You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何配置OAuth登录的Spring Boot响应式应用仍生成默认账号密码?

基于Spring Boot 3.0.6响应式应用OAuth2登录配置问题:仍生成默认用户/密码

我已经为基于Spring Boot 3.0.6的响应式应用配置了OAuth2登录,但启动时系统依然自动生成默认的用户和密码,麻烦帮忙排查配置问题。


控制台日志

2023-05-08T08:32:25.413-04:00  INFO 16296 --- [  restartedMain] ctiveUserDetailsServiceAutoConfiguration :

Using generated security password: 5c98715f-86eb-453b-b0ae-b0794350a048

2023-05-08T08:32:25.805-04:00  INFO 16296 --- [  restartedMain] o.s.b.d.a.OptionalLiveReloadServer       : LiveReload server is running on port 35729

application.yml配置

spring:
  security:
    oauth2:
      client:
        registration:
          my-oauth:
            client-name: my-oauth
            client-id: ${my-oauth-sso-client}
            client-secret: ${my-oauth-sso-secret}
            authorization-grant-type: authorization_code
            redirect-uri: http://localhost:8080/login/oauth2/code/my-oauth
        provider:
          my-oauth:
            authorization-uri: https://my-oauth.com/v2/oauth/authorize
            token-uri: https://my-oauth.com/v2/oauth/token
            user-info-uri: https://my-oauth.com/oauth/verify
            user-name-attribute: UserName
      resourceserver:
        jwt:
          jwk-set-uri: https://my-oauth.com/oauth/jwks
          issuer-uri: https://my-oauth.com

WebSecurityConfig配置

@Configuration
public class WebSecurityConfig {
    @Bean
    public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) {
        http.authorizeExchange()
                .anyExchange()
                .authenticated()
                .and()
                .oauth2Login()
        ;

        return http.build();
    }
}

pom.xml依赖片段

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>
    <parent>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-parent</artifactId>
        <version>3.0.6</version>
        <relativePath/> <!-- lookup parent from repository -->
    </parent>
    <groupId>com.my-oauth</groupId>
    <artifactId>Oauth</artifactId>
    <version>0.0.1-SNAPSHOT</version>
    <name>my-oauth</name>
    <properties>
        <java.version>17</java.version>
        <mapstruct.version>1.5.3.Final</mapstruct.version>
        <testcontainers.version>1.17.6</testcontainers.version>
    </properties>
    <dependencies>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-oauth2-client</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-webflux</artifactId>
        </dependency>
    ...
</project>

问题排查与解决

出现自动生成默认用户密码的核心原因是Spring Security触发了UserDetailsService自动配置,结合你的场景,可通过以下几点调整解决:

  1. 移除冗余的资源服务器配置
    当前应用是作为OAuth2客户端实现登录,而非资源服务器,保留spring.security.oauth2.resourceserver配置会导致Spring Security同时加载两套认证逻辑,触发默认用户生成。建议暂时注释或删除这部分配置。

  2. 显式禁用默认认证方式
    在SecurityWebFilterChain中关闭表单登录和HTTP Basic认证,确保仅启用OAuth2登录逻辑:

    @Configuration
    public class WebSecurityConfig {
        @Bean
        public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) {
            http.authorizeExchange()
                    .anyExchange().authenticated()
                    .and()
                    .oauth2Login()
                    .and()
                    .formLogin().disable()
                    .httpBasic().disable();
    
            return http.build();
        }
    }
    
  3. 验证OAuth2配置有效性
    确认my-oauth-sso-client和my-oauth-sso-secret环境变量已正确加载,避免因配置缺失导致Spring Security fallback到默认认证逻辑。

  4. 检查依赖是否冗余
    确认pom.xml中没有直接引入spring-boot-starter-security(若为间接引入无需处理),确保spring-boot-starter-oauth2-client是核心安全依赖。

调整完成后重启应用,默认用户密码的日志将不再出现,应用会直接引导至OAuth2授权页面完成登录。

内容的提问来源于stack exchange,提问作者Timothy Vogel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 08:20:09