【问题标题】:OAuth 2.0 with Implict Grant type Spring boot appOAuth 2.0 与隐式授权类型 Spring Boot 应用程序
【发布时间】:2018-05-18 17:09:23
【问题描述】:

我们正在构建一个具有以下技术规格的应用程序。

  • 角 4/5 [前端]
  • SpringBoot 框架 [后端]
  • OAuth 2.0 [授权]
  • MySQL [数据库]

注意:我们自己有资源服务器,授权服务器


流程

我们为多个客户 [我们的客户] 提供单一实例应用程序,这些客户将拥有自己的用户。每个用户都会收到一封电子邮件,通过我们的应用程序为他们各自的客户授权一些东西。电子邮件链接将包含 client_id、record_id 加密和编码。当用户点击链接时,它应该去 AuthServer,通过其 client_id 授权客户端,并将令牌传回用户代理,以进行任何进一步的操作。

我们经历了这个 Github repo 并实现了与示例相同的内容。

AuthServerConfigure代码如下:

@Override
public void configure(ClientDetailsServiceConfigurer clients) throws Exception {
       clients.inMemory().withClient("my-trusted-client")
             .authorizedGrantTypes("password", "authorization_code",
                            "refresh_token", "implicit")
             .authorities("ROLE_CLIENT", "ROLE_TRUSTED_CLIENT")
             .scopes("read", "write", "trust").resourceIds("sparklr")
             .accessTokenValiditySeconds(60).and()
             .withClient("my-client-with-registered-redirect")
      .authorizedGrantTypes("authorization_code").authorities("ROLE_CLIENT")
             .scopes("read", "trust").resourceIds("sparklr")
             .redirectUris("http://anywhere?key=value").and()
             .withClient("my-client-with-secret")
             .authorizedGrantTypes("client_credentials", "password")
                    .authorities("ROLE_CLIENT").scopes("read").resourceIds("sparklr")
             .secret("secret");

}

我们对传递给configure方法的值有些疑惑。

  • .inMemory().withClient("my-trusted-client") 在这里代表什么?这会一直被硬编码吗?由于我们将根据收到的 client_id 验证每个客户端,因此我们将在哪里提供此信息以进行动态验证?
  • .withClient("my-client-with-registered-redirect") 是干什么用的?即使这对每个客户来说都保持不变?
  • repo 中的作者还说我们可以通过以下方式验证设置 $ curl -H "Accept: application/json" my-client-with-secret:secret@localhost:8080/oauth/token -d grant_type=client_credentials 我看到 my-client-with-secret:secret 在这里通过。如果要针对不同的客户进行更改,我该如何将此值赋予 .withClient("my-client-with-secret") 和 .secret("secret")

我们很难理解这些概念。我们的要求很简单,我们将使用 client_id 验证每个客户端并为该客户端生成一个令牌。对于这种类型的要求,我们是否需要任何其他Grant_types?

请有人指出我们正确的方向。

【问题讨论】:

    标签: java spring-boot oauth-2.0 spring-security-oauth2 spring-security-rest


    【解决方案1】:

    第一个问题: 在您的示例中,客户端是硬编码的(因此是clients.inMemory())。您可以配置数据源并使用它:

    @Autowired
    DataSource dataSource;
    
    @Override
    public void configure(ClientDetailsServiceConfigurer clients) throws Exception {
        clients.jdbc(dataSource); // Get clients from database, table = oauth_client_details
    }
    

    您可以在documentation找到更多信息

    第二个问题在示例中,配置了三个客户端:

    1. my-trusted-client:此客户端可以授权使用这些 OAuth2 流:"password", "authorization_code", "refresh_token", "implicit"
    2. my-client-with-registered-redirect:此客户端可以授权使用这些 OAuth2 流:"authorization_code"
    3. my-client-with-secret:此客户端可以授权使用这些 OAuth2 流:"client_credentials"

    您需要了解这些流程之间的区别。

    第三个问题如果你想使用其他客户端,你必须将它们添加到你的代码/数据库中

    【讨论】:

    • 非常感谢......它消除了大部分疑虑...... :)
    猜你喜欢
    • 2014-04-15
    • 1970-01-01
    • 2018-11-21
    • 2019-02-11
    • 2019-08-18
    • 2019-03-11
    • 2012-12-27
    • 1970-01-01
    • 2018-07-04
    相关资源
    最近更新 更多