You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring OAuth2资源服务器对接Google授权服务器遇401错误求助

Spring OAuth2资源服务器对接Google时401无效令牌问题排查

我正在实现一个以Google作为OAuth授权服务器的Spring OAuth2资源服务器,参考相关指南配置后,能通过Postman获取到Google的JWT,但调用接口始终返回401错误,已确认请求头中Bearer关键字与token之间有空格。

配置信息

application.yml

spring:
  security:
    oauth2:
      client:
        registration:
          google:
            client-id: *******.apps.googleusercontent.com
            client-secret:********_
            scope:
              - email
              - profile
              - openid
      resourceserver:
        jwt:
          issuer-uri: https://accounts.google.com
          jwk-set-uri: https://www.googleapis.com/oauth2/v3/certs

SecurityConfig.java

@Configuration
public class SecurityConfig {

    @Bean
    protected SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
                .httpBasic().disable()
                .formLogin(AbstractHttpConfigurer::disable)
                .csrf(AbstractHttpConfigurer::disable)
                .authorizeRequests(authorize -> authorize
                                .anyRequest().authenticated()
                )
                .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt)
                .sessionManagement(sessionManagement ->
                        sessionManagement.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
        ;
        return http.build();
    }
}

UserController.java

@RestController
@RequestMapping("/user")
@RequiredArgsConstructor
public class UserController {

    @GetMapping("/{id}")
    public void getUser(@PathVariable String id) {
        System.out.println("Id: " + id);
    }
}

错误现象

Postman返回401状态码,响应头包含:

Bearer error="invalid_token", error_description="Invalid token", error_uri="https://tools.ietf.org/html/rfc6750#section-3.1"

令牌验证情况

通过Google令牌信息验证工具查看该令牌,结果显示正常:

"issued_to": "263667859573-jve8vplquh7qn4ft7aaj1t1m9boaq5d6.apps.googleusercontent.com",
  "audience": "263667859573-jve8vplquh7qn4ft7aaj1t1m9boaq5d6.apps.googleusercontent.com",
  "user_id": "112897290372529438679",
  "scope": "openid https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/userinfo.email",
  "expires_in": 3296,
  "email": "javier@email.com",
  "verified_email": true,
  "access_type": "online"

排查方向

  • 确认令牌类型:你可能传递的是Access Token而非ID Token。Spring OAuth2资源服务器的JWT验证逻辑默认适配ID Token的声明规则,Access Token的结构和字段与ID Token差异较大,需确保获取并传递的是ID Token。
  • 核对audience匹配:检查application.yml中的client-id是否与令牌返回的audience完全一致,包括字符大小写、后缀细节,任何拼写错误都会导致验证失败。
  • 开启调试日志:添加日志配置打印Spring Security的调试信息,能定位令牌验证失败的具体原因:
    logging:
      level:
        org.springframework.security: DEBUG
    
    重启服务后重新调用接口,查看日志中JWT验证环节的细节,比如签名失败、声明不匹配等。
  • 验证issuer声明:用JWT解析工具查看令牌的iss字段,确认其值为https://accounts.google.com,与配置的issuer-uri完全一致。
  • 检查公钥获取情况:确认服务能正常访问https://www.googleapis.com/oauth2/v3/certs获取公钥,若存在网络限制或缓存问题,尝试重启服务刷新公钥缓存。

内容的提问来源于stack exchange,提问作者Javier Sánchez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 12:10:27