Spring Boot 2.0.1集成OAuth2报错:无法解析相关符号咨询
Hey there, let's break down why you're seeing those "Cannot resolve symbol" errors for @EnableResourceServer and other OAuth2-related features when moving from Spring Boot 1.5.x to 2.0.1, plus how to fix it.
Why This Happens
Spring Boot 2.0.x introduced major changes to OAuth2 support:
- The old
spring-security-oauth2module (which contained@EnableResourceServer,@EnableAuthorizationServer, etc.) was split up. - OAuth2 auto-configuration was moved out of the core Spring Boot starters into a separate dependency.
- Over time, the traditional OAuth2 setup (from 1.5.x) was marked deprecated in favor of a new, more flexible Spring Security 5+ OAuth2 model.
Solution 1: Stick with the Traditional 1.5.x-Style Configuration (Quick Fix)
If you want to keep using your existing OAuth2 setup without rewriting everything, you just need to add the correct dependency that includes the missing annotations and auto-configuration.
Add this to your Maven pom.xml:
<dependency> <groupId>org.springframework.security.oauth.boot</groupId> <artifactId>spring-security-oauth2-autoconfigure</artifactId> <version>2.0.1.RELEASE</version> </dependency>
Or for Gradle:
implementation 'org.springframework.security.oauth.boot:spring-security-oauth2-autoconfigure:2.0.1.RELEASE'
This dependency brings back the @EnableResourceServer, @EnableAuthorizationServer annotations and the auto-configuration logic you're used to from 1.5.x.
Solution 2: Migrate to the Modern Spring Security OAuth2 Model (Recommended)
The traditional setup is deprecated and will be removed in newer versions, so it's better to migrate to the current Spring Security OAuth2 implementation. Here's how:
Step 1: Update Dependencies
Remove the old spring-security-oauth2 and spring-security-oauth2-autoconfigure dependencies, then add these:
<dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-oauth2-resource-server</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-oauth2-jose</artifactId> </dependency>
Step 2: Replace @EnableResourceServer with a Security Filter Chain
Instead of using @EnableResourceServer, create a security configuration class with @EnableWebSecurity and define a SecurityFilterChain bean to configure your resource server. For JWT-based authentication, it might look like this:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class ResourceServerConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http // Require authentication for all requests .authorizeHttpRequests(auth -> auth.anyRequest().authenticated()) // Configure OAuth2 resource server with JWT validation .oauth2ResourceServer(oauth2 -> oauth2 .jwt(jwt -> jwt // Point to your authorization server's JWKS endpoint (adjust URL as needed) .jwkSetUri("http://localhost:8080/.well-known/jwks.json") ) ); return http.build(); } }
Step 3: Handling the Authorization Server
Spring Boot 2.0.x no longer provides official auto-configuration for authorization servers. If you need to keep your app acting as both resource and authorization server:
- For short-term use, you can still use the traditional
@EnableAuthorizationServerwith thespring-security-oauth2-autoconfiguredependency (from Solution 1). - For long-term maintenance, upgrade your Spring Boot version to 2.7.x or newer and use the standalone Spring Authorization Server project, which provides modern, supported authorization server functionality.
Important Note
Spring Boot 2.0.1 is extremely outdated—it's no longer receiving security patches or bug fixes. I strongly recommend upgrading to a supported version (like 2.7.x, the latest in the 2.x line, or 3.x if you're ready for Java 17+) to avoid security risks and get better OAuth2 support.
内容的提问来源于stack exchange,提问作者Denis Stephanov

