├── README.md ├── mvnw ├── mvnw.cmd ├── pom.xml └── src ├── main ├── java │ └── com │ │ └── banling │ │ └── oauth2server │ │ ├── Oauth2ServerApplication.java │ │ ├── config │ │ ├── AuthServerConfig.java │ │ ├── ResServerConfig.java │ │ └── SecurityConfig.java │ │ └── web │ │ ├── HomeController.java │ │ ├── ResController.java │ │ └── UserController.java └── resources │ └── application.properties └── test └── java └── com └── banling └── oauth2server └── Oauth2ServerApplicationTests.java /README.md: -------------------------------------------------------------------------------- 1 | # OAuth2-server 2 | 3 | 基于Springboot与spring-security、spring-security-oauth2实现的(认证服务(security)、资源服务、授权服务)服务器。本例的token保存在内存中,也可以很容易修改为保存在数据库或者Redis中。
4 | 认证服务(security)、资源服务、授权服务,合并在同一个工程中实现。现实项目中,一般是认证服务与授权服务在一个工程中,而资源服务在另一个工程中。
5 |
6 | # 一、获取token
7 | 支持三种方式获得access_token,分别是:authorization_code,implicit,refresh_token
8 |
9 | 在本地测试,将OAuth2-server服务发布在本机8080。
10 | 获取token,authorization_code与implicit的方式类似。
11 |
12 | 1、authorization_code方式取得access_token:
13 |
14 | 1)get方式访问:http://localhost:8080/oauth/authorize?client_id=client&response_type=code&redirect_uri=http://localhost:8090/
15 | 注意其中的参数response_type=coderedirect_uri=http://localhost:8090/ ,表示支持authorization_code方式授权和设置回调uri。
16 | 17 | 2)提交被拦截,服务被重定向(forward)向至登录界面。
18 | 在登录界面上输入用户名与密码,提交,服务被重定向(forward)到授权(Approval)界面。
19 | 进行授权(Approval)后,服务被重定向(forward)至http://localhost:8090/。在回调的URI中带上了code,可以看到如:http://localhost:8090/?code=FLWFen
20 | 21 | 3)得到code后,通过postman工具,向OAuth服务器发起申请授权token(本例支持同时返回access_token与refresh_token)的post请求:
22 | 请求的URL是:http://client:secret@localhost:8080/oauth/token, client是登记的客户端,secret是客户端的密文。
23 | 请求的content-Type是:
24 | application/x-www-form-urlencoded
25 | 或者
26 | application/form-data
27 | 本例支持application/form-data。
28 | 请求body的参数:
29 | code:[之前获取的code],注意,code只可以使用一次便失效,并且即使没使用也有时效性。
30 | grant_type:authorization_code
31 | redirect_uri:http://localhost:8090/, 与获取code的redirect_uri必须完全对应
32 |
33 | 34 | 得到的结果如下所示:
35 |
{ 36 |
"access_token": "17586593-06e8-43be-a0bb-41348af9ae88", 37 |
"token_type": "bearer", 38 |
"refresh_token": "c98996d8-2b88-4415-963a-d8d1aaca30c8", 39 |
"expires_in": 43199, 40 |
"scope": "app test" 41 |
} 42 |
43 | 44 | 2、implicit方式获取token:
45 | 注意:仅可获取access_token,不能获取refresh_token。
46 |
47 | 1)get方式访问:http://localhost:8080/oauth/authorize?client_id=client&response_type=token&redirect_uri=http://localhost:8090/
48 | 注意其中的参数response_type=token,与authorization_code方式的最大不同是response_type变为token了
49 | 50 | 2)提交被拦截,服务被重定向(forward)向至登录界面。
51 | 在登录界面上输入用户名与密码,提交,服务被重定向(forward)到授权(Approval)界面。
52 | 进行授权(Approval)后,服务被重定向(forward)至http://localhost:8090/。
53 | 在回调的URI中带上token,可以看到如:http://localhost:8090/#access_token=17586593-06e8-43be-a0bb-41348af9ae88&token_type=bearer&expires_in=42487&scope=app%20test
54 | 其中的access_token是:17586593-06e8-43be-a0bb-41348af9ae88,由于access_token还没有过期,你可以看到这里获取的access_token与authorization_code方式取得的access_token是一样的,再细心点,会发觉,过期时间变短了。
55 |
56 | 57 | 3、refresh_token方式获取token:
58 | 注意:会得到一个全新的access_token。另外,也可以通过修改AuthServerConfig的configure(AuthorizationServerEndpointsConfigurer endpoints),设置AuthorizationServerEndpointsConfigurer的reuseRefreshTokens(false)得到一个全新refresh_token)。 59 |
60 |
61 | 1)post方式发送请求至:http://client:secret@localhost:8080/oauth/token
62 | content-Type是application/x-www-form-urlencoded或者application/form-data都可。
63 | 设置参数:
64 | grant_type:refresh_token
65 | refresh_token:[refresh_token值]
66 | scope:[多个值用空格分开]
67 | 68 | 2)得到结果如所示:
69 |
{ 70 |
