You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为特定URI配置对接Ping SSO的OAuth2ResourceServer

针对特定URI配置OAuth2资源服务器对接Ping SSO

原生Spring Security方案(推荐)

Spring Security原生支持按URI段配置不同安全规则,无需额外自定义过滤器。你可以通过requestMatchers或securityMatcher限定OAuth2认证仅作用于目标客户端路径(如/client1/**),其他路径暂时允许匿名访问。

配置示例(基于你的原有JWT配置)

http
    .authorizeHttpRequests(auth -> auth
        // 仅对/client1/**路径要求认证
        .requestMatchers("/client1/**").authenticated()
        // 其余所有路径允许匿名访问
        .anyRequest().permitAll()
    )
    .oauth2ResourceServer(oauth2ResourceServer ->
        oauth2ResourceServer.jwt(jwt -> jwt.jwtAuthenticationConverter(getJwtAuthenticationConverter()))
            .authenticationEntryPoint(unauthorizedHandler)
            .accessDeniedHandler(unauthorizedHandler)
    );

如果需要更清晰的拆分配置(比如不同客户端路径单独配置),可以用多段securityMatcher:

// 仅对/client1/**应用OAuth2认证
http
    .securityMatcher("/client1/**")
    .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
    .oauth2ResourceServer(oauth2ResourceServer ->
        oauth2ResourceServer.jwt(jwt -> jwt.jwtAuthenticationConverter(getJwtAuthenticationConverter()))
            .authenticationEntryPoint(unauthorizedHandler)
            .accessDeniedHandler(unauthorizedHandler)
    );

// 其他路径(如/client2/**)允许匿名
http
    .securityMatcher("/client2/**")
    .authorizeHttpRequests(auth -> auth.anyRequest().permitAll());

关于自定义过滤器与认证提供者的问题

你提到的addFilterBefore和自定义AbstractUserDetailsAuthenticationProvider并非必须——对接Ping SSO的标准JWT认证时,Spring Security原生的JwtAuthenticationProvider已能满足需求。只有当你需要额外的认证逻辑(比如JWT校验后从数据库加载用户详情)时,才需要自定义实现:

1. 自定义认证提供者示例

@Component
public class CustomJwtAuthProvider extends AbstractUserDetailsAuthenticationProvider {

    private final JwtDecoder jwtDecoder;

    public CustomJwtAuthProvider(JwtDecoder jwtDecoder) {
        this.jwtDecoder = jwtDecoder;
    }

    @Override
    protected void additionalAuthenticationChecks(UserDetails userDetails, UsernamePasswordAuthenticationToken auth) throws AuthenticationException {
        // 补充额外校验逻辑(如权限匹配)
    }

    @Override
    protected UserDetails retrieveUser(String username, UsernamePasswordAuthenticationToken auth) throws AuthenticationException {
        // 解码JWT并加载用户信息
        Jwt jwt = jwtDecoder.decode((String) auth.getCredentials());
        String userId = jwt.getClaim("sub");
        
        // 替换为你的用户查询逻辑
        return User.withUsername(userId)
            .password("") // JWT认证无需密码,留空即可
            .authorities(extractAuthorities(jwt))
            .build();
    }

    private Collection<? extends GrantedAuthority> extractAuthorities(Jwt jwt) {
        // 从Ping SSO返回的JWT中提取权限(示例:从roles字段获取)
        List<String> roles = jwt.getClaimAsStringList("roles");
        return roles.stream().map(SimpleGrantedAuthority::new).collect(Collectors.toList());
    }
}

2. 替换资源服务器默认认证提供者

http
    .securityMatcher("/client1/**")
    .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
    .oauth2ResourceServer(oauth2ResourceServer ->
        oauth2ResourceServer.authenticationProvider(customJwtAuthProvider)
            .authenticationEntryPoint(unauthorizedHandler)
            .accessDeniedHandler(unauthorizedHandler)
    );

注意:自定义认证提供者需要自行处理JWT解码与校验,仅在原生方案无法满足需求时使用。

关键配置要点

  • 确保JwtDecoder正确指向Ping SSO的JWKS端点:
@Bean
public JwtDecoder jwtDecoder() {
    return JwtDecoders.fromIssuerLocation("https://你的Ping SSO域名/oauth2/token");
}
  • 路径匹配顺序:Spring Security按配置顺序匹配路径,优先匹配的规则生效,需确保目标路径的规则排在前面。

内容的提问来源于stack exchange,提问作者JMJ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 22:20:41