【问题标题】:Multiple markers at this line - The type NoOpPasswordEncoder is deprecated - The method getInstance() from the type NoOpPasswordEncoder is deprecated此行有多个标记 - 不推荐使用 NoOpPasswordEncoder 类型 - 不推荐使用 NoOpPasswordEncoder 类型的方法 getInstance()
【发布时间】:2019-02-07 15:06:45
【问题描述】:

我正在研究 Spring Cloud + Boot 示例。在此示例中,我希望进行 SSO。当我运行这个应用程序时,我得到了很好的响应,但看起来像

此行有多个标记 - NoOpPasswordEncoder 类型已弃用 - NoOpPasswordEncoder 类型的方法 getInstance() 是 已弃用

application.properties

server.port: 9000
server.servlet.context-path: /services
security.oauth2.client.clientId: pluralsight
security.oauth2.client.clientSecret: pluralsightsecret
security.oauth2.client.authorized-grant-types: authorization_code,refresh_token,password,client_credentials
security.oauth2.client.scope:toll_read,toll_report

ServiceConfig.java

@Configuration
public class ServiceConfig extends GlobalAuthenticationConfigurerAdapter {

    @Override
    public void init(AuthenticationManagerBuilder auth) throws Exception {
        auth.inMemoryAuthentication()
            .passwordEncoder(NoOpPasswordEncoder.getInstance())
            .withUser("agoldberg").password("pass1").roles("USER")
            .and()
            .withUser("bgoldberg").password("pass2").roles("USER", "OPERATOR");
    }
}

主方法:

@SpringBootApplication
@EnableAuthorizationServer
public class PluralsightSpringcloudM4SecureauthserverApplication {

    public static void main(String[] args) {
        SpringApplication.run(PluralsightSpringcloudM4SecureauthserverApplication.class, args);
    }
}

但 STS 显示错误。不推荐使用的方法的替换是什么?

输出:

【问题讨论】:

    标签: spring spring-boot single-sign-on microservices spring-cloud


    【解决方案1】:

    不要使用 NoOpPasswordEncoder。它什么也不做。请改用:Pbkdf2PasswordEncoder、SCryptPasswordEncoder 或 BCryptPasswordEncoder。我通常使用 BCryptPasswordEncoder。

    作为 bean 启动:

     @Bean
        public PasswordEncoder passwordEncoder() {
            return new BCryptPasswordEncoder();
        }
    

    【讨论】:

      【解决方案2】:

      我能够使用以下代码解决此问题。我正在使用 Spring Boot 版本2.0.4.RELEASE。完成!

      import org.springframework.context.annotation.Configuration;
      import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
      import org.springframework.security.config.annotation.authentication.configuration.GlobalAuthenticationConfigurerAdapter;
      
      @Configuration
      public class ServiceConfig extends GlobalAuthenticationConfigurerAdapter {
      
          @Override
          public void init(AuthenticationManagerBuilder auth) throws Exception {
              auth.inMemoryAuthentication()
                  .withUser("agoldberg").password("{noop}pass1").roles("USER")
                  .and()
                  .withUser("bgoldberg").password("{noop}pass2").roles("USER", "OPERATOR");
          }
      }
      

      【讨论】:

        【解决方案3】:

        您不应使用此密码编码器,因为它不安全。来自official docs:

        此 PasswordEncoder 不安全。而是使用自适应单向函数,如 BCryptPasswordEncoder、Pbkdf2PasswordEncoder 或 SCryptPasswordEncoder。更好地使用支持密码升级的 DelegatingPasswordEncoder。

        【讨论】:

          猜你喜欢
          • 2018-05-13
          • 1970-01-01
          • 2022-08-09
          • 1970-01-01
          • 2015-01-08
          • 2018-08-26
          • 1970-01-01
          • 2014-04-27
          • 1970-01-01
          相关资源
          最近更新 更多