【发布时间】:2017-08-09 15:00:05
【问题描述】:
我创建了一个简单的授权服务器,但无法对其进行配置。
- 启动两个应用程序(8080 用于身份验证服务器,9999 用于客户端)。
- 转到
localhost:9999/client并重定向到localhost:8080/login(如预期的那样)。 - 用用户/用户填写登录表单。
- 被重定向到
localhost:9999/client(如预期),但使用Hello, null而不是Hello, user。
但是,如果我直接去localhost:8080/me,我有{"name":"user"}。如何检索Hello, user?
授权服务器
@RestController
@EnableAuthorizationServer
@SpringBootApplication
public class Application extends WebSecurityConfigurerAdapter {
public static void main(String[] args) {
SpringApplication.run(Application.class, args);
}
@GetMapping({ "/user", "/me" })
public Map<String, String> user(Principal principal) {
return Collections.singletonMap("name", principal == null ? "null" : principal.getName());
}
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
auth.inMemoryAuthentication()
.withUser("user").password("user").authorities(AuthorityUtils.NO_AUTHORITIES);
}
@Override
protected void configure(HttpSecurity http) throws Exception {
http.formLogin();
}
}
应用程序的属性
security:
oauth2:
client:
client-id: clientid
client-secret: clientsecret
scope: read,write
auto-approve-scopes: '.*'
客户
@Configuration
@EnableAutoConfiguration
@EnableOAuth2Sso
@RestController
public class Client {
@GetMapping("/")
public String home(Principal principal) {
return "Hello, " + principal.getName();
}
public static void main(String[] args) {
new SpringApplicationBuilder(Client.class)
.properties("spring.config.name=client").run(args);
}
}
客户的属性
server:
port: 9999
context-path: /client
security:
oauth2:
client:
client-id: clientid
client-secret: clientsecret
access-token-uri: http://localhost:8080/oauth/token
user-authorization-uri: http://localhost:8080/oauth/authorize
resource:
user-info-uri: http://localhost:8080/me
更新:
当一切正常时,我下载了a tutorial,但它的ssoFilter 仅用于OAuth2 身份验证。我只想用loginForm配置它。
我还在 GitHub 上分享了一个临时的 example。我认为用它查找问题会更容易。
【问题讨论】:
-
您的要求如何?包括标题
-
只是猜测,根据 UserDetailsService 合同,用户必须拥有 GrantedAuthorites 否则会抛出 UsernameNotFoundException,尝试给您的用户一个角色。
-
@OrtwinAngermeier,不幸的是,这不起作用。
标签: java spring spring-boot spring-security spring-security-oauth2