You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Postman测试Spring Authorization Server的登出流程?

测试Spring Authorization Server登出流程(Postman操作指南)

1. 确认授权服务器的登出端点配置

新版Spring Authorization Server默认提供/oauth2/revoke令牌撤销端点,需确保你的授权服务器安全配置允许访问该端点,示例配置如下:

@Bean
public SecurityFilterChain authServerSecurityFilterChain(HttpSecurity http) throws Exception {
    OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(http);
    http.getConfigurer(OAuth2AuthorizationServerConfigurer.class)
        .oidc(Customizer.withDefaults()); // 启用OIDC可选
    
    // 允许已认证的客户端访问撤销端点
    http.authorizeHttpRequests(auth -> auth
        .requestMatchers("/oauth2/revoke").authenticated()
    );
    return http.build();
}

2. Postman中构造令牌撤销请求

  • 请求方法:POST
  • 请求URL:{你的授权服务器地址}/oauth2/revoke
  • 请求头:添加Content-Type: application/x-www-form-urlencoded
  • 认证方式:选择Basic Auth,填入你的OAuth2客户端ID和客户端密钥
  • 请求体(选择x-www-form-urlencoded格式):
    • token:填入需要撤销的访问令牌(access_token)或刷新令牌(refresh_token)
    • token_type_hint(可选):指定令牌类型,值为access_token或refresh_token,帮助服务器快速定位令牌

3. 验证登出效果

  • 发送撤销请求后,用被撤销的访问令牌调用受保护的API端点,应该返回401 Unauthorized
  • 若撤销的是刷新令牌,后续再用该刷新令牌请求新的访问令牌会失败

关键注意事项

  • 如果你使用的是JWT(自包含令牌),需在授权/资源服务器端实现令牌黑名单机制(比如用Redis存储已撤销的令牌),因为JWT本身是无状态的,仅靠服务器端撤销无法直接让客户端持有的旧令牌失效,必须在校验令牌时检查是否在黑名单中。
  • 若基于OIDC协议,还可使用/logout端点实现前端登出,但核心的令牌失效逻辑仍依赖/oauth2/revoke端点。

内容的提问来源于stack exchange,提问作者Scorpio76

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 16:22:28