Spring Boot OAuth2资源服务器:公开路径配置失效问题求助
解决Spring Boot Security OAuth2中/public路径仍需认证的问题
我来帮你排查这个问题——你遇到的核心原因是ResourceServer的配置优先级高于WebSecurity,而且你的配置里存在几个关键问题:
问题分析
- ResourceServer配置覆盖WebSecurity:在Spring Security OAuth2中,
ResourceServerConfigurerAdapter的配置会优先于WebSecurityConfigurerAdapter生效。你只在SecurityConfig里配置了/public/**允许匿名访问,但ResourceServer层面没有做对应的配置,所以依然会要求认证。 - 重复的@EnableResourceServer注解:你的
AppConfig类上也加了@EnableResourceServer,这会导致多个ResourceServer实例被创建,引发配置冲突。 - ResourceServerConfig缺少路径授权配置:当前的
ResourceServerConifig(注意类名拼写错误,应该是ResourceServerConfig)没有配置HttpSecurity来放行公开路径。
解决方案
1. 修复AppConfig,移除重复的@EnableResourceServer
把AppConfig上的@EnableResourceServer注解去掉,因为已经在ResourceServerConfig里启用了资源服务器:
@Configuration public class AppConfig { @Bean public TokenStore tokenStore() { return new JwtTokenStore((jwtTokenEnhancer())); } @Bean protected JwtAccessTokenConverter jwtTokenEnhancer() { JwtAccessTokenConverter converter = new JwtAccessTokenConverter(); Resource resource = new ClassPathResource("public.cert"); String publicKey = null; try { publicKey = new String(FileCopyUtils.copyToByteArray(resource.getInputStream())); } catch (IOException e) { throw new RuntimeException(e); } converter.setVerifierKey(publicKey); return converter; } }
2. 完善ResourceServerConfig,添加路径授权配置
首先修正类名拼写(ResourceServerConifig → ResourceServerConfig),然后添加configure(HttpSecurity http)方法,明确放行/public/**路径:
@EnableResourceServer @Configuration public class ResourceServerConfig extends ResourceServerConfigurerAdapter { @Autowired private TokenStore tokenStore; private final AppConfig appConfig; private AuthenticationManager authenticationManager; @Autowired public ResourceServerConfig(AuthenticationManager authenticationManager, AppConfig appConfig) { this.authenticationManager = authenticationManager; this.appConfig = appConfig; } @Bean @Primary ResourceServerTokenServices tokenServices() { DefaultTokenServices defaultTokenServices = new DefaultTokenServices(); defaultTokenServices.setTokenStore(tokenStore); defaultTokenServices.setSupportRefreshToken(true); return defaultTokenServices; } @Override public void configure(ResourceServerSecurityConfigurer resources) throws Exception { resources.tokenServices(tokenServices()); } // 新增:配置路径访问规则 @Override public void configure(HttpSecurity http) throws Exception { http.authorizeRequests() .antMatchers("/public/**").permitAll() // 公开路径无需认证 .anyRequest().authenticated(); // 其他所有路径需要认证 } }
3. 保留SecurityConfig的配置(可选)
你的SecurityConfig配置可以保留,但因为ResourceServer优先级更高,它的配置会覆盖WebSecurity的部分规则。不过保留它也不会有冲突,后续如果有非资源服务器的WebSecurity规则可以在这里配置。
验证修改
重启应用后,访问/public路径应该就能直接返回Hello World!,不需要携带认证令牌了。
内容的提问来源于stack exchange,提问作者KellyM
相关产品推荐
相关产品推荐

