Spring Boot集成Springfox Swagger2 2.9.2版本OAuth授权功能失效求助
Swagger2 2.9.2版本集成Azure AD OAuth2授权失败问题说明
我已经添加Swagger依赖并启用相关功能,可正常查看所有API,但接口授权功能无法正常使用。
依赖配置
我使用的Swagger版本依赖如下:
<dependency> <groupId>io.springfox</groupId> <artifactId>springfox-swagger2</artifactId> <version>2.9.2</version> </dependency> <dependency> <groupId>io.springfox</groupId> <artifactId>springfox-swagger-ui</artifactId> <version>2.9.2</version> </dependency>
Swagger配置代码
@Configuration @EnableSwagger2 public class SwaggerConfig { @Value("${security.oauth2.client.client-id}") public String CLIENT_ID; @Value("${security.oauth2.client.client-secret}") public String CLIENT_SECRET; public String AUTH_SERVER = "https://login.microsoftonline.com/common/oauth2/v2.0"; @Bean public Docket swaggerConfiguration() { return new Docket(DocumentationType.SWAGGER_2) .select() .apis(RequestHandlerSelectors.basePackage("edu.mayo.ima.ccs.rpc_backend.controller")) .paths(PathSelectors.any()) .build() .securitySchemes(Arrays.asList(securityScheme())) .securityContexts(Arrays.asList(securityContext())) .apiInfo(getApiInfo()); } @Bean public SecurityConfiguration security() { return SecurityConfigurationBuilder.builder() .clientId(CLIENT_ID) .clientSecret(CLIENT_SECRET) .scopeSeparator(" ") .useBasicAuthenticationWithAccessCodeGrant(true) .build(); } private SecurityScheme securityScheme() { GrantType grantType = new AuthorizationCodeGrantBuilder() .tokenEndpoint(new TokenEndpoint(AUTH_SERVER + "/token", "oauthtoken")) .tokenRequestEndpoint( new TokenRequestEndpoint(AUTH_SERVER + "/authorize", CLIENT_ID, CLIENT_SECRET)) .build(); SecurityScheme oauth = new OAuthBuilder().name("spring_oauth") .grantTypes(Arrays.asList(grantType)) .scopes(Arrays.asList(scopes())) .build(); return oauth; } private ApiInfo getApiInfo() { return new ApiInfo( "Protocol Catalag ", "", "1.0.0", "", null, "", "", Collections.emptyList() ); } private SecurityContext securityContext() { return SecurityContext.builder() .securityReferences( Arrays.asList(new SecurityReference("spring_oauth", scopes()))) .forPaths(PathSelectors.any()) .build(); } private AuthorizationScope[] scopes() { AuthorizationScope[] scopes = { new AuthorizationScope("access_as_user", "access for application") }; return scopes; } }
问题表现
上述配置部署后,Swagger可正常展示所有API,但点击授权按钮进行授权时会报错,授权流程相关截图如下:


问题排查与修复方案
以下是可直接落地的修复步骤:
1. 修正Azure AD适配配置
当前配置存在两处不符合Azure AD OAuth2规则的错误:
- 若你使用的是单租户应用,必须将
AUTH_SERVER中的common替换为你Azure应用对应的租户ID;若为多租户应用,需要在授权请求中额外添加resource参数指定要访问的API资源标识 useBasicAuthenticationWithAccessCodeGrant参数设为true不符合Azure AD要求,Azure AD获取Token时不支持客户端凭证通过Basic auth传递,必须放在请求体中,该参数需改为false
2. 调整SecurityConfiguration配置
修改security()方法代码如下:
@Bean public SecurityConfiguration security() { return SecurityConfigurationBuilder.builder() .clientId(CLIENT_ID) .clientSecret(CLIENT_SECRET) .scopeSeparator(" ") .useBasicAuthenticationWithAccessCodeGrant(false) .build(); }
3. 检查Azure应用的回调地址配置
必须在Azure AD应用注册的Web重定向URI列表中,添加Swagger UI的回调地址{你的服务访问根地址}/swagger-ui.html,且地址必须和授权请求中的redirect_uri参数完全一致,否则Azure AD会直接返回授权错误
4. 修正Scope配置
你当前使用的access_as_userscope,完整格式应为api://{你的API应用客户端ID}/access_as_user,必须和你在Azure应用中公开的Scope完全匹配,Scope配置错误会直接导致授权请求被拒绝
5. 版本兼容修复(可选)
springfox 2.9.2自带的swagger-ui存在OAuth2授权的已知bug,若上述配置修改后仍报错,可替换为修复后的swagger-ui版本:
<dependency> <groupId>io.springfox</groupId> <artifactId>springfox-swagger2</artifactId> <version>2.9.2</version> </dependency> <!-- 排除原有低版本ui --> <dependency> <groupId>io.springfox</groupId> <artifactId>springfox-swagger-ui</artifactId> <version>2.9.2</version> <exclusions> <exclusion> <groupId>io.springfox</groupId> <artifactId>swagger-ui</artifactId> </exclusion> </exclusions> </dependency> <!-- 引入修复后的ui版本 --> <dependency> <groupId>io.springfox</groupId> <artifactId>swagger-ui</artifactId> <version>2.10.5</version> </dependency>
内容的提问来源于stack exchange,提问作者Pradeep
相关产品推荐
相关产品推荐

