JwtIssuerReactiveAuthenticationManagerResolver多租户认证返回401问题排查
问题:Spring Security响应式OAuth2多租户资源服务器返回401,单租户配置正常
我需要支持多租户功能,已参考Spring Security官方文档进行配置,但多租户方式始终返回401,相同JWK URI的单租户配置却能正常认证。
多租户配置代码
JwtIssuerReactiveAuthenticationManagerResolver authenticationManagerResolver = new JwtIssuerReactiveAuthenticationManagerResolver ("https://jwt.com/token.json");
资源服务器配置:
.oauth2ResourceServer(oauth2 -> oauth2. authenticationManagerResolver(authenticationManagerResolver));
单租户可正常工作的配置
YAML配置:
oauth2: resourceserver: jwt: jwk-set-uri: https://jwt.com/token.json
对应的代码实现:
.oauth2ResourceServer(oauth2 -> oauth2. jwt(Customizer.withDefaults()));
日志差异
多租户配置日志(返回401)
2023-03-21 11:46:11.085 DEBUG 15271 --- [ctor-http-nio-3] o.s.w.s.adapter.HttpWebHandlerAdapter : [cabda122-1] HTTP GET "/api/v1/redacted" 2023-03-21 11:46:11.136 DEBUG 15271 --- [ctor-http-nio-3] o.s.w.s.adapter.HttpWebHandlerAdapter : [cabda122-1] Completed 401 UNAUTHORIZED
单租户配置日志(认证成功)
2023-03-21 11:41:53.843 DEBUG 12500 --- [ctor-http-nio-3] o.s.w.s.adapter.HttpWebHandlerAdapter : [963bfd7a-1] HTTP GET "/api/v1/redacted" 2023-03-21 11:41:53.932 DEBUG 12500 --- [ctor-http-nio-3] o.s.w.r.f.client.ExchangeFunctions : [4740b9ba] HTTP GET https://jwt.com/token.json 2023-03-21 11:41:54.695 DEBUG 12500 --- [ctor-http-nio-3] o.s.w.r.f.client.ExchangeFunctions : [4740b9ba] [3475d267-1, L:/10.26.8.242:58490 - R:jwt.com/99.64.754.467:443] Response 200 OK 2023-03-21 11:41:54.713 DEBUG 12500 --- [ctor-http-nio-3] o.s.core.codec.StringDecoder : [4740b9ba] [3475d267-1, L:/10.26.8.242:58490 - R:jwt.com/99.64.754.467:443] Decoded "REDACTED" 2023-03-21 11:41:54.736 DEBUG 12500 --- [ parallel-1] o.s.w.s.s.DefaultWebSessionManager : Created new WebSession. 2023-03-21 11:41:55.090 DEBUG 12500 --- [ctor-http-nio-3] o.s.w.s.adapter.HttpWebHandlerAdapter : [963bfd7a-1] Completed 200 OK
疑问
多租户配置下,为什么没有像单租户那样调用JWK端点完成JWT解码?我遗漏了哪些配置?官方文档中并未提及相关内容。
内容的提问来源于stack exchange,提问作者user2820906
相关产品推荐
相关产品推荐

