Spring Boot客户端无法跳转至Keycloak授权,遇循环跳转及类缺失错误
Root Cause
The java.lang.NoClassDefFoundError: java.security.acl.Group error stems from a conflict between the Keycloak Tomcat valve (auto-configured by the Spring Boot starter) and your Spring Security adapter setup. The valve attempts to use a deprecated Java class that's not properly accessible in Java 11, causing authentication failures and a redirect loop on /sso/login.
Fix Steps
1. Disable Keycloak Tomcat Valve
Add this property to your application.yml to turn off the conflicting Tomcat auto-configuration:
keycloak: auth-server-url: http://10.15.68.8:8484/auth realm: first-test resource: first-login public-client: true tomcat: enabled: false
2. Validate Keycloak Client Redirect URIs
Ensure your Keycloak client (first-login) in the first-test realm has valid redirect URIs configured:
- Open Keycloak admin console →
first-testrealm →Clients→first-login - Under
Valid Redirect URIs, addhttp://localhost:11002/*(or specific paths likehttp://localhost:11002/sso/login) - Save changes
3. Optional: Upgrade Keycloak Version
Keycloak 12.0.3 has minor Java 11 compatibility quirks. Upgrading to a newer stable version (e.g., 15.0.2) can resolve edge cases:
Update your pom.xml's Keycloak BOM version:
<dependency> <groupId>org.keycloak.bom</groupId> <artifactId>keycloak-adapter-bom</artifactId> <version>15.0.2</version> <type>pom</type> <scope>import</scope> </dependency>
4. Confirm Security Configuration
Your existing WebSecurityConfig is correct for most cases, but double-check:
NullAuthenticatedSessionStrategyis suitable for stateless applications (useRegisterSessionAuthenticationStrategyif you need server-side sessions)SimpleAuthorityMappercorrectly maps Keycloak roles to Spring Security authorities (already configured in your code)
Testing
After applying these changes:
- Restart your Spring Boot application
- Access
http://localhost:11002/api/adminagain - You should be redirected to Keycloak's login page at
http://10.15.68.8:8484/auth - Log in with a user assigned the
ADMINrole to access the endpoint
内容的提问来源于stack exchange,提问作者alexmntmnk

