You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Authorization Server 0.3.1多客户端注册异常求助

问题分析与解决

异常原因

报错信息Registered client must be unique. Found duplicate client secret for identifier: appclientes明确指向:存在两个clientId为appclientes的注册客户端,触发了Spring Security OAuth2中InMemoryRegisteredClientRepository的唯一性校验——它要求所有客户端的clientId必须唯一。

你代码里虽用了client1Id和client2Id两个变量,但实际运行时这两个变量的值大概率一致(均为appclientes),导致生成的两个RegisteredClient对象的clientId重复。另外代码存在笔误:第一个客户端的tokenSettings引用了未定义的tokenBackofficeSettings,应替换为前面定义的tokenClient1Settings,该笔误会导致第一个客户端使用错误的Token配置。

解决步骤

  1. 确认配置参数唯一性:检查client1Id和client2Id对应的配置项(如application.yml/properties),确保两者值完全不同,示例:
    client1.id=appclientes
    client2.id=appclientes2
    
  2. 修正代码笔误:将第一个客户端的tokenSettings(tokenBackofficeSettings)改为tokenSettings(tokenClient1Settings)。
  3. 保证客户端clientId唯一:确保每个RegisteredClient通过.clientId(...)设置的标识符互不重复,主键ID(withId(...))可与clientId相同,但多个客户端的clientId不能重复。

修正后的完整代码:

@Bean
public RegisteredClientRepository registeredClientRepository() {        
    TokenSettings tokenClient1Settings = TokenSettings.builder()
            .accessTokenTimeToLive(Duration.ofSeconds(client1AccessTokenValiditySeconds))
            .build();
    
    RegisteredClient registeredClient1 = RegisteredClient.withId(client1Id)
            .clientId(client1Id)
            .clientSecret("{noop}" + client1Secret)
            .authorizationGrantType(AuthorizationGrantType.PASSWORD)
            .clientAuthenticationMethod(ClientAuthenticationMethod.CLIENT_SECRET_BASIC)
            .tokenSettings(tokenClient1Settings)
            .scope("read")
            .scope("write")
            .build();
    
    TokenSettings tokenClient2Settings = TokenSettings.builder()
            .accessTokenTimeToLive(Duration.ofSeconds(client2AccessTokenValiditySeconds))
            .build();
    
    RegisteredClient registeredClient2 = RegisteredClient.withId(client2Id)
            .clientId(client2Id)
            .clientSecret("{noop}" + client2Secret)
            .authorizationGrantType(AuthorizationGrantType.PASSWORD)
            .clientAuthenticationMethod(ClientAuthenticationMethod.CLIENT_SECRET_BASIC)
            .tokenSettings(tokenClient2Settings)
            .scope("read")
            .scope("write")
            .build();
    
    return new InMemoryRegisteredClientRepository(List.of(registeredClient1, registeredClient2));
}

内容的提问来源于stack exchange,提问作者Juanjo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 15:55:33