You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Java代码编程式设置Spring OAuth2的userInfoUri

通过Java代码配置Spring OAuth2的userInfoUri

没问题,我来给你梳理几种纯Java代码设置userInfoUri的方式,完全不用依赖配置文件属性:

1. 传统Spring Security OAuth2配置(基于ResourceServerConfigurerAdapter)

如果你用的是Spring Security OAuth2经典版本(比如依赖spring-cloud-starter-oauth2),可以自定义ResourceServerConfigurerAdapter,直接注入并配置令牌服务对象:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter;
import org.springframework.security.oauth2.config.annotation.web.configurers.ResourceServerSecurityConfigurer;
import org.springframework.security.oauth2.provider.token.RemoteTokenServices;

@Configuration
public class ResourceServerConfig extends ResourceServerConfigurerAdapter {

    @Override
    public void configure(ResourceServerSecurityConfigurer resources) throws Exception {
        RemoteTokenServices tokenServices = new RemoteTokenServices();
        // 可选:设置令牌校验地址(如果需要令牌合法性校验)
        tokenServices.setCheckTokenEndpointUrl("https://your-auth-server/oauth/check_token");
        tokenServices.setClientId("your-client-id");
        tokenServices.setClientSecret("your-client-secret");
        // 重点:设置userInfoUri
        tokenServices.setUserInfoEndpointUrl("https://your-auth-server/userinfo");
        
        resources.tokenServices(tokenServices);
    }
}

2. Spring Security 5+ OAuth2资源服务器配置

如果是Spring Security 5.x及以上版本(依赖spring-security-oauth2-resource-server),配置更简洁,直接在SecurityFilterChain中设置:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwt -> jwt
                    .userInfoEndpoint(userInfo -> userInfo
                        // 直接配置userInfoUri
                        .userInfoUri("https://your-auth-server/userinfo")
                    )
                )
            );
        return http.build();
    }
}

3. 自定义配置类绑定属性(灵活管理配置)

如果想更灵活地管理配置参数,可以先自定义一个属性绑定类,再注入到配置逻辑中:

import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.context.annotation.Configuration;

@Configuration
@ConfigurationProperties(prefix = "security.oauth2.resource")
public class OAuth2ResourceProperties {
    private String userInfoUri;

    // getter & setter
    public String getUserInfoUri() {
        return userInfoUri;
    }

    public void setUserInfoUri(String userInfoUri) {
        this.userInfoUri = userInfoUri;
    }
}

然后在配置类中注入这个属性类,再设置到令牌服务:

@Configuration
public class ResourceServerConfig extends ResourceServerConfigurerAdapter {

    private final OAuth2ResourceProperties resourceProperties;

    // 构造注入属性类
    public ResourceServerConfig(OAuth2ResourceProperties resourceProperties) {
        this.resourceProperties = resourceProperties;
    }

    @Override
    public void configure(ResourceServerSecurityConfigurer resources) throws Exception {
        RemoteTokenServices tokenServices = new RemoteTokenServices();
        tokenServices.setUserInfoEndpointUrl(resourceProperties.getUserInfoUri());
        // 其他必要配置...
        resources.tokenServices(tokenServices);
    }
}

你可以根据自己的Spring版本和依赖情况,选择最适合的方式来配置userInfoUri~

内容的提问来源于stack exchange,提问作者Jose Martinez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:47:06