如何配置Spring OAuth2授权服务器允许GET方法访问/oauth2/introspect
配置/oauth2/introspect端点支持GET方法
针对Spring Security OAuth2中原有TokenEndpoint配置方法已废弃的情况,以下是两种可行方案实现端点支持GET请求:
方案一:自定义端点处理器替代默认实现
- 编写自定义端点类,同时处理POST和GET请求:
import org.springframework.security.oauth2.server.resource.introspection.OAuth2IntrospectionResponse; import org.springframework.security.oauth2.server.resource.introspection.OAuth2Introspector; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.PostMapping; import org.springframework.web.bind.annotation.RequestParam; import org.springframework.web.bind.annotation.RestController; @RestController public class CustomIntrospectEndpoint { private final OAuth2Introspector introspector; public CustomIntrospectEndpoint(OAuth2Introspector introspector) { this.introspector = introspector; } @PostMapping("/oauth2/introspect") public OAuth2IntrospectionResponse introspectPost(@RequestParam("token") String token) { return introspector.introspect(token); } @GetMapping("/oauth2/introspect") public OAuth2IntrospectionResponse introspectGet(@RequestParam("token") String token) { return introspector.introspect(token); } }
- 在Security配置中禁用默认端点,避免冲突:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .oauth2ResourceServer(oauth2 -> oauth2 .introspection(introspection -> introspection .clientId("你的客户端ID") .clientSecret("你的客户端密钥") ) .disableDefaultEndpoint() ); return http.build(); } }
方案二:修改默认端点的请求方法映射
无需完全自定义端点,通过注册请求映射扩展允许的方法:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.oauth2.server.resource.web.OAuth2IntrospectionEndpointFilter; import org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping; @Configuration public class EndpointMappingConfig { @Bean public RequestMappingHandlerMapping requestMappingHandlerMapping() { RequestMappingHandlerMapping mapping = new RequestMappingHandlerMapping(); // 为默认introspect端点添加GET方法支持 mapping.registerMapping( org.springframework.web.bind.annotation.RequestMethod.GET, "/oauth2/introspect", OAuth2IntrospectionEndpointFilter.class, "introspect" ); return mapping; } }
验证
启动服务后,发送GET请求 GET /oauth2/introspect?token=你的访问令牌,应返回与POST请求一致的令牌校验结果。
内容的提问来源于stack exchange,提问作者Sard
相关产品推荐
相关产品推荐

