【问题标题】:Spring Boot Oauth UnautorizedSpring Boot Oauth 未经授权
【发布时间】:2018-07-04 22:34:34
【问题描述】:

我正在尝试遵循 this 教程以使 oa​​uth 正常工作。

但是当我尝试提出以下请求时

curl -X POST -d "client_id=client-id&client_secret=secret&grant_type=password&username=demo&password=1234" http://localhost:8080/oauth/token

我收到以下错误消息

{"timestamp":"2018-01-25T14:47:42.286+0000","status":401,"error":"Unauthorized","message":"Unauthorized","path":"/oauth/token"}

我的 AuthorizationServerConfiguration 如下所示

@Configuration
@EnableAuthorizationServer
class AuthorizationServerConfiguration : AuthorizationServerConfigurerAdapter() {
    @Autowired
    private val tokenStore: TokenStore? = null

    @Autowired
    private val userApprovalHandler: UserApprovalHandler? = null

    @Autowired
    @Qualifier("authenticationManagerBean")
    private val authenticationManager: AuthenticationManager? = null

    @Throws(Exception::class)
    override fun configure(clients: ClientDetailsServiceConfigurer?) {
        clients!!.inMemory()
                .withClient("client-id")
                .authorizedGrantTypes("password", "authorization_code", "refresh_token", "implicit")
                .authorities("ROLE_CLIENT", "ROLE_TRUSTED_CLIENT")
                .scopes("read", "write", "trust")
                .secret("secret")
                .accessTokenValiditySeconds(120)//Access token is only valid for 2 minutes.
                .refreshTokenValiditySeconds(600)//Refresh token is only valid for 10 minutes.
    }

    @Throws(Exception::class)
    override fun configure(endpoints: AuthorizationServerEndpointsConfigurer?) {
        endpoints!!.tokenStore(tokenStore).userApprovalHandler(userApprovalHandler)
                .authenticationManager(authenticationManager)
    }

    @Throws(Exception::class)
    override fun configure(oauthServer: AuthorizationServerSecurityConfigurer?) {
        oauthServer!!.realm(REALM + "/client")
    }

    companion object {
        private val REALM = "MY_OAUTH_REALM"
    }
}

我的 ResourceServerConfiguration 如下所示

@Configuration
@EnableResourceServer
class ResourceServerConfiguration : ResourceServerConfigurerAdapter() {

    override fun configure(resources: ResourceServerSecurityConfigurer?) {
        resources!!.resourceId(RESOURCE_ID).stateless(false)
    }

    @Throws(Exception::class)
    override fun configure(http: HttpSecurity) {
        http.anonymous().disable()
                .requestMatchers().antMatchers("/users/**")
                .and().authorizeRequests()
                .antMatchers("/users/**").access("hasRole('ADMIN')")
                .and().exceptionHandling().accessDeniedHandler(OAuth2AccessDeniedHandler())
    }

    companion object {
        private val RESOURCE_ID = "my_rest_api"
    }

}

我的 OAuth2SecurityConfiguration 如下所示

@Configuration
@EnableWebSecurity
class OAuth2SecurityConfiguration : WebSecurityConfigurerAdapter() {

    @Autowired
    private val clientDetailsService: ClientDetailsService? = null

    @Autowired
    @Throws(Exception::class)
    fun globalUserDetails(auth: AuthenticationManagerBuilder) {
        auth.inMemoryAuthentication()
                .withUser("bill").password("abc123").roles("ADMIN").and()
                .withUser("demo").password("1234").roles("USER")
    }

    @Throws(Exception::class)
    override fun configure(http: HttpSecurity) {
        http
                .csrf().disable()
                .anonymous().disable()
                .authorizeRequests()
                .antMatchers("/oauth/token").permitAll()
    }

    @Bean
    @Throws(Exception::class)
    override fun authenticationManagerBean(): AuthenticationManager {
        return super.authenticationManagerBean()
    }


    @Bean
    fun tokenStore(): TokenStore {
        return InMemoryTokenStore()
    }

    @Bean
    @Autowired
    fun userApprovalHandler(tokenStore: TokenStore): TokenStoreUserApprovalHandler {
        val handler = TokenStoreUserApprovalHandler()
        handler.setTokenStore(tokenStore)
        handler.setRequestFactory(DefaultOAuth2RequestFactory(clientDetailsService))
        handler.setClientDetailsService(clientDetailsService)
        return handler
    }

    @Bean
    @Autowired
    @Throws(Exception::class)
    fun approvalStore(tokenStore: TokenStore): ApprovalStore {
        val store = TokenApprovalStore()
        store.setTokenStore(tokenStore)
        return store
    }
}

关于我做错了什么的任何线索?

【问题讨论】:

    标签: spring spring-boot oauth kotlin


    【解决方案1】:

    token的请求需要Basic Authentication。 尝试在您的请求中添加以下选项:

    -u "client-id:secret"
    

    请求:

    curl -X POST -u "client-id:secret" -d "client_id=client-id&client_secret=secret&grant_type=password&username=demo&password=1234" http://localhost:8080/oauth/token
    

    【讨论】:

    • 我想它可以进一步修剪: curl -X POST -u "client-id:secret" -d "grant_type=password&username=demo&password=1234" localhost:8080/oauth/token。现在我得到 {"timestamp":"2018-01-25T21:35:12.887+0000","status":500,"error":"Internal Server Error","message":"没有为id \"null\"","path":"/oauth/token"}。无论如何,我会给你学分并提出一个新问题。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2013-07-05
    • 2019-09-09
    • 1970-01-01
    • 2021-04-07
    • 2019-11-09
    • 2016-10-10
    • 2015-10-13
    相关资源
    最近更新 更多