You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot OAuth2资源服务器:公开路径配置失效问题求助

解决Spring Boot Security OAuth2中/public路径仍需认证的问题

我来帮你排查这个问题——你遇到的核心原因是ResourceServer的配置优先级高于WebSecurity,而且你的配置里存在几个关键问题:

问题分析

  1. ResourceServer配置覆盖WebSecurity:在Spring Security OAuth2中,ResourceServerConfigurerAdapter的配置会优先于WebSecurityConfigurerAdapter生效。你只在SecurityConfig里配置了/public/**允许匿名访问,但ResourceServer层面没有做对应的配置,所以依然会要求认证。
  2. 重复的@EnableResourceServer注解:你的AppConfig类上也加了@EnableResourceServer,这会导致多个ResourceServer实例被创建,引发配置冲突。
  3. ResourceServerConfig缺少路径授权配置:当前的ResourceServerConifig(注意类名拼写错误,应该是ResourceServerConfig)没有配置HttpSecurity来放行公开路径。

解决方案

1. 修复AppConfig,移除重复的@EnableResourceServer

把AppConfig上的@EnableResourceServer注解去掉,因为已经在ResourceServerConfig里启用了资源服务器:

@Configuration
public class AppConfig {
    @Bean
    public TokenStore tokenStore() {
        return new JwtTokenStore((jwtTokenEnhancer()));
    }

    @Bean
    protected JwtAccessTokenConverter jwtTokenEnhancer() {
        JwtAccessTokenConverter converter = new JwtAccessTokenConverter();
        Resource resource = new ClassPathResource("public.cert");
        String publicKey = null;
        try {
            publicKey = new String(FileCopyUtils.copyToByteArray(resource.getInputStream()));
        } catch (IOException e) {
            throw new RuntimeException(e);
        }
        converter.setVerifierKey(publicKey);
        return converter;
    }
}

2. 完善ResourceServerConfig,添加路径授权配置

首先修正类名拼写(ResourceServerConifig → ResourceServerConfig),然后添加configure(HttpSecurity http)方法,明确放行/public/**路径:

@EnableResourceServer
@Configuration
public class ResourceServerConfig extends ResourceServerConfigurerAdapter {
    @Autowired
    private TokenStore tokenStore;
    private final AppConfig appConfig;
    private AuthenticationManager authenticationManager;

    @Autowired
    public ResourceServerConfig(AuthenticationManager authenticationManager, AppConfig appConfig) {
        this.authenticationManager = authenticationManager;
        this.appConfig = appConfig;
    }

    @Bean
    @Primary
    ResourceServerTokenServices tokenServices() {
        DefaultTokenServices defaultTokenServices = new DefaultTokenServices();
        defaultTokenServices.setTokenStore(tokenStore);
        defaultTokenServices.setSupportRefreshToken(true);
        return defaultTokenServices;
    }

    @Override
    public void configure(ResourceServerSecurityConfigurer resources) throws Exception {
        resources.tokenServices(tokenServices());
    }

    // 新增:配置路径访问规则
    @Override
    public void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
                .antMatchers("/public/**").permitAll() // 公开路径无需认证
                .anyRequest().authenticated(); // 其他所有路径需要认证
    }
}

3. 保留SecurityConfig的配置(可选)

你的SecurityConfig配置可以保留,但因为ResourceServer优先级更高,它的配置会覆盖WebSecurity的部分规则。不过保留它也不会有冲突,后续如果有非资源服务器的WebSecurity规则可以在这里配置。

验证修改

重启应用后,访问/public路径应该就能直接返回Hello World!,不需要携带认证令牌了。

内容的提问来源于stack exchange,提问作者KellyM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:27:30