升级至Spring Boot 2后@EnableOAuth2Sso注解缺失问题咨询
解决Spring Boot 2.0.0中@EnableOAuth2Sso被移除的迁移方案
我完全懂你升级时碰到这个问题的困惑——这个注解在Spring Boot 2.0里确实被移除了,而且初期的迁移文档确实没把替代方案讲得太明白。下面是具体的迁移思路和实现步骤:
核心替代方向:用Spring Security OAuth2的新配置体系
从Spring Boot 2.0开始,官方更推荐基于编程式配置的方式来实现SSO,核心是结合@EnableWebSecurity和OAuth2客户端的专属配置,替代原来@EnableOAuth2Sso的封装能力。
步骤1:调整依赖
确保你的项目依赖里包含这两个核心starter,替换掉原来和@EnableOAuth2Sso绑定的旧依赖:
<!-- Maven示例 --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency>
步骤2:配置OAuth2服务商信息
在application.yml或application.properties里配置你的授权服务商(比如GitHub、Google或者自定义授权服务器)的信息:
spring: security: oauth2: client: registration: github: client-id: 你的客户端ID client-secret: 你的客户端密钥 scope: read:user,user:email provider: github: authorization-uri: https://github.com/login/oauth/authorize token-uri: https://github.com/login/oauth/access_token user-info-uri: https://api.github.com/user user-name-attribute: login
步骤3:编写安全配置类
创建一个安全配置类,通过oauth2Login()配置来实现原来@EnableOAuth2Sso的SSO效果:
import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .oauth2Login() // 这是替代@EnableOAuth2Sso的核心配置 .loginPage("/oauth2/authorization/github"); // 指定授权跳转的入口路径 } }
如果是Spring Boot 2.7及以上版本,官方更推荐无适配器的写法:
import org.springframework.context.annotation.Bean; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .oauth2Login(oauth2 -> oauth2 .loginPage("/oauth2/authorization/github") ); return http.build(); } }
补充说明:为什么@EnableOAuth2Sso会被移除?
官方的设计思路是把原来@EnableOAuth2Sso封装的“客户端+资源服务器”组合能力拆解开,让开发者可以更灵活地控制安全规则——比如你可以单独配置客户端逻辑,也可以同时搭配资源服务器的配置,避免原来注解的黑盒式封装带来的扩展性问题。
内容的提问来源于stack exchange,提问作者romeara
相关产品推荐
相关产品推荐

