如何通过Java代码编程式设置Spring OAuth2的userInfoUri
通过Java代码配置Spring OAuth2的userInfoUri
没问题,我来给你梳理几种纯Java代码设置userInfoUri的方式,完全不用依赖配置文件属性:
1. 传统Spring Security OAuth2配置(基于ResourceServerConfigurerAdapter)
如果你用的是Spring Security OAuth2经典版本(比如依赖spring-cloud-starter-oauth2),可以自定义ResourceServerConfigurerAdapter,直接注入并配置令牌服务对象:
import org.springframework.context.annotation.Configuration; import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter; import org.springframework.security.oauth2.config.annotation.web.configurers.ResourceServerSecurityConfigurer; import org.springframework.security.oauth2.provider.token.RemoteTokenServices; @Configuration public class ResourceServerConfig extends ResourceServerConfigurerAdapter { @Override public void configure(ResourceServerSecurityConfigurer resources) throws Exception { RemoteTokenServices tokenServices = new RemoteTokenServices(); // 可选:设置令牌校验地址(如果需要令牌合法性校验) tokenServices.setCheckTokenEndpointUrl("https://your-auth-server/oauth/check_token"); tokenServices.setClientId("your-client-id"); tokenServices.setClientSecret("your-client-secret"); // 重点:设置userInfoUri tokenServices.setUserInfoEndpointUrl("https://your-auth-server/userinfo"); resources.tokenServices(tokenServices); } }
2. Spring Security 5+ OAuth2资源服务器配置
如果是Spring Security 5.x及以上版本(依赖spring-security-oauth2-resource-server),配置更简洁,直接在SecurityFilterChain中设置:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .oauth2ResourceServer(oauth2 -> oauth2 .jwt(jwt -> jwt .userInfoEndpoint(userInfo -> userInfo // 直接配置userInfoUri .userInfoUri("https://your-auth-server/userinfo") ) ) ); return http.build(); } }
3. 自定义配置类绑定属性(灵活管理配置)
如果想更灵活地管理配置参数,可以先自定义一个属性绑定类,再注入到配置逻辑中:
import org.springframework.boot.context.properties.ConfigurationProperties; import org.springframework.context.annotation.Configuration; @Configuration @ConfigurationProperties(prefix = "security.oauth2.resource") public class OAuth2ResourceProperties { private String userInfoUri; // getter & setter public String getUserInfoUri() { return userInfoUri; } public void setUserInfoUri(String userInfoUri) { this.userInfoUri = userInfoUri; } }
然后在配置类中注入这个属性类,再设置到令牌服务:
@Configuration public class ResourceServerConfig extends ResourceServerConfigurerAdapter { private final OAuth2ResourceProperties resourceProperties; // 构造注入属性类 public ResourceServerConfig(OAuth2ResourceProperties resourceProperties) { this.resourceProperties = resourceProperties; } @Override public void configure(ResourceServerSecurityConfigurer resources) throws Exception { RemoteTokenServices tokenServices = new RemoteTokenServices(); tokenServices.setUserInfoEndpointUrl(resourceProperties.getUserInfoUri()); // 其他必要配置... resources.tokenServices(tokenServices); } }
你可以根据自己的Spring版本和依赖情况,选择最适合的方式来配置userInfoUri~
内容的提问来源于stack exchange,提问作者Jose Martinez
相关产品推荐
相关产品推荐

