Spring Boot资源服务器JWT无iss声明的验证绕过方案咨询
问题描述
请求Spring Boot资源服务器验证JWT时,始终报错:
Bearer error="invalid_token", error_description="An error occurred while attempting to decode the Jwt: The iss claim is not valid", error_uri="https://tools.ietf.org/html/rfc6750#section-3.1"
已在application.properties中配置Issuer URI:
spring.security.oauth2.resourceserver.jwt.issuer-uri=<IssuerUri>
但实际JWT并不包含与该Issuer URI匹配的iss声明,想知道如何在Spring Boot中覆盖issuer URI的验证逻辑,之前尝试在WebSecurityConfigurerAdapter里找关闭验证的选项但没找到。
解决方案
可以通过自定义JWT验证器来跳过或修改iss声明的验证逻辑,具体步骤如下:
移除配置文件中的issuer-uri配置
先删除application.properties里的spring.security.oauth2.resourceserver.jwt.issuer-uri配置项,避免默认的iss验证逻辑自动生效。自定义JwtDecoder Bean
创建配置类,自定义JwtDecoder来替换默认实现,在其中添加自定义验证规则:import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.oauth2.jwt.Jwt; import org.springframework.security.oauth2.jwt.JwtDecoder; import org.springframework.security.oauth2.jwt.NimbusJwtDecoder; import org.springframework.security.oauth2.core.OAuth2TokenValidator; import org.springframework.security.oauth2.core.OAuth2TokenValidatorResult; @Configuration public class JwtConfig { @Bean public JwtDecoder jwtDecoder() { // 替换为你的JWKS端点地址,若用对称密钥则改用NimbusJwtDecoder.withSecretKey方法 NimbusJwtDecoder decoder = NimbusJwtDecoder.withJwkSetUri("<你的JWKS地址>").build(); // 自定义验证器,直接跳过iss声明验证 OAuth2TokenValidator<Jwt> customIssValidator = jwt -> { // 可在此添加其他必要验证,比如exp、nbf等 return OAuth2TokenValidatorResult.success(); }; decoder.setJwtValidator(customIssValidator); return decoder; } }保留其他默认验证(可选)
若只想跳过iss验证,保留令牌过期、生效时间等默认校验,可组合验证器:import org.springframework.security.oauth2.jwt.JwtValidators; import org.springframework.security.oauth2.core.DelegatingOAuth2TokenValidator; // ... 其他代码 OAuth2TokenValidator<Jwt> defaultValidator = JwtValidators.createDefault(); OAuth2TokenValidator<Jwt> customIssValidator = jwt -> OAuth2TokenValidatorResult.success(); // 组合默认验证与自定义iss验证 OAuth2TokenValidator<Jwt> combinedValidator = new DelegatingOAuth2TokenValidator<>(defaultValidator, customIssValidator); decoder.setJwtValidator(combinedValidator);注意事项
- 务必替换代码中
<你的JWKS地址>为实际的密钥配置端点或对称密钥。 - 跳过
iss验证会降低令牌安全性,仅建议在特定场景下使用,优先考虑让JWT生成方添加正确的iss声明。
- 务必替换代码中
内容的提问来源于stack exchange,提问作者Yanni2
相关产品推荐
相关产品推荐

