Spring Security项目能否同时支持JWT凭证登录与Google OAuth2登录?
Spring Security 同时实现JWT账号登录与Google OAuth2登录方案
核心思路
不用修改现有JWT校验逻辑,仅需要在Google OAuth2登录成功后,基于Google返回的用户身份信息生成你系统自有JWT,后续前端请求仍携带该自有JWT,原有校验逻辑可直接复用。
具体实现步骤
1. 引入OAuth2 Client依赖
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency>
2. 新增Google OAuth2配置
在application.yml中添加对应配置:
spring: security: oauth2: client: registration: google: client-id: 你在Google Cloud申请的client-id client-secret: 你在Google Cloud申请的client-secret scope: openid,profile,email redirect-uri: "{baseUrl}/login/oauth2/code/google" provider: google: user-name-attribute: email
3. 实现自定义OAuth2登录成功处理器
这个处理器负责在Google授权成功后,生成你系统的自有JWT:
@Component public class CustomOAuth2SuccessHandler implements AuthenticationSuccessHandler { @Autowired private MyUserDetailsService myUserDetailsService; @Autowired private JwtUtils jwtUtils; // 你现有生成JWT的工具类 @Autowired private PasswordEncoder passwordEncoder; @Override public void onAuthenticationSuccess(HttpServletRequest request, HttpServletResponse response, Authentication authentication) throws IOException, ServletException { OAuth2User oauth2User = (OAuth2User) authentication.getPrincipal(); String email = oauth2User.getAttribute("email"); // 查询系统是否存在对应用户 UserDetails userDetails; try { userDetails = myUserDetailsService.loadUserByUsername(email); } catch (UsernameNotFoundException e) { // 自动创建用户逻辑,可根据业务调整 User newUser = new User(); newUser.setUsername(email); newUser.setEmail(email); newUser.setNickname(oauth2User.getAttribute("name")); newUser.setPassword(passwordEncoder.encode(UUID.randomUUID().toString())); // 随机密码,OAuth2登录不会使用 userDetails = myUserDetailsService.saveNewUser(newUser); // 需要在MyUserDetailsService新增保存用户的方法 } // *如果你的业务要求OAuth2登录必须绑定已有账号,可在用户不存在时返回绑定指引,不自动创建新用户 // 生成自有JWT String token = jwtUtils.generateToken(userDetails); // 返回给前端,前后端分离场景可直接写回JSON,也可拼接参数重定向到前端页面 response.setContentType("application/json;charset=utf-8"); response.getWriter().write(JSON.toJSONString(Map.of("token", token))); } }
4. 修改Spring Security配置
修改你原有的configure方法,添加OAuth2相关配置:
@Autowired private CustomOAuth2SuccessHandler customOAuth2SuccessHandler; @Override protected void configure(HttpSecurity http) throws Exception { http.cors(); http.csrf().disable() .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS) .and(); http.authorizeRequests() // 放开登录、OAuth2相关接口权限 .antMatchers("/login", "/oauth2/**", "/login/oauth2/code/google").permitAll() .anyRequest().authenticated() // 新增OAuth2登录配置,指定自定义成功处理器 .and() .oauth2Login() .successHandler(customOAuth2SuccessHandler); http.addFilter(new JWTAuthenticationFilter(authenticationManager())); http.addFilter(new JWTValidationToken(authenticationManager())); }
流程验证
- 用户前端点击Google登录按钮,跳转至
/oauth2/authorization/google - 跳转Google授权页完成授权后,回调至服务端,触发自定义成功处理器
- 成功处理器返回你系统自有JWT给前端,后续所有请求前端携带该JWT即可,原有JWT校验逻辑完全不需要修改
内容的提问来源于stack exchange,提问作者roberto
相关产品推荐
相关产品推荐

