如何在Spring Boot服务类方法中获取OAuth客户端与Principal对象
实现方案
1 获取OAuth2User(Principal)
Spring Security默认会把当前请求的认证信息存储在SecurityContextHolder的ThreadLocal变量中,你可以直接在服务层任意位置取出:
// 取出当前认证信息 Authentication authentication = SecurityContextHolder.getContext().getAuthentication(); // 判断是否为OAuth2认证的用户 if (authentication instanceof OAuth2AuthenticationToken oauthToken) { OAuth2User oauth2User = oauthToken.getPrincipal(); // 可以直接获取用户的名称、权限、属性等信息 String username = oauth2User.getName(); Collection<? extends GrantedAuthority> authorities = oauth2User.getAuthorities(); Map<String, Object> attributes = oauth2User.getAttributes(); }
2 获取OAuth2AuthorizedClient
你需要先注入OAuth2AuthorizedClientService,结合上面拿到的OAuth2认证信息即可获取到客户端对象:
@Service public class YourService { @Autowired private OAuth2AuthorizedClientService authorizedClientService; public void yourMethod() { Authentication authentication = SecurityContextHolder.getContext().getAuthentication(); if (authentication instanceof OAuth2AuthenticationToken oauthToken) { // 取出客户端注册ID String clientRegistrationId = oauthToken.getClientRegistrationId(); // 加载授权客户端 OAuth2AuthorizedClient authorizedClient = authorizedClientService.loadAuthorizedClient( clientRegistrationId, oauthToken.getName() ); // 可以获取客户端名称、配置等信息 String clientName = authorizedClient.getClientRegistration().getClientName(); } } }
注意事项
- 该方案仅在请求线程中生效,因为
SecurityContext默认是线程隔离的ThreadLocal存储,如果需要在子线程中获取,需要配置Spring Security的安全上下文策略为MODE_INHERITABLETHREADLOCAL - 非请求上下文(如定时任务、异步消息处理等无用户请求的场景)无法通过该方式获取到对应的对象,需要自行传递或存储相关信息
内容的提问来源于stack exchange,提问作者zilcuanu
相关产品推荐
相关产品推荐

