Spring Boot 3迁移后OAuth2登录循环并报client_secret必填异常
Spring Boot 3 OAuth2登录无限循环,提示client_secret is must异常
将应用从Spring Boot 2.7.5迁移至3.x版本后,登录时出现登录页面无限循环问题,调试后捕获到如下异常:
org.springframework.security.oauth2.core.OAuth2AuthorizationException: [invalid_request] client_secret is must
该异常出现在DefaultAuthorizationCodeTokenResponseClient.getTokenResponse(OAuth2AuthorizationCodeGrantRequest authorizationCodeGrantRequest)方法中。
SecurityFilterChain配置
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .csrf(csrf -> csrf .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()) .ignoringRequestMatchers(new CsrfIgnoreRequestMatcher()) ) .headers(headers -> headers .cacheControl().disable() .frameOptions().disable() ) //Access configuration .authorizeHttpRequests(authorizeRequest -> authorizeRequest .requestMatchers(HttpMethod.OPTIONS).permitAll() .requestMatchers( LOGIN, LOGOUT).permitAll() ) .exceptionHandling(exceptionHandling -> exceptionHandling .authenticationEntryPoint(new Http401UnauthorizedEntryPoint()) ) //######## OAUTH2-Login configuration ######## .oauth2Login(oAuth2Login -> oAuth2Login .authorizationEndpoint(authorizationEndpoint -> authorizationEndpoint .baseUri(LOGIN) .authorizationRequestResolver(customOAuth2AuthorizationRequestResolver) ) .loginProcessingUrl(LOGIN) .userInfoEndpoint(userInfo -> userInfo.userAuthoritiesMapper(new RoleMapper())) ) .logout(logout -> logout .logoutUrl(LOGOUT) .invalidateHttpSession(true) .logoutSuccessHandler(new HttpStatusReturningLogoutSuccessHandler(HttpStatus.OK)) ); return http.build(); }
安全相关application.yaml配置
spring: security: oauth2: client: provider: customIdp: authorization-uri: https://sso.company/app/login jwk-set-uri: https://sso.company/oauth/nam/keys token-uri: https://sso.company/oauth/nam/token?resourceServer=IdentityProviderRSUE& user-info-uri: https://sso.company/oauth/nam/userinfo user-name-attribute: cn customIdpSso: authorization-uri: https://sso.company/app/login token-uri: ${spring.security.oauth2.client.provider.customIdp.tokenUri} user-info-uri: ${spring.security.oauth2.client.provider.customIdp.userInfoUri} user-name-attribute: ${spring.security.oauth2.client.provider.customIdp.userNameAttribute} registration: customIdp: authorizationGrantType: authorization_code clientAuthenticationMethod: basic client-id: custom-client-id clientName: Custom client-secret: custom-client-secret provider: customIdp redirect-uri: \"{baseUrl}/api/login\" scope: portal customIdpSso: authorizationGrantType: ${spring.security.oauth2.client.registration.customIdp.authorizationGrantType} clientAuthenticationMethod: ${spring.security.oauth2.client.registration.customIdp.clientAuthenticationMethod} clientId: ${spring.security.oauth2.client.registration.customIdp.clientId} clientName: ${spring.security.oauth2.client.registration.customIdp.clientName} client-secret: ${spring.security.oauth2.client.registration.customIdp.clientSecret} provider: customIdpnosso redirect-uri: ${spring.security.oauth2.client.registration.customIdp.redirect-uri} scope: ${spring.security.oauth2.client.registration.customIdp.scope}
注:已完成Spring Boot新版本迁移,不再使用WebSecurityConfigurerAdapter,如需更多信息可补充。
内容的提问来源于stack exchange,提问作者Martin Krumov
相关产品推荐
相关产品推荐

