OAuth2FeignRequestInterceptor替代方案咨询:依赖已弃用类问题
Let me break down clear answers to your three questions based on my hands-on experience with Spring Security and Spring Cloud:
1. Is OAuth2ClientContext really deprecated, or just need adjustment?
OAuth2ClientContext is definitely deprecated—it’s part of the older Spring Security OAuth2 2.x stack that Spring has fully phased out in favor of the modern OAuth2 client framework introduced in Spring Security 5.x. It’s not a case of tweaking how you use it; the entire old client infrastructure is being retired, and this class is marked for removal in future releases. You might still encounter it in legacy Spring Cloud versions, but it’s not a sustainable component to rely on long-term.
2. What's the correct replacement if it's deprecated?
The modern solution leverages Spring Security 5.x’s OAuth2AuthorizedClientManager and related APIs. You can build a custom Feign request interceptor that transparently fetches and attaches OAuth2 tokens, just like the old OAuth2FeignRequestInterceptor did. Here’s a practical implementation:
First, create the custom Feign interceptor:
import feign.RequestInterceptor; import feign.RequestTemplate; import org.springframework.security.oauth2.client.OAuth2AuthorizedClient; import org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager; import org.springframework.security.oauth2.client.OAuth2AuthorizeRequest; import org.springframework.stereotype.Component; @Component public class CustomOAuth2FeignInterceptor implements RequestInterceptor { private final OAuth2AuthorizedClientManager authorizedClientManager; public CustomOAuth2FeignInterceptor(OAuth2AuthorizedClientManager authorizedClientManager) { this.authorizedClientManager = authorizedClientManager; } @Override public void apply(RequestTemplate template) { // Adjust the client registration ID and principal to match your use case OAuth2AuthorizeRequest authorizeRequest = OAuth2AuthorizeRequest.withClientRegistrationId("your-client-id") .principal("client-principal") // Use "anonymousUser" for client credentials flow, or current user for authorization code flow .build(); OAuth2AuthorizedClient authorizedClient = authorizedClientManager.authorize(authorizeRequest); if (authorizedClient != null && authorizedClient.getAccessToken() != null) { template.header("Authorization", "Bearer " + authorizedClient.getAccessToken().getTokenValue()); } } }
Then configure the OAuth2AuthorizedClientManager bean:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager; import org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider; import org.springframework.security.oauth2.client.OAuth2AuthorizedClientProviderBuilder; import org.springframework.security.oauth2.client.registration.ClientRegistrationRepository; import org.springframework.security.oauth2.client.web.DefaultOAuth2AuthorizedClientManager; import org.springframework.security.oauth2.client.web.OAuth2AuthorizedClientRepository; @Configuration public class OAuth2ClientConfig { @Bean public OAuth2AuthorizedClientManager authorizedClientManager( ClientRegistrationRepository clientRegistrationRepository, OAuth2AuthorizedClientRepository authorizedClientRepository) { OAuth2AuthorizedClientProvider authorizedClientProvider = OAuth2AuthorizedClientProviderBuilder.builder() .clientCredentials() // Add other grant types like authorizationCode if your flow requires it .build(); DefaultOAuth2AuthorizedClientManager authorizedClientManager = new DefaultOAuth2AuthorizedClientManager( clientRegistrationRepository, authorizedClientRepository); authorizedClientManager.setAuthorizedClientProvider(authorizedClientProvider); return authorizedClientManager; } }
This setup works for all common OAuth2 flows—just adjust the OAuth2AuthorizedClientProvider and principal value to fit your specific use case.
3. Are there plans to migrate OAuth2FeignRequestInterceptor away from deprecated classes?
From Spring Cloud’s official roadmap, the old spring-cloud-security-oauth2 module (which houses OAuth2FeignRequestInterceptor) is in maintenance mode. The team has shifted focus to integrating natively with Spring Security 5.x’s modern OAuth2 client stack, rather than updating deprecated components. There’s no public plan to migrate this specific interceptor; instead, the official recommendation is to adopt the custom interceptor approach using the modern Spring Security APIs outlined above.
内容的提问来源于stack exchange,提问作者Alexander

