【问题标题】:Spring Security Multi Entry point with OAuth2使用 OAuth2 的 Spring Security 多入口点
【发布时间】:2021-06-06 11:34:10
【问题描述】:

我正在尝试使用多个入口点来保护我的 Spring Boot 应用程序,具体取决于用户。

我有 3 种身份验证:

  • 系统用户的基本 http 用户名和密码
  • 普通用户的 OAuth
  • 用户注册/登录后的Jwt

这个想法是让 /register、/login 和 /token 端点在 OAuth 身份验证后可访问。 对于系统用户,/register、/login 和 /token 端点只能通过用户名和密码访问。 所有其他端点只能通过从 /login 或 /token 端点获得的 JWT 令牌访问。

为此我设置了 3 个 WebSecurityConfigurer:

@Configuration
@Order(1)
public class BasicWebSecurityConfigurationAdapter extends WebSecurityConfigurerAdapter {
    @Autowired
    private UserDetailsService userDetailsService;

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf().disable()
                .antMatcher("/api/v1/system/**")
                    .authorizeRequests()
                    .anyRequest()
                    .authenticated()
                .and()
                .httpBasic();
    }

    @Override
    public void configure(AuthenticationManagerBuilder auth)
            throws Exception {

        auth
                .userDetailsService(userDetailsService)
                .passwordEncoder(new BCryptPasswordEncoder());
    }

    @Bean
    @Override
    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();
    }
}
@Configuration
@Order(2)
public class OAuthWebSecurityConfigurerAdapter extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf().disable()
                .antMatcher("/api/v1/access/**")
                .authorizeRequests()
                    .anyRequest()
                    .authenticated()
                .and()
                .oauth2Login();
    }
}
@Configuration
@Order(3)
public class JwtWebSecurityConfigurerAdapter extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf().disable()
                .antMatcher("/api/v1/**")
                .authorizeRequests()
                    .anyRequest()
                    .authenticated();

        http
                .addFilterBefore(new JwtAuthenticationFilter(), UsernamePasswordAuthenticationFilter.class);

        http
                .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);
    }
}

我遇到的问题是 OAuth 配置。找不到以下网址

http://localhost:8080/oauth2/authorization/google

我想 antMatcher 隐藏了其他端点?

有人可以帮忙吗?

谢谢

【问题讨论】:

    标签: spring-security


    【解决方案1】:

    SecurityFilterChain 是从"/oauth2/authorization/google" 发起授权请求的原因。

    由于"/oauth2/authorization/google" 与"/api/v1/system/**"、"/api/v1/access/**" 或"/api/v1/**" 不匹配,因此不会为该请求调用SecurityFilterChain,这意味着未启动授权请求。

    您可以更改用于授权请求的基本 URI,以匹配您为 SecurityFilterChain 指定的路径(默认为 "/oauth2/authorization/{registrationId}")。

    http
        .antMatcher("/api/v1/access/**")
        .authorizeRequests(authorize -> authorize
            .anyRequest().authenticated()
        )
        .oauth2Login(oauth2 -> oauth2
            .authorizationEndpoint(ae -> ae
                .baseUri("/api/v1/access/oauth2/authorization/{registrationId}")
            )
        );
    

    【讨论】:

      猜你喜欢
      • 2018-09-07
      • 2015-01-01
      • 2019-09-25
      • 1970-01-01
      • 2011-09-23
      • 2018-07-23
      • 2016-02-23
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多