求助:已配置Grant Type仍提示InvalidRequestException缺失授权类型
Hey there, let's dig into this frustrating error you're hitting—nothing's more annoying than swearing you configured the grant type correctly, only to get that "Missing grant type" message. Let's break down the most likely fixes based on your scenario and the code snippet you shared.
1. First: Verify Your Client's Authorized Grant Types Are Explicitly Configured
Looking at your OAuth2Config snippet, you’ve set up fields for token validity and autowired the AuthenticationManager, but the critical piece of configuring allowed grant types for your client is missing.
You need to override the configure(ClientDetailsServiceConfigurer clients) method to define which grant types your client is permitted to use. Here’s how to add that (adjust for in-memory or database storage as needed):
@Override public void configure(ClientDetailsServiceConfigurer clients) throws Exception { // Example for in-memory client storage (use JDBC for production) clients.inMemory() .withClient("your-client-id") .secret("{noop}your-client-secret") // Use {noop} for plaintext; use password encoder in production .authorizedGrantTypes("password", "refresh_token") // List ALL grant types you need here .scopes("read", "write") .accessTokenValiditySeconds(accessTokenValiditySeconds) .refreshTokenValiditySeconds(refreshTokenValiditySeconds); }
If you’re using a database to store client details, double-check that the authorized_grant_types column for your client includes the exact grant type you’re trying to use (e.g., password, authorization_code).
2. Check How You’re Sending the Request to the Token Endpoint
OAuth2’s /oauth/token endpoint expects parameters to be sent as application/x-www-form-urlencoded, not JSON. Even if you’ve configured the grant type correctly, a malformed request will trigger this error.
Correct Request Example (using curl):
curl -X POST -u your-client-id:your-client-secret \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=password&username=your-username&password=your-password&scope=read" \ http://localhost:8080/oauth/token
Key checks here:
- Ensure the
grant_typeparameter is spelled correctly (no typos!) - Confirm the
Content-Typeheader is set properly - Include client credentials (via Basic Auth or form parameters) if your client requires authentication (the default behavior)
3. Confirm Your Endpoints Configuration Includes Required Beans
If you’re using the password grant type, you must explicitly attach your AuthenticationManager to the authorization server endpoints. Add this override to your OAuth2Config class:
@Override public void configure(AuthorizationServerEndpointsConfigurer endpoints) throws Exception { endpoints.authenticationManager(authenticationManager); }
Since you’ve already autowired the AuthenticationManager, this ensures the server can validate user credentials for password grant requests.
4. Double-Check Client Authentication Settings
If your client is configured to require authentication (default), make sure you’re sending valid client credentials with your request. You can either:
- Use Basic Auth (like the curl example above, with
-u client-id:client-secret) - Include
client_idandclient_secretas form parameters in your request
If you intentionally want a public client (no authentication), add autoApprove(true) and secret(null) to your client configuration—but this is not recommended for production.
内容的提问来源于stack exchange,提问作者Kunle Ajiboye

