如何创建兼容spring.security.oauth2.resourceserver.jwt.jwk-set-uri的认证服务器端点
如何创建兼容spring.security.oauth2.resourceserver.jwt.jwk-set-uri的认证服务器端点
嘿,看你已经在搭基于JWT的认证服务器了,用的是Spring Boot 3.2.2和io.jsonwebtoken库对吧?要让它和spring.security.oauth2.resourceserver.jwt.jwk-set-uri兼容,关键是要在你的认证服务器上暴露一个JWK(JSON Web Key)集合端点——资源服务器靠这个端点获取公钥,才能验证你签发的JWT签名。
先确认你的基础父依赖配置是这样的:
<parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.2.2</version> <relativePath/> <!-- lookup parent from repository --> </parent>
接下来分几步实现:
1. 添加必要依赖
最省心的方式是引入Spring Security OAuth2 Authorization Server starter,它自带了JWK端点的完整支持,不用自己手动造轮子:
<dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-oauth2-authorization-server</artifactId> <version>1.2.2</version> <!-- 这个版本适配Spring Boot 3.2.2 --> </dependency>
2. 配置JWK端点与密钥
在Spring Security配置类里启用JWK端点,同时生成或配置密钥对(用于JWT的签名和验证):
@Configuration @EnableWebSecurity public class SecurityConfig { // 配置授权服务器的安全过滤链,启用JWK端点 @Bean public SecurityFilterChain authorizationServerSecurityFilterChain(HttpSecurity http) throws Exception { OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(http); // 指定JWK集合端点的路径,默认就是/oauth2/jwks,也可以自定义 http.getConfigurer(OAuth2AuthorizationServerConfigurer.class) .jwt(jwt -> jwt.jwkSetUri("/oauth2/jwks")); return http.build(); } // 提供JWK源,这里生成一个RSA密钥对用于JWT签名 @Bean public JWKSource<SecurityContext> jwkSource() { RSAKey rsaKey = generateRsaKey(); JWKSet jwkSet = new JWKSet(rsaKey); return (jwkSelector, securityContext) -> jwkSelector.select(jwkSet); } // 生成RSA密钥对 private static RSAKey generateRsaKey() { KeyPair keyPair = generateRsaKeyPair(); RSAPublicKey publicKey = (RSAPublicKey) keyPair.getPublic(); RSAPrivateKey privateKey = (RSAPrivateKey) keyPair.getPrivate(); return new RSAKey.Builder(publicKey) .privateKey(privateKey) .keyID(UUID.randomUUID().toString()) .build(); } private static KeyPair generateRsaKeyPair() { try { KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA"); keyPairGenerator.initialize(2048); return keyPairGenerator.generateKeyPair(); } catch (NoSuchAlgorithmException ex) { throw new IllegalStateException("生成RSA密钥对失败", ex); } } }
3. 配置资源服务器的JWK端点地址
在你的资源服务器配置文件(比如application.properties)里指定认证服务器的JWK端点:
spring.security.oauth2.resourceserver.jwt.jwk-set-uri=http://你的认证服务器地址/oauth2/jwks
如果你不想用官方的Authorization Server starter,想基于io.jsonwebtoken自己实现JWK端点,那需要手动创建一个Controller,把你的公钥转换成JWK格式的JSON返回。不过这种方式需要自己处理密钥的序列化、格式校验,容易踩坑,还是官方starter更靠谱。
内容来源于stack exchange
相关产品推荐
相关产品推荐

