SpringBoot3+SpringSecurity6微服务中checkToken校验实现问询
Spring Boot 3 + Spring Security 6 客户端Token校验实现方案
核心变化说明
Spring Security 6 里,旧版本的RemoteTokenServices已被标记为过时,官方推荐用 OAuth2 Resource Server 模块的原生能力实现令牌校验,主要分两种场景:JWT令牌本地校验、不透明令牌远程校验。
场景1:JWT令牌本地校验(推荐)
如果认证服务签发的是JWT令牌,客户端可直接本地校验签名、解析Claims,无需远程调用认证服务,性能更优。
依赖配置
确保项目引入OAuth2 Resource Server依赖:
<!-- Maven --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-resource-server</artifactId> </dependency>
配置类实现
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class ResourceServerConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .oauth2ResourceServer(oauth2 -> oauth2 .jwt(jwt -> jwt // 接入自定义JWT转换器(处理自定义Claims时启用) .jwtAuthenticationConverter(new JwtAccessTokenConverterCustom()) ) ); return http.build(); } }
配置文件(application.yml)
指定JWT签发者地址,Spring Security会自动获取公钥完成校验:
spring: security: oauth2: resourceserver: jwt: issuer-uri: ${authUrl} # 认证服务根地址,例:http://localhost:8080/auth
场景2:不透明令牌(Opaque Token)远程校验
如果认证服务签发的是无法本地解析的不透明令牌,需配置令牌 introspection 端点完成远程校验。
依赖配置
同样引入spring-boot-starter-oauth2-resource-server依赖。
配置类实现
import org.springframework.beans.factory.annotation.Value; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.oauth2.server.resource.introspection.NimbusOpaqueTokenIntrospector; import org.springframework.security.oauth2.server.resource.introspection.OpaqueTokenIntrospector; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class ResourceServerConfig { private final String authUrl; private final String oauthClient; private final String oauthClientSecret; // 构造注入配置参数 public ResourceServerConfig( @Value("${auth.url}") String authUrl, @Value("${oauth.client-id}") String oauthClient, @Value("${oauth.client-secret}") String oauthClientSecret) { this.authUrl = authUrl; this.oauthClient = oauthClient; this.oauthClientSecret = oauthClientSecret; } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .oauth2ResourceServer(oauth2 -> oauth2 .opaqueToken(token -> token .introspector(opaqueTokenIntrospector()) ) ); return http.build(); } @Bean public OpaqueTokenIntrospector opaqueTokenIntrospector() { // 配置令牌校验端点,替代旧的RemoteTokenServices return new NimbusOpaqueTokenIntrospector( authUrl + "/oauth2/introspect", oauthClient, oauthClientSecret ); } }
注意事项
- 认证服务需开启令牌 introspection 端点,Spring Authorization Server 默认已开启
/oauth2/introspect - 确保客户端(资源服务)在认证服务中被配置为允许调用该校验接口
旧代码失效原因
RemoteTokenServices属于Spring Security 6的遗留组件,官方不再维护,核心逻辑已整合到OAuth2 Resource Server模块- Spring Security 6配置范式变更,需显式声明
oauth2ResourceServer配置,否则无法触发令牌校验流程
内容的提问来源于stack exchange,提问作者Gabriel Garcia
相关产品推荐
相关产品推荐

