You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot资源服务器JWT无iss声明的验证绕过方案咨询

问题描述

请求Spring Boot资源服务器验证JWT时,始终报错:

Bearer error="invalid_token", error_description="An error occurred while attempting to decode the Jwt: The iss claim is not valid", error_uri="https://tools.ietf.org/html/rfc6750#section-3.1"

已在application.properties中配置Issuer URI:

spring.security.oauth2.resourceserver.jwt.issuer-uri=<IssuerUri> 

但实际JWT并不包含与该Issuer URI匹配的iss声明,想知道如何在Spring Boot中覆盖issuer URI的验证逻辑,之前尝试在WebSecurityConfigurerAdapter里找关闭验证的选项但没找到。

解决方案

可以通过自定义JWT验证器来跳过或修改iss声明的验证逻辑,具体步骤如下:

  • 移除配置文件中的issuer-uri配置
    先删除application.properties里的spring.security.oauth2.resourceserver.jwt.issuer-uri配置项,避免默认的iss验证逻辑自动生效。

  • 自定义JwtDecoder Bean
    创建配置类,自定义JwtDecoder来替换默认实现,在其中添加自定义验证规则:

    import org.springframework.context.annotation.Bean;
    import org.springframework.context.annotation.Configuration;
    import org.springframework.security.oauth2.jwt.Jwt;
    import org.springframework.security.oauth2.jwt.JwtDecoder;
    import org.springframework.security.oauth2.jwt.NimbusJwtDecoder;
    import org.springframework.security.oauth2.core.OAuth2TokenValidator;
    import org.springframework.security.oauth2.core.OAuth2TokenValidatorResult;
    
    @Configuration
    public class JwtConfig {
    
        @Bean
        public JwtDecoder jwtDecoder() {
            // 替换为你的JWKS端点地址,若用对称密钥则改用NimbusJwtDecoder.withSecretKey方法
            NimbusJwtDecoder decoder = NimbusJwtDecoder.withJwkSetUri("<你的JWKS地址>").build();
            
            // 自定义验证器,直接跳过iss声明验证
            OAuth2TokenValidator<Jwt> customIssValidator = jwt -> {
                // 可在此添加其他必要验证,比如exp、nbf等
                return OAuth2TokenValidatorResult.success();
            };
    
            decoder.setJwtValidator(customIssValidator);
            return decoder;
        }
    }
    
  • 保留其他默认验证(可选)
    若只想跳过iss验证,保留令牌过期、生效时间等默认校验,可组合验证器:

    import org.springframework.security.oauth2.jwt.JwtValidators;
    import org.springframework.security.oauth2.core.DelegatingOAuth2TokenValidator;
    
    // ... 其他代码
    OAuth2TokenValidator<Jwt> defaultValidator = JwtValidators.createDefault();
    OAuth2TokenValidator<Jwt> customIssValidator = jwt -> OAuth2TokenValidatorResult.success();
    
    // 组合默认验证与自定义iss验证
    OAuth2TokenValidator<Jwt> combinedValidator = new DelegatingOAuth2TokenValidator<>(defaultValidator, customIssValidator);
    decoder.setJwtValidator(combinedValidator);
    
  • 注意事项

    • 务必替换代码中<你的JWKS地址>为实际的密钥配置端点或对称密钥。
    • 跳过iss验证会降低令牌安全性,仅建议在特定场景下使用,优先考虑让JWT生成方添加正确的iss声明。

内容的提问来源于stack exchange,提问作者Yanni2

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 18:20:43