You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从OAuth2获取附加信息列表?服务类中获取自定义Token增强列表方法

嘿,我来帮你搞定这个问题!你已经成功通过自定义CustomTokenEnhancer把companies列表塞进令牌的附加信息里了,现在要在服务类里取出这个列表,有几种实用的方式,我给你一步步说明:

方法1:从SecurityContext直接获取认证信息

Spring Security会把当前用户的认证信息存在SecurityContext里,你可以从这里拿到OAuth2认证对象,进而提取令牌的附加信息:

import org.springframework.security.core.context.SecurityContextHolder;
import org.springframework.security.oauth2.provider.OAuth2Authentication;
import org.springframework.security.oauth2.provider.token.DefaultOAuth2AccessToken;
import java.util.List;
import java.util.Collections;

// 在你的服务类方法中
public List<String> getCurrentUserCompanies() {
    // 获取当前的OAuth2认证对象
    OAuth2Authentication authentication = (OAuth2Authentication) 
        SecurityContextHolder.getContext().getAuthentication();
    
    // 从认证对象中取出访问令牌
    DefaultOAuth2AccessToken accessToken = (DefaultOAuth2AccessToken) 
        authentication.getUserAuthentication().getDetails();
    
    // 提取附加信息里的companies列表,记得做空值判断避免报错
    if (accessToken.getAdditionalInformation() != null 
        && accessToken.getAdditionalInformation().containsKey("companies")) {
        return (List<String>) accessToken.getAdditionalInformation().get("companies");
    }
    
    return Collections.emptyList();
}
方法2:用@AuthenticationPrincipal注解(资源服务器场景)

如果你的服务是资源服务器,并且用的是JWT格式的令牌,可以直接用@AuthenticationPrincipal注解注入Jwt对象,然后读取附加信息:

import org.springframework.security.oauth2.jwt.Jwt;
import org.springframework.security.core.annotation.AuthenticationPrincipal;
import java.util.List;
import java.util.Collections;

// 在你的服务类方法中(或者控制器方法里)
public List<String> getCompaniesFromJwt(@AuthenticationPrincipal Jwt jwt) {
    // 从Jwt的claims中直接取出companies
    List<String> companies = jwt.getClaim("companies");
    return companies != null ? companies : Collections.emptyList();
}

⚠️ 注意:这种方式需要确保你的JWT转换器已经配置正确,能把自定义的附加信息解析到Jwt的claims里。

方法3:通过TokenStore查询令牌(适合需要手动传token的场景)

如果你的项目用了TokenStore(比如内存存储、数据库存储令牌),可以通过前端传来的令牌值,从TokenStore中读取完整的令牌对象,再提取附加信息:

import org.springframework.security.oauth2.provider.token.TokenStore;
import org.springframework.security.oauth2.provider.token.DefaultOAuth2AccessToken;
import java.util.List;
import java.util.Collections;

@Autowired
private TokenStore tokenStore;

public List<String> getCompaniesByToken(String tokenValue) {
    OAuth2AccessToken accessToken = tokenStore.readAccessToken(tokenValue);
    
    if (accessToken instanceof DefaultOAuth2AccessToken) {
        DefaultOAuth2AccessToken defaultToken = (DefaultOAuth2AccessToken) accessToken;
        if (defaultToken.getAdditionalInformation() != null 
            && defaultToken.getAdditionalInformation().containsKey("companies")) {
            return (List<String>) defaultToken.getAdditionalInformation().get("companies");
        }
    }
    
    return Collections.emptyList();
}
小提示

不管用哪种方式,都一定要做空值判断!避免因为令牌里没有附加信息或者类型不匹配导致空指针异常。

内容的提问来源于stack exchange,提问作者Eniss

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:37:02