Spring Boot应用Oauth2认证出现Bad Credentials错误求助
Hey there, let's break down how to troubleshoot this "invalid_grant / Bad credentials" error in your Spring Boot 1.5.9 OAuth2 app connected to SQL Server. While you suspect a Hibernate @Table annotation naming bug, let's cover all angles step by step:
1. Rule Out Basic OAuth2 Configuration Issues First
"Bad credentials" almost always ties back to credential validation failures, so let's eliminate these first:
- Double-check that the
usernameandpasswordin your/oauth/tokenrequest match exactly what's stored in your SQL Server database. Critical note: If your user passwords are encrypted (e.g., with BCrypt), ensure the plaintext password in your request can be correctly matched against the encrypted value in the DB. - Verify your
client_idandclient_secretmatch what's configured in your OAuth2ClientDetailsService(check for typos, case sensitivity, or special characters). - Confirm the
passwordgrant type is allowed for your client—make sureauthorizedGrantTypesincludes "password" in your client configuration.
2. Validate Hibernate @Table Annotation Naming for SQL Server
If the above checks pass, let's dive into your suspicion about table naming:
- SQL Server is often case-sensitive (depending on your database collation settings). If your
@Tableannotation specifies a table name that doesn't match the actual case in the database (e.g.,@Table(name = "users")vs. a DB table namedUsers), Hibernate will fail to find the user data, leading to credential validation errors. - Enable Hibernate SQL logging to see exactly what queries are being run. Add these lines to your
application.properties:
After restarting your app, call thelogging.level.org.hibernate.SQL=DEBUG logging.level.org.hibernate.type.descriptor.sql.BasicBinder=TRACE/oauth/tokenendpoint again. Check the logs to see if the user lookup SQL is targeting the correct table, and if there are any "table not found" errors. - If your table name is a SQL Server reserved keyword (like
User), you'll need to wrap it in brackets in the@Tableannotation:@Table(name = "[User]")to avoid parsing issues.
3. Check Your UserDetailsService Implementation
Make sure your user lookup logic is working as expected:
- If you've implemented a custom
UserDetailsService, verify that your query correctly fetches the username, encrypted password, enabled status, and authorities from the database. A missing or incorrect WHERE clause here would cause no user to be found, triggering the "Bad credentials" error. - If you're using the default
JdbcUserDetailsManager, confirm your query statements are tailored to SQL Server's syntax. For example:
Ensure the table and column names here match exactly what's in your SQL Server database.jdbcUserDetailsManager.setUsersByUsernameQuery( "SELECT username, password, enabled FROM users WHERE username = ?" ); jdbcUserDetailsManager.setAuthoritiesByUsernameQuery( "SELECT username, authority FROM authorities WHERE username = ?" );
4. Verify Database Connection & Permissions
- Confirm that the database user your Spring Boot app uses has read access to the user and client tables (if using
JdbcClientDetailsService). A lack of permissions would prevent Hibernate from fetching the necessary data. - Double-check your database connection properties to ensure you're connecting to the correct SQL Server instance and database.
Start with the OAuth2 credential checks first—they're the most likely cause—but don't skip verifying the Hibernate table mapping if those don't resolve the issue. The SQL logs will be your best friend here to pinpoint exactly where the lookup is failing.
内容的提问来源于stack exchange,提问作者Shitija

