Spring Boot OAuth中InMemoryTokenStore始终为空问题求助
Ah, I see the issue here! This is actually behavior by design with the implicit grant type in OAuth 2.0, not a bug in your configuration. Let me break this down for you:
Implicit Grant Type's Core Behavior
The implicit flow is specifically built for public clients (like single-page JavaScript apps) that can’t securely store a client secret. Instead of generating an authorization code first (like theauthorization_codeflow), the authorization server directly returns theaccess_tokenas part of the redirect URL to the client.Crucially, the authorization server does NOT persist or store this token server-side—that’s exactly why your
storeAccessToken()method is never called, and yourInMemoryTokenStorestays empty. This is intentional: the implicit flow is meant to be lightweight and stateless from the server’s perspective.Compare to Other Grant Types
If you temporarily switch your client to use theauthorization_codegrant type (you’ll need to add.secret("your-client-secret")to your client config), you’ll immediately see thestoreAccessToken()method get triggered. That’s because in this flow, the server first issues an authorization code, then exchanges it for an access token—at which point it needs to store the token for future validation.If You Really Need to Store Implicit Tokens
While it goes against the intended design of the implicit flow, if you must track these tokens server-side for a specific use case, you’ll need to customize the flow:- Create a custom
ImplicitGrantTokenGranterthat extends the default implementation. - Override the
grant()method to calltokenStore.storeAccessToken()right after generating the token. - Register this custom granter with your
AuthorizationServerEndpointsConfigurer.
Keep in mind though: implicit tokens are designed to be short-lived, and storing them adds unnecessary server overhead. It’s generally better to stick with the flow’s intended behavior unless you have a clear, justified reason to deviate.
- Create a custom
To confirm your setup is working correctly, just check that the access_token is present in the redirect URL’s fragment—if it is, your implicit flow is functioning as expected, and the empty InMemoryTokenStore is completely normal.
内容的提问来源于stack exchange,提问作者dasteini

