Spring Security中JwtAccessTokenConverter和JwtTokenStore已弃用,替代方案是什么?
弃用原因
你用到的JwtAccessTokenConverter和JwtTokenStore属于已经停止维护的spring-security-oauth2遗留模块组件,从Spring Security 5.3版本开始,官方将OAuth2相关能力全部整合到Spring Security主项目中,旧的OAuth2模块整体被标记为废弃,不再维护更新。
官方推荐替代方案
官方推荐使用Spring Security原生提供的JwtDecoder(JWT解析校验)和JwtEncoder(JWT生成签发)组件替代原有功能,具体实现如下:
1. 依赖引入
首先移除旧的spring-security-oauth2相关依赖,按需引入官方新的starter:
- 只需要解析校验JWT的资源服务:引入
spring-boot-starter-oauth2-resource-server - 需要签发JWT的授权服务:引入
spring-boot-starter-oauth2-authorization-server
2. 基础配置替代
原有配置的替代实现代码如下:
package com.devsuperior.dscatalog.config; import org.springframework.beans.factory.annotation.Value; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.oauth2.jwt.JwtDecoder; import org.springframework.security.oauth2.jwt.NimbusJwtDecoder; import javax.crypto.spec.SecretKeySpec; @Configuration public class AppConfig { @Value("${jwt.secret:MY-JWT-SECRET}") private String jwtSecret; @Bean public BCryptPasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } // 替代原有JwtAccessTokenConverter、JwtTokenStore的JWT解析校验功能 @Bean public JwtDecoder jwtDecoder() { SecretKeySpec secretKey = new SecretKeySpec(jwtSecret.getBytes(), "HmacSHA256"); return NimbusJwtDecoder.withSecretKey(secretKey).build(); } }
3. 安全配置绑定
需要在安全过滤器链配置中开启JWT资源服务能力,绑定自定义的JwtDecoder:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class SecurityConfig { private final JwtDecoder jwtDecoder; public SecurityConfig(JwtDecoder jwtDecoder) { this.jwtDecoder = jwtDecoder; } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth // 按需配置公开接口路径 .anyRequest().authenticated() ) .oauth2ResourceServer(oauth2 -> oauth2 .jwt(jwtConfigurer -> jwtConfigurer.decoder(jwtDecoder)) ); return http.build(); } }
4. JWT生成场景替代
如果你需要手动生成JWT令牌,使用JwtEncoder组件即可:
@Bean public JwtEncoder jwtEncoder() { SecretKeySpec secretKey = new SecretKeySpec(jwtSecret.getBytes(), "HmacSHA256"); return new NimbusJwtEncoder((context) -> secretKey); }
内容的提问来源于stack exchange,提问作者gil-son
相关产品推荐
相关产品推荐

