You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AngularJS对接Azure AD搭配Spring Boot实现身份验证是否有参考示例?

Azure AD适配AngularJS+Spring Boot独立部署架构的身份验证方案

完全存在适配该架构的可行落地方案,无需调整现有两套应用的独立部署模式,采用OAuth 2.0 授权码流(搭配PKCE扩展适配AngularJS公开客户端特性)即可实现统一身份校验。

前端AngularJS侧接入步骤

  • 引入适配AngularJS生态的ADAL JS v1官方库,无需大幅重构存量代码,仅需在根模块完成Azure AD基础配置即可,示例代码如下:
// app.js 根模块配置
angular.module('yourExistingApp', ['AdalAngular'])
.config(['$httpProvider', 'adalAuthenticationServiceProvider', function($httpProvider, adalProvider) {
  adalProvider.init(
    {
      tenant: '替换为你的Azure AD租户ID',
      clientId: '替换为Azure AD注册的前端应用客户端ID',
      redirectUri: window.location.origin,
      cacheLocation: 'localStorage'
    },
    $httpProvider
  );
}]);
  • 需要登录后访问的路由,在路由配置中新增requireADLogin: true属性即可,ADAL库会自动拦截未登录请求跳转到Azure AD登录页,登录成功后自动将access_token注入所有发往后端的HTTP请求的Authorization头,无需修改现有接口请求逻辑。

后端Spring Boot侧接入步骤

  • 引入Spring Security OAuth2资源服务依赖,Maven配置示例如下:
<dependency>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
</dependency>
  • 在application.yml中添加Azure AD JWT校验配置,示例如下:
spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          issuer-uri: https://login.microsoftonline.com/替换为你的Azure AD租户ID/v2.0
  • 接口权限控制直接使用Spring Security原生注解即可,例如@PreAuthorize("hasAuthority('SCOPE_自定义API权限标识')"),Token有效性校验逻辑已被框架封装,无需自行实现。

前置配置说明

你需要提前在Azure AD后台完成两个应用注册:

  • 注册前端应用,配置为公开客户端,设置正确的重定向URI
  • 注册后端应用,暴露自定义API权限,给前端应用授予该API的访问权限

内容的提问来源于stack exchange,提问作者would_like_to_be_anon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 20:27:03