You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot3+SpringSecurity6微服务中checkToken校验实现问询

Spring Boot 3 + Spring Security 6 客户端Token校验实现方案

核心变化说明

Spring Security 6 里,旧版本的RemoteTokenServices已被标记为过时,官方推荐用 OAuth2 Resource Server 模块的原生能力实现令牌校验,主要分两种场景:JWT令牌本地校验、不透明令牌远程校验。


场景1:JWT令牌本地校验(推荐)

如果认证服务签发的是JWT令牌,客户端可直接本地校验签名、解析Claims,无需远程调用认证服务,性能更优。

依赖配置

确保项目引入OAuth2 Resource Server依赖:

<!-- Maven -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
</dependency>

配置类实现

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class ResourceServerConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwt -> jwt
                    // 接入自定义JWT转换器(处理自定义Claims时启用)
                    .jwtAuthenticationConverter(new JwtAccessTokenConverterCustom())
                )
            );
        return http.build();
    }
}

配置文件(application.yml)

指定JWT签发者地址,Spring Security会自动获取公钥完成校验:

spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          issuer-uri: ${authUrl} # 认证服务根地址,例:http://localhost:8080/auth

场景2:不透明令牌(Opaque Token)远程校验

如果认证服务签发的是无法本地解析的不透明令牌,需配置令牌 introspection 端点完成远程校验。

依赖配置

同样引入spring-boot-starter-oauth2-resource-server依赖。

配置类实现

import org.springframework.beans.factory.annotation.Value;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.oauth2.server.resource.introspection.NimbusOpaqueTokenIntrospector;
import org.springframework.security.oauth2.server.resource.introspection.OpaqueTokenIntrospector;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class ResourceServerConfig {

    private final String authUrl;
    private final String oauthClient;
    private final String oauthClientSecret;

    // 构造注入配置参数
    public ResourceServerConfig(
            @Value("${auth.url}") String authUrl,
            @Value("${oauth.client-id}") String oauthClient,
            @Value("${oauth.client-secret}") String oauthClientSecret) {
        this.authUrl = authUrl;
        this.oauthClient = oauthClient;
        this.oauthClientSecret = oauthClientSecret;
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .oauth2ResourceServer(oauth2 -> oauth2
                .opaqueToken(token -> token
                    .introspector(opaqueTokenIntrospector())
                )
            );
        return http.build();
    }

    @Bean
    public OpaqueTokenIntrospector opaqueTokenIntrospector() {
        // 配置令牌校验端点,替代旧的RemoteTokenServices
        return new NimbusOpaqueTokenIntrospector(
                authUrl + "/oauth2/introspect",
                oauthClient,
                oauthClientSecret
        );
    }
}

注意事项

  • 认证服务需开启令牌 introspection 端点,Spring Authorization Server 默认已开启/oauth2/introspect
  • 确保客户端(资源服务)在认证服务中被配置为允许调用该校验接口

旧代码失效原因

  1. RemoteTokenServices属于Spring Security 6的遗留组件,官方不再维护,核心逻辑已整合到OAuth2 Resource Server模块
  2. Spring Security 6配置范式变更,需显式声明oauth2ResourceServer配置,否则无法触发令牌校验流程

内容的提问来源于stack exchange,提问作者Gabriel Garcia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 03:55:18