You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security中JwtAccessTokenConverter和JwtTokenStore已弃用,替代方案是什么?

弃用原因

你用到的JwtAccessTokenConverter和JwtTokenStore属于已经停止维护的spring-security-oauth2遗留模块组件,从Spring Security 5.3版本开始,官方将OAuth2相关能力全部整合到Spring Security主项目中,旧的OAuth2模块整体被标记为废弃,不再维护更新。

官方推荐替代方案

官方推荐使用Spring Security原生提供的JwtDecoder(JWT解析校验)和JwtEncoder(JWT生成签发)组件替代原有功能,具体实现如下:

1. 依赖引入

首先移除旧的spring-security-oauth2相关依赖,按需引入官方新的starter:

  • 只需要解析校验JWT的资源服务:引入spring-boot-starter-oauth2-resource-server
  • 需要签发JWT的授权服务:引入spring-boot-starter-oauth2-authorization-server

2. 基础配置替代

原有配置的替代实现代码如下:

package com.devsuperior.dscatalog.config;

import org.springframework.beans.factory.annotation.Value;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.oauth2.jwt.JwtDecoder;
import org.springframework.security.oauth2.jwt.NimbusJwtDecoder;

import javax.crypto.spec.SecretKeySpec;

@Configuration
public class AppConfig {

    @Value("${jwt.secret:MY-JWT-SECRET}")
    private String jwtSecret;

    @Bean
    public BCryptPasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
    
    // 替代原有JwtAccessTokenConverter、JwtTokenStore的JWT解析校验功能
    @Bean
    public JwtDecoder jwtDecoder() {
        SecretKeySpec secretKey = new SecretKeySpec(jwtSecret.getBytes(), "HmacSHA256");
        return NimbusJwtDecoder.withSecretKey(secretKey).build();
    }
}

3. 安全配置绑定

需要在安全过滤器链配置中开启JWT资源服务能力,绑定自定义的JwtDecoder:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    private final JwtDecoder jwtDecoder;

    public SecurityConfig(JwtDecoder jwtDecoder) {
        this.jwtDecoder = jwtDecoder;
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                // 按需配置公开接口路径
                .anyRequest().authenticated()
            )
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwtConfigurer -> jwtConfigurer.decoder(jwtDecoder))
            );
        return http.build();
    }
}

4. JWT生成场景替代

如果你需要手动生成JWT令牌,使用JwtEncoder组件即可:

@Bean
public JwtEncoder jwtEncoder() {
    SecretKeySpec secretKey = new SecretKeySpec(jwtSecret.getBytes(), "HmacSHA256");
    return new NimbusJwtEncoder((context) -> secretKey);
}

内容的提问来源于stack exchange,提问作者gil-son

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 04:06:04