You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Spring OAuth2授权服务器允许GET方法访问/oauth2/introspect

配置/oauth2/introspect端点支持GET方法

针对Spring Security OAuth2中原有TokenEndpoint配置方法已废弃的情况,以下是两种可行方案实现端点支持GET请求:

方案一:自定义端点处理器替代默认实现

  1. 编写自定义端点类,同时处理POST和GET请求:
import org.springframework.security.oauth2.server.resource.introspection.OAuth2IntrospectionResponse;
import org.springframework.security.oauth2.server.resource.introspection.OAuth2Introspector;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class CustomIntrospectEndpoint {

    private final OAuth2Introspector introspector;

    public CustomIntrospectEndpoint(OAuth2Introspector introspector) {
        this.introspector = introspector;
    }

    @PostMapping("/oauth2/introspect")
    public OAuth2IntrospectionResponse introspectPost(@RequestParam("token") String token) {
        return introspector.introspect(token);
    }

    @GetMapping("/oauth2/introspect")
    public OAuth2IntrospectionResponse introspectGet(@RequestParam("token") String token) {
        return introspector.introspect(token);
    }
}
  1. 在Security配置中禁用默认端点,避免冲突:
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .oauth2ResourceServer(oauth2 -> oauth2
                .introspection(introspection -> introspection
                    .clientId("你的客户端ID")
                    .clientSecret("你的客户端密钥")
                )
                .disableDefaultEndpoint()
            );
        return http.build();
    }
}

方案二:修改默认端点的请求方法映射

无需完全自定义端点,通过注册请求映射扩展允许的方法:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.oauth2.server.resource.web.OAuth2IntrospectionEndpointFilter;
import org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping;

@Configuration
public class EndpointMappingConfig {

    @Bean
    public RequestMappingHandlerMapping requestMappingHandlerMapping() {
        RequestMappingHandlerMapping mapping = new RequestMappingHandlerMapping();
        // 为默认introspect端点添加GET方法支持
        mapping.registerMapping(
            org.springframework.web.bind.annotation.RequestMethod.GET,
            "/oauth2/introspect",
            OAuth2IntrospectionEndpointFilter.class,
            "introspect"
        );
        return mapping;
    }
}

验证

启动服务后,发送GET请求 GET /oauth2/introspect?token=你的访问令牌,应返回与POST请求一致的令牌校验结果。

内容的提问来源于stack exchange,提问作者Sard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 00:48:16