Spring Boot适配Azure AD与Google双OAuth2认证登录方案咨询
实现Azure AD与Google双登录的解决方案
1. 修改安全配置类
不再继承AadWebSecurityConfigurerAdapter,改用标准Spring Security OAuth2客户端配置,摆脱Azure强制跳转的限制,同时支持多认证提供商:
@EnableWebSecurity @EnableGlobalMethodSecurity(prePostEnabled = true) public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .oauth2Login() // 启用OAuth2登录,自动识别所有配置的客户端 .defaultSuccessUrl("/", true); // 登录成功后默认跳转首页 } }
2. 调整application配置文件
将Azure AD的认证信息迁移到标准OAuth2客户端配置节点下,和Google配置统一管理,移除原spring.cloud.azure.active-directory相关配置:
spring: security: oauth2: client: registration: azure-ad: # 自定义Azure AD的注册标识 client-id: 你的Azure客户端ID client-secret: 你的Azure客户端密钥 authorization-grant-type: authorization_code redirect-uri: "{baseUrl}/login/oauth2/code/azure-ad" scope: openid, profile, email client-name: Azure Active Directory google: client-id: 你的Google客户端ID client-secret: 你的Google客户端密钥 scope: openid, profile, email provider: azure-ad: # 配置Azure AD的认证服务端点 authorization-uri: https://login.microsoftonline.com/你的租户ID/oauth2/v2.0/authorize token-uri: https://login.microsoftonline.com/你的租户ID/oauth2/v2.0/token user-info-uri: https://graph.microsoft.com/oidc/userinfo user-name-attribute: name
关键说明
- 配置完成后,访问需要认证的接口时,Spring Security会自动生成登录选择页面,提供Azure AD和Google两个登录选项。
- 如果需要自定义登录页面,可以创建前端页面并添加两个跳转链接:
/oauth2/authorization/azure-ad和/oauth2/authorization/google,然后在配置中通过.loginPage("/自定义登录页路径")指定。
内容的提问来源于stack exchange,提问作者telebog
相关产品推荐
相关产品推荐

