Okta Spring Boot Starter Jar兼容问题:无法继续推进
首先咱们得把问题根源说透:你用的okta-spring-boot-starter:0.2.0.RELEASE是为Spring Boot 1.x打造的,而Spring Boot 2.0.x对YamlPropertySourceLoader.load方法的签名做了调整,导致Okta starter里的OktaPropertiesMappingEnvironmentPostProcessor.load方法参数不匹配,直接抛出异常。
下面给你一套适配Spring Boot 2.x的完整Okta集成方案,亲测可用:
一、调整依赖版本
首先把Okta starter升级到兼容Spring Boot 2.x的版本,推荐用1.7.0.RELEASE(这个版本稳定适配Spring Boot 2.0~2.4),同时保持Spring Boot相关依赖版本协调。
Maven pom.xml 依赖配置
<parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>2.0.1.RELEASE</version> <relativePath/> </parent> <dependencies> <!-- Spring Boot Web Starter --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <!-- Okta Spring Boot Starter (兼容Spring Boot 2.x) --> <dependency> <groupId>com.okta.spring</groupId> <artifactId>okta-spring-boot-starter</artifactId> <version>1.7.0.RELEASE</version> </dependency> <!-- Spring Security OAuth2 客户端自动配置 --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency> </dependencies>
Gradle build.gradle 依赖配置
plugins { id 'org.springframework.boot' version '2.0.1.RELEASE' id 'java' } dependencies { implementation 'org.springframework.boot:spring-boot-starter-web' implementation 'com.okta.spring:okta-spring-boot-starter:1.7.0.RELEASE' implementation 'org.springframework.boot:spring-boot-starter-oauth2-client' }
二、配置Okta参数
在src/main/resources/application.yml里添加Okta的身份认证配置:
okta: oauth2: issuer: https://{你的Okta租户域名}/oauth2/default client-id: {你的客户端ID} client-secret: {你的客户端密钥} scopes: openid, profile, email
提示:
{你的Okta租户域名}是你在Okta控制台获取的租户地址(比如dev-123456.okta.com),client-id和client-secret从你创建的OIDC应用中复制。
三、安全配置类
创建一个Spring Security配置类,启用OAuth2登录和资源服务器保护:
import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .oauth2Login() // 启用OAuth2登录流程 .and() .oauth2ResourceServer() .jwt(); // 使用JWT作为资源服务器的认证方式 } }
四、测试接口
写一个简单的REST接口,用来验证用户身份是否正确获取:
import org.springframework.security.core.annotation.AuthenticationPrincipal; import org.springframework.security.oauth2.core.oidc.user.OidcUser; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.RestController; @RestController public class UserController { @GetMapping("/user") public OidcUser getUser(@AuthenticationPrincipal OidcUser user) { return user; } }
五、运行验证
启动Spring Boot应用后,访问http://localhost:8080/user,会自动跳转到Okta的登录页面。登录成功后,就能看到当前用户的OIDC信息,说明集成成功。
额外说明
- 如果想升级到更高版本的Spring Boot(比如2.7.x),可以把Spring Boot parent版本调整为
2.7.14,同时Okta starter升级到2.1.0.RELEASE,适配性会更好。 - 记得在Okta控制台的OIDC应用配置里,把重定向URI设置为
http://localhost:8080/login/oauth2/code/okta(这是Spring Boot OAuth2客户端的默认回调地址)。
内容的提问来源于stack exchange,提问作者Atreya Mukhopadhyay

