You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级至Spring Boot 2后@EnableOAuth2Sso注解缺失问题咨询

解决Spring Boot 2.0.0中@EnableOAuth2Sso被移除的迁移方案

我完全懂你升级时碰到这个问题的困惑——这个注解在Spring Boot 2.0里确实被移除了,而且初期的迁移文档确实没把替代方案讲得太明白。下面是具体的迁移思路和实现步骤:

核心替代方向:用Spring Security OAuth2的新配置体系

从Spring Boot 2.0开始,官方更推荐基于编程式配置的方式来实现SSO,核心是结合@EnableWebSecurity和OAuth2客户端的专属配置,替代原来@EnableOAuth2Sso的封装能力。

步骤1:调整依赖

确保你的项目依赖里包含这两个核心starter,替换掉原来和@EnableOAuth2Sso绑定的旧依赖:

<!-- Maven示例 -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-oauth2-client</artifactId>
</dependency>

步骤2:配置OAuth2服务商信息

在application.yml或application.properties里配置你的授权服务商(比如GitHub、Google或者自定义授权服务器)的信息:

spring:
  security:
    oauth2:
      client:
        registration:
          github:
            client-id: 你的客户端ID
            client-secret: 你的客户端密钥
            scope: read:user,user:email
        provider:
          github:
            authorization-uri: https://github.com/login/oauth/authorize
            token-uri: https://github.com/login/oauth/access_token
            user-info-uri: https://api.github.com/user
            user-name-attribute: login

步骤3:编写安全配置类

创建一个安全配置类,通过oauth2Login()配置来实现原来@EnableOAuth2Sso的SSO效果:

import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .anyRequest().authenticated()
                .and()
            .oauth2Login() // 这是替代@EnableOAuth2Sso的核心配置
                .loginPage("/oauth2/authorization/github"); // 指定授权跳转的入口路径
    }
}

如果是Spring Boot 2.7及以上版本,官方更推荐无适配器的写法:

import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .oauth2Login(oauth2 -> oauth2
                .loginPage("/oauth2/authorization/github")
            );
        return http.build();
    }
}

补充说明:为什么@EnableOAuth2Sso会被移除?

官方的设计思路是把原来@EnableOAuth2Sso封装的“客户端+资源服务器”组合能力拆解开,让开发者可以更灵活地控制安全规则——比如你可以单独配置客户端逻辑,也可以同时搭配资源服务器的配置,避免原来注解的黑盒式封装带来的扩展性问题。

内容的提问来源于stack exchange,提问作者romeara

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:55:42