You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何自定义Spring Security授权服务器的scopes_supported返回值?

自定义Spring Authorization Server OIDC配置端点的scopes_supported字段

现有Spring Authorization Server配置如下:

@Bean
@Order(1)
public SecurityFilterChain authorizationServerSecurityFilterChain(HttpSecurity http) throws Exception {
    OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(http);
    http.getConfigurer(OAuth2AuthorizationServerConfigurer.class)
            .oidc(Customizer.withDefaults());   // Enable OpenID Connect 1.0
    http
            // Redirect to the login page when not authenticated from the
            // authorization endpoint
            .exceptionHandling((exceptions) -> exceptions
                    .authenticationEntryPoint(
                            new LoginUrlAuthenticationEntryPoint("/login"))
            )

            // Accept access tokens for User Info and/or Client Registration
            .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt);

    return http.build();
}

当前访问http://[host]/.well-known/openid-configuration时,scopes_supported字段仅返回["openid"]。已知该字段在OidcProviderConfigurationEndpointFilter中是硬编码的,请问如何将其修改为返回["openid", "email", "profile"]?


可以通过自定义OIDC提供者配置的定制器来修改该字段,无需修改底层硬编码的类。具体方案如下:

方法一:通过OidcConfigurer的定制器修改

在原有的SecurityFilterChain配置中,调整oidc()的配置逻辑,添加providerConfigurationCustomizer覆盖默认的scopes_supported:

@Bean
@Order(1)
public SecurityFilterChain authorizationServerSecurityFilterChain(HttpSecurity http) throws Exception {
    OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(http);
    
    http.getConfigurer(OAuth2AuthorizationServerConfigurer.class)
            .oidc(oidc -> oidc
                    .providerConfigurationCustomizer(config -> {
                        // 设置自定义支持的scopes
                        config.setScopesSupported(List.of("openid", "email", "profile"));
                    })
            );   // Enable OpenID Connect 1.0
    
    http
            .exceptionHandling((exceptions) -> exceptions
                    .authenticationEntryPoint(new LoginUrlAuthenticationEntryPoint("/login"))
            )
            .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt);

    return http.build();
}

方法二:注册自定义OidcProviderConfiguration Bean

如果需要更全面的自定义OIDC提供者配置,可以直接注册OidcProviderConfiguration的Bean,覆盖默认实现:

@Bean
public OidcProviderConfiguration oidcProviderConfiguration() {
    OidcProviderConfiguration config = new OidcProviderConfiguration();
    // 设置支持的scopes
    config.setScopesSupported(List.of("openid", "email", "profile"));
    // 可同时自定义其他OIDC配置字段,比如支持的声明
    config.setClaimsSupported(List.of("sub", "email", "email_verified", "name", "given_name", "family_name"));
    return config;
}

注意事项

  • 上述方案适用于Spring Authorization Server 1.x及以上版本(含最新2.x版本)。
  • 自定义完成后,重新访问/.well-known/openid-configuration即可看到更新后的scopes_supported字段。
  • 若同时使用两种方法,OidcProviderConfiguration Bean的优先级更高。

内容的提问来源于stack exchange,提问作者Anoop Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 00:57:28