You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring MVC如何通过XML配置将OAuth2的UUID令牌替换为JWT令牌?

Spring MVC XML配置OAuth2返回JWT令牌

要把原有的UUID格式access_token改成JWT格式,只需对Spring Security OAuth2的XML配置做以下关键修改:

1. 替换TokenStore实现

将原有的InMemoryTokenStore替换为JwtTokenStore,它专门用于处理JWT令牌的存储与解析。

2. 配置JWT令牌转换器

添加JwtAccessTokenConverter bean,用于JWT的生成和签名验证,示例使用对称密钥(生产环境建议使用RSA非对称密钥以提升安全性)。

3. 更新TokenServices配置

给DefaultTokenServices添加tokenEnhancer属性,关联JWT转换器,让它生成JWT格式的access_token。

修改后的完整配置

<!-- 配置JWT令牌转换器,设置签名密钥 -->
<beans:bean id="jwtAccessTokenConverter" class="org.springframework.security.oauth2.provider.token.store.JwtAccessTokenConverter">
    <beans:property name="signingKey" value="your-secure-secret-key"/> <!-- 替换为实际生产级密钥 -->
</beans:bean>

<!-- 替换为JWT TokenStore -->
<beans:bean id="tokenStore" class="org.springframework.security.oauth2.provider.token.store.JwtTokenStore">
    <beans:constructor-arg ref="jwtAccessTokenConverter"/>
</beans:bean>

<beans:bean id="requestFactory"
            class="org.springframework.security.oauth2.provider.request.DefaultOAuth2RequestFactory">
    <beans:constructor-arg name="clientDetailsService" ref="clientDetails"/>
</beans:bean>

<!-- 更新TokenServices,添加tokenEnhancer -->
<beans:bean id="tokenServices"
            class="org.springframework.security.oauth2.provider.token.DefaultTokenServices">
    <beans:property name="tokenStore" ref="tokenStore"/>
    <beans:property name="supportRefreshToken" value="true"/>
    <beans:property name="accessTokenValiditySeconds" value="100"/>
    <beans:property name="clientDetailsService" ref="clientDetails"/>
    <beans:property name="tokenEnhancer" ref="jwtAccessTokenConverter"/> <!-- 新增JWT转换器关联 -->
</beans:bean>

<beans:bean id="userApprovalHandler" class="org.springframework.security.oauth2.provider.approval.TokenStoreUserApprovalHandler">
    <beans:property name="tokenStore" ref="tokenStore"/>
    <beans:property name="requestFactory" ref="requestFactory"/>
</beans:bean>

<oauth:authorization-server
        client-details-service-ref="clientDetails" token-services-ref="tokenServices"
        user-approval-handler-ref="userApprovalHandler">
    <oauth:authorization-code/>
    <oauth:implicit/>
    <oauth:refresh-token/>
    <oauth:client-credentials/>
    <oauth:password/>
</oauth:authorization-server>

<!-- 资源服务器使用相同的tokenServices,确保能解析JWT -->
<oauth:resource-server id="resourceServerFilter" resource-id="test" token-services-ref="tokenServices"/>

<!--client configuration-->
<oauth:client-details-service id="clientDetails">
    <oauth:client client-id="app"
                  authorized-grant-types="authorization_code,client_credentials,password,refresh_token,implicit"
                  scope="read, write, trust"
                  secret="123456"/>
</oauth:client-details-service>

注意事项

  • 密钥安全:示例中使用对称密钥signingKey,生产环境推荐使用RSA非对称密钥,可通过keyPair属性配置RSA密钥对。
  • Refresh Token:JWT TokenStore下,refresh_token仍会以UUID格式返回(因为refresh_token需要持久化存储,JWT本身是无状态的,无法直接作为refresh_token使用)。
  • 依赖要求:确保项目中引入了spring-security-oauth2和spring-security-jwt相关依赖,否则JWT相关类会无法加载。

修改完成后,调用/oauth/token?grant_type=password会返回类似如下的响应:

{
    "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE3MTk2NzQyMTcsInVzZXJfbmFtZSI6InVzZXIiLCJhdXRob3JpdGllcyI6WyJST0xFX1VTRVIiXSwianRpIjoiYjE2YzJkNzAtYjU0OC00NzJmLWI0MTUtYjI5MjQzYjJhYzU2IiwiY2xpZW50X2lkIjoiYXBwIiwic2NvcGUiOlsidHJ1c3QiLCJ3cml0ZSIsInJlYWQiXX0.SampleSignature",
    "token_type": "bearer",
    "refresh_token": "7586ee7c-f7c7-4fa5-960d-4fa35ca2dbac",
    "expires_in": 99,
    "scope": "trust write read"
}

内容的提问来源于stack exchange,提问作者nooruto

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 20:03:27