【问题标题】:Oauth2 Spring Security Authorization CodeOauth2 Spring 安全授权代码
【发布时间】:2023-04-01 07:10:01
【问题描述】:

我正在尝试重现此处提供的 oauth 服务器:

https://spring.io/blog/2015/02/03/sso-with-oauth2-angular-js-and-spring-security-part-v 测试这个基本服务器的 curl 调用应该是:

curl acme:acmesecret@localhost:9999/uaa/oauth/token  \
-d grant_type=authorization_code -d client_id=acme     \
-d redirect_uri=http://example.com -d code=jYWioI

虽然我不断收到以下错误: 无效的授权码:jYWioI

这个授权码在授权服务器哪里配置?

【问题讨论】:

  • 源代码在哪里?我在那个网站上找不到。

标签: oauth-2.0 spring-boot spring-security-oauth2


【解决方案1】:

您需要生成一个新的授权码!

您可以使用授权类型 authentication_code 或密码来完成

使用授权码:

打开浏览器并访问授权端点 http://localhost:9999/uaa/oauth/authorize?response_type=code&client_id=acme&redirect_uri=http://example.com

在登录过程(登录名:用户密码:密码)后,您将被重定向到 http://example.com/?code=CODE

现在你得到了令牌:

curl acme:acmesecret@localhost:9999/uaa/oauth/token -d grant_type=authorization_code -d client_id=acme -d redirect_uri=http://example.com -d code=CODE

响应:{"access_token":"eyJhbGciOiJS....."}

使用密码grantType:

curl acme:acmesecret@localhost:9999/uaa/oauth/token  -d grant_type=password -d username=user -d password=password

响应:{"access_token":"eyJhbGciOiJS....."}

我建议您阅读有关 oauth grantTypes 的更多信息,以了解什么对您的解决方案更好 https://aaronparecki.com/articles/2012/07/29/1/oauth2-simplified

【讨论】:

  • 登录页面是spring自己提供的吗?
  • 是的,spring 提供了一个默认登录视图,您可以覆盖 @user962206
  • Spring 提供的登录是基于会话的。如何使其基于令牌(JWT)?
猜你喜欢
  • 2017-05-10
  • 2012-04-07
  • 2017-02-25
  • 1970-01-01
  • 2017-10-04
  • 1970-01-01
  • 2013-11-02
  • 2015-05-20
相关资源
最近更新 更多