenticationConverter converter = new JwtAuthenticationConverter(); // 示例:添加自定义权限转换规则 converter.setJwtGrantedAuthoritiesMapper(yourGrantedAuthoritiesMapper()); return converter; }
说明
废弃无参jwt()方法是Spring Security为了统一配置风格,通过Consumer Lambda可以更清晰地封装JWT相关的所有配置(除转换器外,还可配置验证器、解码器等),让配置代码更具可读性和内聚性。
内容的提问来源于stack exchange,提问作者Flocke
相关产品推荐
相关产品推荐

