You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级Spring Boot至2.7.2替换WebSecurityConfigurerAdapter遇启动错误

解决方案:Spring Boot 2.7.2 升级后 SecurityFilterChain 与 WebSecurityConfigurerAdapter 冲突问题

问题根源

你遇到的BeanCreationException确实和@EnableOAuth2Sso有关。旧版本的spring-security-oauth2-autoconfigure中,@EnableOAuth2Sso会自动生成一个基于WebSecurityConfigurerAdapter的配置Bean,和你手动编写的SecurityFilterChain产生冲突,导致容器无法确定使用哪一套配置。

具体解决步骤

1. 替换@EnableOAuth2Sso为新版OAuth2配置

直接移除@EnableOAuth2Sso注解,改用@EnableOAuth2Client配合SecurityFilterChain实现SSO功能:

@Configuration
@EnableOAuth2Client
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // 配置请求授权规则
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            // 启用OAuth2登录,替代原@EnableOAuth2Sso的SSO能力
            .oauth2Login(oauth2 -> oauth2
                // 可选:自定义登录页面路径,默认跳转到认证服务商登录页
                .loginPage("/login")
            );
        return http.build();
    }
}

2. 升级spring-security-oauth2-autoconfigure版本

你当前用的2.0.0.RELEASE适配Spring Boot早期版本,和2.7.2不兼容。在依赖管理文件中升级到对应版本:

<!-- Maven 示例 -->
<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-oauth2-autoconfigure</artifactId>
    <version>2.7.2</version>
</dependency>

3. 清理遗留的旧配置

检查项目中所有继承WebSecurityConfigurerAdapter的类,直接删除或重构为基于SecurityFilterChain的配置,确保容器中没有残留的旧配置Bean。

4. 配置OAuth2客户端信息

在application.yml(或application.properties)中填入你的认证服务商信息,示例如下:

spring:
  security:
    oauth2:
      client:
        registration:
          # 替换为你的认证服务商ID,比如github、google、企业自有OAuth2服务等
          custom-oauth2:
            client-id: 你的客户端ID
            client-secret: 你的客户端密钥
            scope: openid,profile,email
            authorization-grant-type: authorization_code
            redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
        provider:
          custom-oauth2:
            authorization-uri: https://你的认证服务商地址/oauth/authorize
            token-uri: https://你的认证服务商地址/oauth/token
            user-info-uri: https://你的认证服务商地址/userinfo
            user-name-attribute: sub # 根据服务商返回的用户ID字段调整

5. 自定义用户处理逻辑(可选)

如果之前用@EnableOAuth2Sso时有自定义用户信息转换、权限注入逻辑,可通过OAuth2UserService扩展实现:

@Bean
public OAuth2UserService<OAuth2UserRequest, OAuth2User> customOAuth2UserService() {
    DefaultOAuth2UserService defaultService = new DefaultOAuth2UserService();
    return request -> {
        OAuth2User oauth2User = defaultService.loadUser(request);
        // 自定义处理:比如转换为系统内部UserDetails对象、添加权限
        Set<GrantedAuthority> authorities = new HashSet<>(oauth2User.getAuthorities());
        authorities.add(new SimpleGrantedAuthority("ROLE_USER"));
        return new DefaultOAuth2User(authorities, oauth2User.getAttributes(), "sub");
    };
}

内容的提问来源于stack exchange,提问作者Gokulkrishnan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 21:54:14