You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Access/ID Token更新授权服务器用户信息?调用接口授权失败

解决Spring Authorization Server下/user端点授权失败问题

核心排查点

  • 资源服务器是否正确关联授权服务器的Token校验端点
  • /user端点的安全规则是否开启了Bearer Token校验
  • Access Token的scope是否包含访问该端点的权限

具体修复步骤

  1. 补全资源服务器配置
    必须在资源服务器配置类里明确指定授权服务器的地址,让Token校验逻辑能找到正确的签名验证源:

    @Configuration
    @EnableWebSecurity
    public class ResourceServerConfig {
        @Bean
        public SecurityFilterChain resourceServerFilterChain(HttpSecurity http) throws Exception {
            http
                .authorizeHttpRequests(auth -> auth
                    .requestMatchers("/user").authenticated()
                )
                .oauth2ResourceServer(oauth2 -> oauth2
                    .jwt(jwt -> jwt
                        .issuerUri("http://你的授权服务器地址:端口") // 替换成实际地址
                    )
                );
            return http.build();
        }
    }
    
  2. 验证Token状态与权限
    调用授权服务器的令牌introspect接口,传入你的Access Token,确认Token未过期、未被撤销,且包含所需的scope(比如user:write)。

  3. 检查请求头格式
    确认请求头严格遵循Authorization: Bearer <你的Access Token>格式,注意Bearer和Token之间有空格,不要出现拼写错误。

  4. 处理跨域场景
    如果是前端跨域调用,要配置CORS允许携带Authorization请求头:

    @Bean
    public CorsConfigurationSource corsConfig() {
        CorsConfiguration corsConfig = new CorsConfiguration();
        corsConfig.setAllowedOrigins(List.of("http://你的前端地址"));
        corsConfig.setAllowedMethods(List.of("PUT", "POST", "GET"));
        corsConfig.setAllowedHeaders(List.of("Authorization", "Content-Type"));
        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        source.registerCorsConfiguration("/**", corsConfig);
        return source;
    }
    
  5. 注意同应用下的配置顺序

    若授权服务器和资源服务器在同一应用中,必须保证资源服务器的SecurityFilterChain优先级高于授权服务器的配置,否则会出现Token校验规则被覆盖的情况。

内容的提问来源于stack exchange,提问作者Thirumal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 22:52:38