为何配置OAuth登录的Spring Boot响应式应用仍生成默认账号密码?
基于Spring Boot 3.0.6响应式应用OAuth2登录配置问题:仍生成默认用户/密码
我已经为基于Spring Boot 3.0.6的响应式应用配置了OAuth2登录,但启动时系统依然自动生成默认的用户和密码,麻烦帮忙排查配置问题。
控制台日志
2023-05-08T08:32:25.413-04:00 INFO 16296 --- [ restartedMain] ctiveUserDetailsServiceAutoConfiguration : Using generated security password: 5c98715f-86eb-453b-b0ae-b0794350a048 2023-05-08T08:32:25.805-04:00 INFO 16296 --- [ restartedMain] o.s.b.d.a.OptionalLiveReloadServer : LiveReload server is running on port 35729
application.yml配置
spring: security: oauth2: client: registration: my-oauth: client-name: my-oauth client-id: ${my-oauth-sso-client} client-secret: ${my-oauth-sso-secret} authorization-grant-type: authorization_code redirect-uri: http://localhost:8080/login/oauth2/code/my-oauth provider: my-oauth: authorization-uri: https://my-oauth.com/v2/oauth/authorize token-uri: https://my-oauth.com/v2/oauth/token user-info-uri: https://my-oauth.com/oauth/verify user-name-attribute: UserName resourceserver: jwt: jwk-set-uri: https://my-oauth.com/oauth/jwks issuer-uri: https://my-oauth.com
WebSecurityConfig配置
@Configuration public class WebSecurityConfig { @Bean public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) { http.authorizeExchange() .anyExchange() .authenticated() .and() .oauth2Login() ; return http.build(); } }
pom.xml依赖片段
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.0.6</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>com.my-oauth</groupId> <artifactId>Oauth</artifactId> <version>0.0.1-SNAPSHOT</version> <name>my-oauth</name> <properties> <java.version>17</java.version> <mapstruct.version>1.5.3.Final</mapstruct.version> <testcontainers.version>1.17.6</testcontainers.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-webflux</artifactId> </dependency> ... </project>
问题排查与解决
出现自动生成默认用户密码的核心原因是Spring Security触发了UserDetailsService自动配置,结合你的场景,可通过以下几点调整解决:
移除冗余的资源服务器配置
当前应用是作为OAuth2客户端实现登录,而非资源服务器,保留spring.security.oauth2.resourceserver配置会导致Spring Security同时加载两套认证逻辑,触发默认用户生成。建议暂时注释或删除这部分配置。显式禁用默认认证方式
在SecurityWebFilterChain中关闭表单登录和HTTP Basic认证,确保仅启用OAuth2登录逻辑:@Configuration public class WebSecurityConfig { @Bean public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) { http.authorizeExchange() .anyExchange().authenticated() .and() .oauth2Login() .and() .formLogin().disable() .httpBasic().disable(); return http.build(); } }验证OAuth2配置有效性
确认my-oauth-sso-client和my-oauth-sso-secret环境变量已正确加载,避免因配置缺失导致Spring Security fallback到默认认证逻辑。检查依赖是否冗余
确认pom.xml中没有直接引入spring-boot-starter-security(若为间接引入无需处理),确保spring-boot-starter-oauth2-client是核心安全依赖。
调整完成后重启应用,默认用户密码的日志将不再出现,应用会直接引导至OAuth2授权页面完成登录。
内容的提问来源于stack exchange,提问作者Timothy Vogel
相关产品推荐
相关产品推荐

