Spring Cloud Data Flow 2.9.2 OAuth2:如何绑定att_member属性为用户角色?
Spring Cloud Data Flow 2.9.2 绑定OAuth2 Token自定义属性为用户角色
可以通过自定义Spring Security的OAuth2用户信息转换器/权限映射器,将ID-token中的att_member属性映射为用户角色,无需修改scope配置。具体实现分两种场景:
场景1:使用Authorization Code模式的OAuth2 Login
如果是通过前端跳转授权码流程获取用户信息,自定义OAuth2UserService来解析att_member并转换为权限:
@Configuration @EnableOAuth2Login public class OAuth2SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .oauth2Login() .userInfoEndpoint() .userService(customOAuth2UserService()); } private OAuth2UserService<OAuth2UserRequest, OAuth2User> customOAuth2UserService() { DefaultOAuth2UserService defaultService = new DefaultOAuth2UserService(); return request -> { OAuth2User originalUser = defaultService.loadUser(request); // 从token属性中提取att_member(注意类型匹配,若为单个字符串需做拆分) List<String> roleValues = (List<String>) originalUser.getAttributes().get("att_member"); // 转换为Spring Security标准权限,建议添加ROLE_前缀适配SCDF的权限规则 Collection<GrantedAuthority> authorities = roleValues.stream() .map(role -> new SimpleGrantedAuthority("ROLE_" + role)) .collect(Collectors.toList()); // 返回包含自定义权限的OAuth2用户对象 return new DefaultOAuth2User(authorities, originalUser.getAttributes(), "sub"); }; } }
场景2:使用JWT类型的ID-token作为资源服务器凭证
如果SCDF作为资源服务器直接解析JWT格式的ID-token,自定义JwtAuthenticationConverter来映射权限:
@Configuration public class JwtSecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .oauth2ResourceServer() .jwt() .jwtAuthenticationConverter(jwtAuthenticationConverter()); } @Bean public JwtAuthenticationConverter jwtAuthenticationConverter() { JwtAuthenticationConverter converter = new JwtAuthenticationConverter(); converter.setJwtGrantedAuthoritiesConverter(jwt -> { // 从JWT Claims中读取att_member List<String> roleValues = jwt.getClaim("att_member"); // 转换为GrantedAuthority return roleValues.stream() .map(role -> new SimpleGrantedAuthority("ROLE_" + role)) .collect(Collectors.toList()); }); return converter; } }
注意事项
- 确保
att_member的类型与代码中解析的一致(列表/字符串),如果是单个字符串,可通过String.split(",")等方式拆分为角色列表 - SCDF的权限控制依赖带
ROLE_前缀的权限标识,所以转换时建议统一添加该前缀 - 测试时可通过
SecurityContextHolder.getContext().getAuthentication().getAuthorities()验证权限是否正确加载
内容的提问来源于stack exchange,提问作者jakeops
相关产品推荐
相关产品推荐

