【问题标题】:How to use JWKs with spring?如何将 JWK 与 spring 一起使用?
【发布时间】:2021-08-27 16:15:44
【问题描述】:

我的任务是在项目中实施 jwks。在我们的项目中,我们使用 oauth2 实现了令牌验证检查。我们使用 jks 格式的证书来获取公钥。我们的项目中没有使用私钥,因为我们需要检查令牌的有效性。我们的目标是摆脱 .jks 文件。 jwks 的资源太少,因此有些地方不清楚。 如果我理解正确,那么 jwks 的意思是资源中有一个 jwks.json 文件,里面有键,我们从 token 头中由 child 选择。根据文档,不清楚它是什么类型的文件以及它是如何加载以供孩子检查的,即它发生在什么时间。有没有可以作为示例的项目?提前致谢

https://docs.spring.io/spring-security-oauth2-boot/docs/2.2.x-SNAPSHOT/reference/html/boot-features-security-oauth2-authorization-server.html

【问题讨论】:

  • 谁在创建 JWT 令牌?它是在您的项目上创建的还是在外部身份验证服务器上创建的?
  • 在外部服务器上,我的服务器只检查令牌有效性

标签: jwk


【解决方案1】:

可以使用spring-boot资源服务器实现。

首先,你需要在你的项目中添加如下依赖

<dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
    </dependency>

其次,您需要添加一个身份验证服务器配置。您提到的 JSON 文件必须位于身份验证服务器上,或者您可以使用身份验证服务器的 JWKs URL。 您的属性文件中应该有这样的配置。

spring.security.oauth2.resourceserver.jwt.jwk-set-uri=https:/example.com/.well-known/openid-configuration/jwks
spring.security.oauth2.resourceserver.jwt.issuer-uri=https:/example.com

最后,您需要遵循自然的 spring-security API 配置。您需要的是如下所示。

@Configuration
@EnableWebSecurity
public class SecureSecurityConfiguration extends WebSecurityConfigurerAdapter {

    @Value("${spring.security.oauth2.resourceserver.jwt.jwk-set-uri}")
    private String jwtSetUri;

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.requiresChannel().anyRequest().requiresInsecure().and().cors()
                .and().csrf().disable()
                .authorizeRequests()
                .antMatchers(HttpMethod.GET, "some path1").permitAll()
                .antMatchers(HttpMethod.POST, "some path2").permitAll()
                .antMatchers(HttpMethod.GET, "some path3").permitAll()
                .antMatchers("/**").hasAuthority("some scope") // if you need this scope.
                .anyRequest()
                .authenticated()
                .and()
                .oauth2ResourceServer()
                .jwt().decoder(jwtDecoder());
    }


    @Bean
    CorsConfigurationSource corsConfigurationSource() {
        final UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        CorsConfiguration config = new CorsConfiguration().applyPermitDefaultValues();
        config.addAllowedMethod("PUT");
        config.addAllowedMethod("DELETE");
        source.registerCorsConfiguration("/**", config);
        return source;
    }

    private JwtDecoder jwtDecoder() {
        return NimbusJwtDecoder.withJwkSetUri(jwtSetUri)
                .jwtProcessorCustomizer(p -> p.setJWSTypeVerifier(
                        new DefaultJOSEObjectTypeVerifier<>(new JOSEObjectType("at+jwt")))).build();
    }
}

在此之后,Spring 应使用身份验证服务器自动验证对 API 的每个请求。

【讨论】:

  • spring.security.oauth2.resourceserver.jwt.jwk-set-uri 我如何使用我的 .json?我不明白这个文件来自哪里。
  • 您不需要任何 JSON 文件。你需要学习认证服务器的jwk-set-uri。就是这样。
  • 你的意思是我的服务每次都要向生成token的服务申请json吗?
  • 当然,在用户每次请求你的API之后,Spring都要与认证服务器通信并验证令牌
  • 但是不会生成token,只是会被验证
猜你喜欢
  • 2013-04-15
  • 2011-05-26
  • 2012-05-10
  • 2019-08-14
  • 2014-12-11
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2020-11-02
相关资源
最近更新 更多