Azure包com.microsoft.azure:adal4j:1.6.7依赖解析错误及排险咨询
依赖解析问题:Jcenter下线导致adal4j依赖无法获取的解决方案及风险分析
错误日志
Could not resolve all files for configuration ':lib-provider:compileClasspath'. > Could not resolve net.minidev:json-smart:[1.3.2,2.4.2]. Required by: project :lib-provider > com.microsoft.azure:adal4j:1.6.7 > com.nimbusds:oauth2-oidc-sdk:9.4
问题背景
由于Jcenter服务下线,Azure包com.microsoft.azure:adal4j:1.6.7的传递依赖net.minidev:json-smart:[1.3.2,2.4.2]无法被解析。目前通过添加exclude group: 'net.minidev', module: 'json-smart'解决了构建错误,但不确定该操作是否安全、是否会引发运行时问题,同时希望了解其他可行解决方案。
一、排除json-smart的风险分析
- 运行时崩溃风险极高:
oauth2-oidc-sdk:9.4明确依赖json-smart,该库主要用于OIDC协议的JSON格式响应解析、令牌处理等核心逻辑。如果你的业务代码触发了这些流程,直接排除会导致ClassNotFoundException或NoClassDefFoundError,引发运行时崩溃。 - 例外场景不可控:若当前代码未用到
adal4j中依赖oauth2-oidc-sdk的功能(比如仅用基础认证逻辑),可能暂时无异常,但后续代码迭代大概率会触发相关逻辑,风险无法提前预判。
二、其他可行解决方案
1. 升级/替换adal4j库
adal4j 1.6.7版本过于老旧,微软已推出替代方案:
- 若使用新Azure服务,直接替换为
azure-identity库(官方维护的新一代认证SDK); - 若需继续使用adal4j,升级到最新稳定版(新版本已将依赖迁移至Maven Central,且更新了传递依赖的版本范围,避免依赖解析问题)。
2. 强制指定json-smart版本并配置可用仓库
原依赖的版本范围是[1.3.2,2.4.2],可在项目依赖管理中强制指定具体版本,并确保构建脚本包含Maven Central仓库(该仓库包含所有json-smart版本):
Gradle示例:
repositories { mavenCentral() // 其他必要仓库 } dependencies { constraints { implementation 'net.minidev:json-smart:2.4.2' } }
Maven示例:
<repositories> <repository> <id>mavenCentral</id> <url>https://repo1.maven.org/maven2/</url> </repository> </repositories> <dependencyManagement> <dependencies> <dependency> <groupId>net.minidev</groupId> <artifactId>json-smart</artifactId> <version>2.4.2</version> </dependency> </dependencies> </dependencyManagement>
3. 本地引入json-smart jar包
若无法访问公共仓库,可从可靠渠道下载对应版本的json-smart jar包,放入项目本地lib目录后引入:
Gradle示例:
dependencies { implementation files('libs/json-smart-2.4.2.jar') }
Maven示例:
<dependency> <groupId>net.minidev</groupId> <artifactId>json-smart</artifactId> <version>2.4.2</version> <scope>system</scope> <systemPath>${project.basedir}/libs/json-smart-2.4.2.jar</systemPath> </dependency>
内容的提问来源于stack exchange,提问作者thesavvyguy
相关产品推荐
相关产品推荐