"access_token": "ef73b228-ac8d-4c20-a916-d17189048698", 71 |
"token_type": "bearer", 72 |
"refresh_token": "c98996d8-2b88-4415-963a-d8d1aaca30c8", 73 |
"expires_in": 43199, 74 |
"scope": "app test" 75 |
} 76 |
77 | 78 | # 二、通过access_token访问受保护的资源
79 |
80 | 1、获取客户端信息
81 | 有两种方式:
82 | 方式一,url中追加access_token参数,如:
83 | http://localhost:8080/user?access_token=ef73b228-ac8d-4c20-a916-d17189048698
84 | 2)在请求的header中设置参数: 85 | Authorization参数,值是“[grant_type] [access_token]”,grant_type值与access_token值之间用空格分开。例如:bearer 65d6f4f6-70d3-4bb4-b36b-c6e570a3027b
86 |
87 | 2、其它受保护的资源
88 | 与获取客户端信息的操作类同。
89 |
90 | 91 | 92 | 93 | -------------------------------------------------------------------------------- /mvnw: -------------------------------------------------------------------------------- 1 | #!/bin/sh 2 | # ---------------------------------------------------------------------------- 3 | # Licensed to the Apache Software Foundation (ASF) under one 4 | # or more contributor license agreements. See the NOTICE file 5 | # distributed with this work for additional information 6 | # regarding copyright ownership. The ASF licenses this file 7 | # to you under the Apache License, Version 2.0 (the 8 | # "License"); you may not use this file except in compliance 9 | # with the License. You may obtain a copy of the License at 10 | # 11 | # http://www.apache.org/licenses/LICENSE-2.0 12 | # 13 | # Unless required by applicable law or agreed to in writing, 14 | # software distributed under the License is distributed on an 15 | # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 16 | # KIND, either express or implied. See the License for the 17 | # specific language governing permissions and limitations 18 | # under the License. 19 | # ---------------------------------------------------------------------------- 20 | 21 | # ---------------------------------------------------------------------------- 22 | # Maven2 Start Up Batch script 23 | # 24 | # Required ENV vars: 25 | # ------------------ 26 | # JAVA_HOME - location of a JDK home dir 27 | # 28 | # Optional ENV vars 29 | # ----------------- 30 | # M2_HOME - location of maven2's installed home dir 31 | # MAVEN_OPTS - parameters passed to the Java VM when running Maven 32 | # e.g. to debug Maven itself, use 33 | # set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 34 | # MAVEN_SKIP_RC - flag to disable loading of mavenrc files 35 | # ---------------------------------------------------------------------------- 36 | 37 | if [ -z "$MAVEN_SKIP_RC" ] ; then 38 | 39 | if [ -f /etc/mavenrc ] ; then 40 | . /etc/mavenrc 41 | fi 42 | 43 | if [ -f "$HOME/.mavenrc" ] ; then 44 | . "$HOME/.mavenrc" 45 | fi 46 | 47 | fi 48 | 49 | # OS specific support. $var _must_ be set to either true or false. 50 | cygwin=false; 51 | darwin=false; 52 | mingw=false 53 | case "`uname`" in 54 | CYGWIN*) cygwin=true ;; 55 | MINGW*) mingw=true;; 56 | Darwin*) darwin=true 57 | # Use /usr/libexec/java_home if available, otherwise fall back to /Library/Java/Home 58 | # See https://developer.apple.com/library/mac/qa/qa1170/_index.html 59 | if [ -z "$JAVA_HOME" ]; then 60 | if [ -x "/usr/libexec/java_home" ]; then 61 | export JAVA_HOME="`/usr/libexec/java_home`" 62 | else 63 | export JAVA_HOME="/Library/Java/Home" 64 | fi 65 | fi 66 | ;; 67 | esac 68 | 69 | if [ -z "$JAVA_HOME" ] ; then 70 | if [ -r /etc/gentoo-release ] ; then 71 | JAVA_HOME=`java-config --jre-home` 72 | fi 73 | fi 74 | 75 | if [ -z "$M2_HOME" ] ; then 76 | ## resolve links - $0 may be a link to maven's home 77 | PRG="$0" 78 | 79 | # need this for relative symlinks 80 | while [ -h "$PRG" ] ; do 81 | ls=`ls -ld "$PRG"` 82 | link=`expr "$ls" : '.