You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何创建兼容spring.security.oauth2.resourceserver.jwt.jwk-set-uri的认证服务器端点

如何创建兼容spring.security.oauth2.resourceserver.jwt.jwk-set-uri的认证服务器端点

嘿,看你已经在搭基于JWT的认证服务器了,用的是Spring Boot 3.2.2和io.jsonwebtoken库对吧?要让它和spring.security.oauth2.resourceserver.jwt.jwk-set-uri兼容,关键是要在你的认证服务器上暴露一个JWK(JSON Web Key)集合端点——资源服务器靠这个端点获取公钥,才能验证你签发的JWT签名。

先确认你的基础父依赖配置是这样的:

<parent>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-parent</artifactId>
    <version>3.2.2</version>
    <relativePath/> <!-- lookup parent from repository -->
</parent>

接下来分几步实现:

1. 添加必要依赖

最省心的方式是引入Spring Security OAuth2 Authorization Server starter,它自带了JWK端点的完整支持,不用自己手动造轮子:

<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-oauth2-authorization-server</artifactId>
    <version>1.2.2</version> <!-- 这个版本适配Spring Boot 3.2.2 -->
</dependency>

2. 配置JWK端点与密钥

在Spring Security配置类里启用JWK端点,同时生成或配置密钥对(用于JWT的签名和验证):

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    // 配置授权服务器的安全过滤链,启用JWK端点
    @Bean
    public SecurityFilterChain authorizationServerSecurityFilterChain(HttpSecurity http) throws Exception {
        OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(http);
        // 指定JWK集合端点的路径,默认就是/oauth2/jwks,也可以自定义
        http.getConfigurer(OAuth2AuthorizationServerConfigurer.class)
            .jwt(jwt -> jwt.jwkSetUri("/oauth2/jwks"));
        return http.build();
    }

    // 提供JWK源,这里生成一个RSA密钥对用于JWT签名
    @Bean
    public JWKSource<SecurityContext> jwkSource() {
        RSAKey rsaKey = generateRsaKey();
        JWKSet jwkSet = new JWKSet(rsaKey);
        return (jwkSelector, securityContext) -> jwkSelector.select(jwkSet);
    }

    // 生成RSA密钥对
    private static RSAKey generateRsaKey() {
        KeyPair keyPair = generateRsaKeyPair();
        RSAPublicKey publicKey = (RSAPublicKey) keyPair.getPublic();
        RSAPrivateKey privateKey = (RSAPrivateKey) keyPair.getPrivate();
        return new RSAKey.Builder(publicKey)
            .privateKey(privateKey)
            .keyID(UUID.randomUUID().toString())
            .build();
    }

    private static KeyPair generateRsaKeyPair() {
        try {
            KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA");
            keyPairGenerator.initialize(2048);
            return keyPairGenerator.generateKeyPair();
        } catch (NoSuchAlgorithmException ex) {
            throw new IllegalStateException("生成RSA密钥对失败", ex);
        }
    }
}

3. 配置资源服务器的JWK端点地址

在你的资源服务器配置文件(比如application.properties)里指定认证服务器的JWK端点:

spring.security.oauth2.resourceserver.jwt.jwk-set-uri=http://你的认证服务器地址/oauth2/jwks

如果你不想用官方的Authorization Server starter,想基于io.jsonwebtoken自己实现JWK端点,那需要手动创建一个Controller,把你的公钥转换成JWK格式的JSON返回。不过这种方式需要自己处理密钥的序列化、格式校验,容易踩坑,还是官方starter更靠谱。

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.08 13:19:53