【发布时间】:2017-05-25 01:25:18
【问题描述】:
我正在尝试使用 Spring Boot 和 Spring Security 的 OAuth2 集成来设置 OAuth2 授权服务器。
当我尝试进行身份验证时,我得到一个 HTTP 状态代码 400response 说:“Bad Credentials”。
在这里你可以找到我的授权服务器和网络安全配置:https://gist.github.com/codecitizen/8d130469d83439f5fca86b1a84733aab
我有 UserDetailsService 和 ClientDetailsService 的自定义实现。但它们似乎配置正确。当我运行以下测试用例时:
given().
formParam("grant_type", "password").
formParam("username", user.getUsername()).
formParam("password", password).
auth().basic(client.getClientId(), client.getClientSecret()).
when().
post("/oauth/token").
then().extract().asString();
使用 RestAssurred,调用两个服务。
事件陌生人:当我在 IntelliJ 中为此表达式设置断点并对其进行评估时,它会返回正确的 JWT 令牌,并且身份验证似乎有效。当我再次执行测试方法并得到完全相同的结果时:{"error":"invalid_grant","error_description":"Bad credentials"}this 响应!无需更改代码中的任何内容!
我真的无法弄清楚问题是什么。任何有 Spring Security + OAuth2 经验的人可以提供帮助吗?
【问题讨论】:
标签: spring spring-security spring-security-oauth2 oauth2 spring-oauth2