*-> \(.*\)$'` 83 | if expr "$link" : '/.*' > /dev/null; then 84 | PRG="$link" 85 | else 86 | PRG="`dirname "$PRG"`/$link" 87 | fi 88 | done 89 | 90 | saveddir=`pwd` 91 | 92 | M2_HOME=`dirname "$PRG"`/.. 93 | 94 | # make it fully qualified 95 | M2_HOME=`cd "$M2_HOME" && pwd` 96 | 97 | cd "$saveddir" 98 | # echo Using m2 at $M2_HOME 99 | fi 100 | 101 | # For Cygwin, ensure paths are in UNIX format before anything is touched 102 | if $cygwin ; then 103 | [ -n "$M2_HOME" ] && 104 | M2_HOME=`cygpath --unix "$M2_HOME"` 105 | [ -n "$JAVA_HOME" ] && 106 | JAVA_HOME=`cygpath --unix "$JAVA_HOME"` 107 | [ -n "$CLASSPATH" ] && 108 | CLASSPATH=`cygpath --path --unix "$CLASSPATH"` 109 | fi 110 | 111 | # For Mingw, ensure paths are in UNIX format before anything is touched 112 | if $mingw ; then 113 | [ -n "$M2_HOME" ] && 114 | M2_HOME="`(cd "$M2_HOME"; pwd)`" 115 | [ -n "$JAVA_HOME" ] && 116 | JAVA_HOME="`(cd "$JAVA_HOME"; pwd)`" 117 | # TODO classpath? 118 | fi 119 | 120 | if [ -z "$JAVA_HOME" ]; then 121 | javaExecutable="`which javac`" 122 | if [ -n "$javaExecutable" ] && ! [ "`expr \"$javaExecutable\" : '\([^ ]*\)'`" = "no" ]; then 123 | # readlink(1) is not available as standard on Solaris 10. 124 | readLink=`which readlink` 125 | if [ ! `expr "$readLink" : '\([^ ]*\)'` = "no" ]; then 126 | if $darwin ; then 127 | javaHome="`dirname \"$javaExecutable\"`" 128 | javaExecutable="`cd \"$javaHome\" && pwd -P`/javac" 129 | else 130 | javaExecutable="`readlink -f \"$javaExecutable\"`" 131 | fi 132 | javaHome="`dirname \"$javaExecutable\"`" 133 | javaHome=`expr "$javaHome" : '\(.*\)/bin'` 134 | JAVA_HOME="$javaHome" 135 | export JAVA_HOME 136 | fi 137 | fi 138 | fi 139 | 140 | if [ -z "$JAVACMD" ] ; then 141 | if [ -n "$JAVA_HOME" ] ; then 142 | if [ -x "$JAVA_HOME/jre/sh/java" ] ; then 143 | # IBM's JDK on AIX uses strange locations for the executables 144 | JAVACMD="$JAVA_HOME/jre/sh/java" 145 | else 146 | JAVACMD="$JAVA_HOME/bin/java" 147 | fi 148 | else 149 | JAVACMD="`which java`" 150 | fi 151 | fi 152 | 153 | if [ ! -x "$JAVACMD" ] ; then 154 | echo "Error: JAVA_HOME is not defined correctly." >&2 155 | echo " We cannot execute $JAVACMD" >&2 156 | exit 1 157 | fi 158 | 159 | if [ -z "$JAVA_HOME" ] ; then 160 | echo "Warning: JAVA_HOME environment variable is not set." 161 | fi 162 | 163 | CLASSWORLDS_LAUNCHER=org.codehaus.plexus.classworlds.launcher.Launcher 164 | 165 | # traverses directory structure from process work directory to filesystem root 166 | # first directory with .mvn subdirectory is considered project base directory 167 | find_maven_basedir() { 168 | 169 | if [ -z "$1" ] 170 | then 171 | echo "Path not specified to find_maven_basedir" 172 | return 1 173 | fi 174 | 175 | basedir="$1" 176 | wdir="$1" 177 | while [ "$wdir" != '/' ] ; do 178 | if [ -d "$wdir"/.mvn ] ; then 179 | basedir=$wdir 180 | break 181 | fi 182 | # workaround for JBEAP-8937 (on Solaris 10/Sparc) 183 | if [ -d "${wdir}" ]; then 184 | wdir=`cd "$wdir/.."; pwd` 185 | fi 186 | # end of workaround 187 | done 188 | echo "${basedir}" 189 | } 190 | 191 | # concatenates all lines of a file 192 | concat_lines() { 193 | if [ -f "$1" ]; then 194 | echo "$(tr -s '\n' ' ' < "$1")" 195 | fi 196 | } 197 | 198 | BASE_DIR=`find_maven_basedir "$(pwd)"` 199 | if [ -z "$BASE_DIR" ]; then 200 | exit 1; 201 | fi 202 | 203 | ########################################################################################## 