升级Spring Boot至2.7.2替换WebSecurityConfigurerAdapter遇启动错误
解决方案:Spring Boot 2.7.2 升级后 SecurityFilterChain 与 WebSecurityConfigurerAdapter 冲突问题
问题根源
你遇到的BeanCreationException确实和@EnableOAuth2Sso有关。旧版本的spring-security-oauth2-autoconfigure中,@EnableOAuth2Sso会自动生成一个基于WebSecurityConfigurerAdapter的配置Bean,和你手动编写的SecurityFilterChain产生冲突,导致容器无法确定使用哪一套配置。
具体解决步骤
1. 替换@EnableOAuth2Sso为新版OAuth2配置
直接移除@EnableOAuth2Sso注解,改用@EnableOAuth2Client配合SecurityFilterChain实现SSO功能:
@Configuration @EnableOAuth2Client public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http // 配置请求授权规则 .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) // 启用OAuth2登录,替代原@EnableOAuth2Sso的SSO能力 .oauth2Login(oauth2 -> oauth2 // 可选:自定义登录页面路径,默认跳转到认证服务商登录页 .loginPage("/login") ); return http.build(); } }
2. 升级spring-security-oauth2-autoconfigure版本
你当前用的2.0.0.RELEASE适配Spring Boot早期版本,和2.7.2不兼容。在依赖管理文件中升级到对应版本:
<!-- Maven 示例 --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-oauth2-autoconfigure</artifactId> <version>2.7.2</version> </dependency>
3. 清理遗留的旧配置
检查项目中所有继承WebSecurityConfigurerAdapter的类,直接删除或重构为基于SecurityFilterChain的配置,确保容器中没有残留的旧配置Bean。
4. 配置OAuth2客户端信息
在application.yml(或application.properties)中填入你的认证服务商信息,示例如下:
spring: security: oauth2: client: registration: # 替换为你的认证服务商ID,比如github、google、企业自有OAuth2服务等 custom-oauth2: client-id: 你的客户端ID client-secret: 你的客户端密钥 scope: openid,profile,email authorization-grant-type: authorization_code redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}" provider: custom-oauth2: authorization-uri: https://你的认证服务商地址/oauth/authorize token-uri: https://你的认证服务商地址/oauth/token user-info-uri: https://你的认证服务商地址/userinfo user-name-attribute: sub # 根据服务商返回的用户ID字段调整
5. 自定义用户处理逻辑(可选)
如果之前用@EnableOAuth2Sso时有自定义用户信息转换、权限注入逻辑,可通过OAuth2UserService扩展实现:
@Bean public OAuth2UserService<OAuth2UserRequest, OAuth2User> customOAuth2UserService() { DefaultOAuth2UserService defaultService = new DefaultOAuth2UserService(); return request -> { OAuth2User oauth2User = defaultService.loadUser(request); // 自定义处理:比如转换为系统内部UserDetails对象、添加权限 Set<GrantedAuthority> authorities = new HashSet<>(oauth2User.getAuthorities()); authorities.add(new SimpleGrantedAuthority("ROLE_USER")); return new DefaultOAuth2User(authorities, oauth2User.getAttributes(), "sub"); }; }
内容的提问来源于stack exchange,提问作者Gokulkrishnan
相关产品推荐
相关产品推荐

