【问题标题】:Spring Boot OAuth2 Authorization Server, Bad Credentials ResponseSpring Boot OAuth2 授权服务器,错误凭证响应
【发布时间】:2017-05-25 01:25:18
【问题描述】:

我正在尝试使用 Spring Boot 和 Spring Security 的 OAuth2 集成来设置 OAuth2 授权服务器。

当我尝试进行身份验证时,我得到一个 HTTP 状态代码 400response 说:“Bad Credentials”。

在这里你可以找到我的授权服务器和网络安全配置:https://gist.github.com/codecitizen/8d130469d83439f5fca86b1a84733aab

我有 UserDetailsService 和 ClientDetailsService 的自定义实现。但它们似乎配置正确。当我运行以下测试用例时:

            given().
                    formParam("grant_type", "password").
                    formParam("username", user.getUsername()).
                    formParam("password", password).
                    auth().basic(client.getClientId(), client.getClientSecret()).
            when().
                    post("/oauth/token").
            then().extract().asString();

使用 RestAssurred,调用两个服务。

事件陌生人:当我在 IntelliJ 中为此表达式设置断点并对其进行评估时,它会返回正确的 JWT 令牌,并且身份验证似乎有效。当我再次执行测试方法并得到完全相同的结果时:{"error":"invalid_grant","error_description":"Bad credentials"}this 响应!无需更改代码中的任何内容!

我真的无法弄清楚问题是什么。任何有 Spring Security + OAuth2 经验的人可以提供帮助吗?

【问题讨论】:

    标签: spring spring-security spring-security-oauth2 oauth2 spring-oauth2


    【解决方案1】:

    您确定您的自定义 ClientDetails 设置了正确的 Oauth2 授权类型。

    如果你有一个手工制作的 UserDetailsS​​ervice,它可能会被配置为默认的授权类型(而不是你需要的 password 授权类型)

    • 授权码
    • 刷新令牌

    要添加password 授权类型,您需要执行以下操作:

    @Override
    public void configure(ClientDetailsServiceConfigurer clients) throws Exception {
       InMemoryClientDetailsServiceBuilder clientsBuilder = clients
         .inMemory()
         .withClient("clientid")
         .scopes("openid","read", "write")
         .authorizedGrantTypes("password", "refresh_token", "authorization_code")
         .secret("clientSecret"));
    }
    

    【讨论】:

    • 嘿,授权类型是正确的。我检查了。我使用stytex.de/blog/2016/02/01/spring-cloud-security-with-oauth2 重新完成了所有配置,然后应用了我的 ClientDetailsS​​ervice 和 UserDetailsS​​ervice。这个问题在某种程度上与 DefaultTokenServices 和 JwtTokenStore bean 有关。我明天去看看到底是什么原因。
    猜你喜欢
    • 2015-03-31
    • 2018-08-29
    • 2015-05-14
    • 2022-08-03
    • 2021-10-29
    • 2015-05-22
    • 2020-11-22
    • 1970-01-01
    • 2014-12-25
    相关资源
    最近更新 更多