You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 3集成Azure AD配置疑问:替代旧继承方式实现认证

Spring Boot 3 配置 Azure AD 认证(替代旧适配器方案)

1. 依赖确认

你当前使用的依赖版本是适配的,azure-spring-boot-starter-active-directory:4.0.0 完全支持 Spring Boot 3,无需调整。

2. 配置 Azure AD 参数

在 application.yml(或 application.properties)中添加以下配置,替换为你的 Azure AD 租户和客户端信息:

spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          issuer-uri: https://login.microsoftonline.com/你的租户ID/v2.0
azure:
  active-directory:
    tenant-id: 你的租户ID
    client-id: 你的后端应用客户端ID

3. 编写 Security 配置类

替代旧的 AADResourceServerWebSecurityConfigurerAdapter,使用 SecurityFilterChain Bean 配置认证规则:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;
import com.azure.spring.cloud.autoconfigure.aad.AADJwtAuthenticationConverter;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // Angular前端用PKCE时无需CSRF保护
            .csrf(csrf -> csrf.disable())
            // 启用CORS配置
            .cors(cors -> cors.configure(http))
            // 配置接口访问规则
            .authorizeHttpRequests(auth -> auth
                // 允许公开接口(如健康检查)
                .requestMatchers("/actuator/**", "/public/**").permitAll()
                // 其余接口需认证
                .anyRequest().authenticated()
            )
            // 配置OAuth2资源服务器,用JWT验证token
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwt -> jwt.jwtAuthenticationConverter(new AADJwtAuthenticationConverter()))
            );
        return http.build();
    }
}

AADJwtAuthenticationConverter 是Azure starter提供的工具类,可自动解析Azure AD JWT中的声明(如角色、用户信息)。

4. 配置CORS支持Angular前端

添加CORS配置Bean,允许你的Angular前端跨域请求:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.cors.CorsConfigurationSource;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;

import java.util.List;

@Configuration
public class CorsConfig {

    @Bean
    public CorsConfigurationSource corsConfigurationSource() {
        CorsConfiguration config = new CorsConfiguration();
        // 替换为你的Angular前端实际域名
        config.setAllowedOrigins(List.of("http://localhost:4200"));
        config.setAllowedMethods(List.of("GET", "POST", "PUT", "DELETE", "OPTIONS"));
        config.setAllowedHeaders(List.of("*"));
        config.setAllowCredentials(true);

        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        source.registerCorsConfiguration("/**", config);
        return source;
    }
}

5. 验证配置

启动后端后,Angular前端通过PKCE流程获取Azure AD的JWT Token,请求后端接口时携带 Authorization: Bearer <token> 请求头,后端会自动验证Token有效性,允许认证用户访问受保护接口。

内容的提问来源于stack exchange,提问作者meiksner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 21:21:46