204 | # Extension to allow automatically downloading the maven-wrapper.jar from Maven-central 205 | # This allows using the maven wrapper in projects that prohibit checking in binary data. 206 | ########################################################################################## 207 | if [ -r "$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" ]; then 208 | if [ "$MVNW_VERBOSE" = true ]; then 209 | echo "Found .mvn/wrapper/maven-wrapper.jar" 210 | fi 211 | else 212 | if [ "$MVNW_VERBOSE" = true ]; then 213 | echo "Couldn't find .mvn/wrapper/maven-wrapper.jar, downloading it ..." 214 | fi 215 | jarUrl="https://repo.maven.apache.org/maven2/io/takari/maven-wrapper/0.4.2/maven-wrapper-0.4.2.jar" 216 | while IFS="=" read key value; do 217 | case "$key" in (wrapperUrl) jarUrl="$value"; break ;; 218 | esac 219 | done < "$BASE_DIR/.mvn/wrapper/maven-wrapper.properties" 220 | if [ "$MVNW_VERBOSE" = true ]; then 221 | echo "Downloading from: $jarUrl" 222 | fi 223 | wrapperJarPath="$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" 224 | 225 | if command -v wget > /dev/null; then 226 | if [ "$MVNW_VERBOSE" = true ]; then 227 | echo "Found wget ... using wget" 228 | fi 229 | wget "$jarUrl" -O "$wrapperJarPath" 230 | elif command -v curl > /dev/null; then 231 | if [ "$MVNW_VERBOSE" = true ]; then 232 | echo "Found curl ... using curl" 233 | fi 234 | curl -o "$wrapperJarPath" "$jarUrl" 235 | else 236 | if [ "$MVNW_VERBOSE" = true ]; then 237 | echo "Falling back to using Java to download" 238 | fi 239 | javaClass="$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.java" 240 | if [ -e "$javaClass" ]; then 241 | if [ ! -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then 242 | if [ "$MVNW_VERBOSE" = true ]; then 243 | echo " - Compiling MavenWrapperDownloader.java ..." 244 | fi 245 | # Compiling the Java class 246 | ("$JAVA_HOME/bin/javac" "$javaClass") 247 | fi 248 | if [ -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then 249 | # Running the downloader 250 | if [ "$MVNW_VERBOSE" = true ]; then 251 | echo " - Running MavenWrapperDownloader.java ..." 252 | fi 253 | ("$JAVA_HOME/bin/java" -cp .mvn/wrapper MavenWrapperDownloader "$MAVEN_PROJECTBASEDIR") 254 | fi 255 | fi 256 | fi 257 | fi 258 | ########################################################################################## 259 | # End of extension 260 | ########################################################################################## 261 | 262 | export MAVEN_PROJECTBASEDIR=${MAVEN_BASEDIR:-"$BASE_DIR"} 263 | if [ "$MVNW_VERBOSE" = true ]; then 264 | echo $MAVEN_PROJECTBASEDIR 265 | fi 266 | MAVEN_OPTS="$(concat_lines "$MAVEN_PROJECTBASEDIR/.mvn/jvm.config") $MAVEN_OPTS" 267 | 268 | # For Cygwin, switch paths to Windows format before running java 269 | if $cygwin; then 270 | [ -n "$M2_HOME" ] && 271 | M2_HOME=`cygpath --path --windows "$M2_HOME"` 272 | [ -n "$JAVA_HOME" ] && 273 | JAVA_HOME=`cygpath --path --windows "$JAVA_HOME"` 274 | [ -n "$CLASSPATH" ] && 275 | CLASSPATH=`cygpath --path --windows "$CLASSPATH"` 276 | [ -n "$MAVEN_PROJECTBASEDIR" ] && 277 | MAVEN_PROJECTBASEDIR=`cygpath --path --windows "$MAVEN_PROJECTBASEDIR"` 278 | fi 279 | 280 | WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain 281 | 282 | exec "$JAVACMD" \ 283 | $MAVEN_OPTS \ 284 | -classpath "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" \ 285 | "-Dmaven.home=${M2_HOME}" "-Dmaven.multiModuleProjectDirectory=${MAVEN_PROJECTBASEDIR}" \ 286 | ${WRAPPER_LAUNCHER} $MAVEN_CONFIG "$@" 287 | -------------------------------------------------------------------------------- /mvnw.cmd: -------------------------------------------------------------------------------- 1 | @REM ---------------------------------------------------------------------------- 2 | @REM Licensed to the Apache Software Foundation (ASF) under one 3 | @REM or more contributor license agreements. See the NOTICE file 4 | @REM distributed with this work for additional information 5 | @REM regarding copyright ownership. The ASF licenses this file 6 | @REM to you under the Apache License, Version 2.0 (the 7 | @REM "License"); you may not use this file except in compliance 8 | @REM with the License. You may obtain a copy of the License at 9 | @REM 10 | @REM http://www.apache.org/licenses/LICENSE-2.0 11 | @REM 12 | @REM Unless required by applicable law or agreed to in writing, 13 | @REM software distributed under the License is distributed on an 14 | @REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 15 | @REM KIND, either express or implied. See the License for the 16 | @REM specific language governing permissions and limitations 17 | @REM under the License. 18 | @REM ---------------------------------------------------------------------------- 19 | 20 | @REM ---------------------------------------------------------------------------- 21 | @REM Maven2 Start Up Batch script 22 | @REM 23 | @REM Required ENV vars: 24 | @REM JAVA_HOME - location of a JDK home dir 25 | @REM 26 | @REM Optional ENV vars 27 | @REM M2_HOME - location of maven2's installed home dir 28 | @REM MAVEN_BATCH_ECHO - set to 'on' to enable the echoing of the batch commands 29 | @REM MAVEN_BATCH_PAUSE - set to 'on' to wait for a key stroke before ending 30 | @REM MAVEN_OPTS - parameters passed to the Java VM when running Maven 31 | @REM e.g. to debug Maven itself, use 32 | @REM set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 33 | @REM MAVEN_SKIP_RC - flag to disable loading of mavenrc files 34 | @REM ---------------------------------------------------------------------------- 35 | 36 | @REM Begin all REM lines with '@' in case MAVEN_BATCH_ECHO is 'on' 37 | @echo off 38 | @REM set title of command window 39 | title %0 40 | @REM enable echoing my setting MAVEN_BATCH_ECHO to 'on' 41 | @if "%MAVEN_BATCH_ECHO%" == "on" echo %MAVEN_BATCH_ECHO% 42 | 43 | @REM set %HOME% to equivalent of $HOME 44 | if "%HOME%" == "" (set "HOME=%HOMEDRIVE%%HOMEPATH%") 45 | 46 | @REM Execute a user defined script before this one 47 | if not "%MAVEN_SKIP_RC%" == "" goto skipRcPre 48 | @REM check for pre script, once with legacy .bat ending and once with .cmd ending 49 | if exist "%HOME%\mavenrc_pre.bat" call "%HOME%\mavenrc_pre.bat" 50 | if exist "%HOME%\mavenrc_pre.cmd" call "%HOME%\mavenrc_pre.cmd" 51 | :skipRcPre 52 | 53 | @setlocal 54 | 55 | set ERROR_CODE=0 56 | 57 | @REM To isolate internal variables from possible post scripts, we use another setlocal 58 | @setlocal 59 | 60 | @REM ==== START VALIDATION ==== 61 | if not "%JAVA_HOME%" == "" goto OkJHome 62 | 63 | echo. 64 | echo Error: JAVA_HOME not found in your environment. >&2 65 | echo Please set the JAVA_HOME variable in your environment to match the >&2 66 | echo location of your Java installation. >&2 67 | echo. 68 | goto error 69 | 70 | :OkJHome 71 | if exist "%JAVA_HOME%\bin\java.exe" goto init 72 | 73 | echo. 74 | echo Error: JAVA_HOME is set to an invalid directory. >&2 75 | echo JAVA_HOME = "%JAVA_HOME%" >&2 76 | echo Please set the JAVA_HOME variable in your environment to match the >&2 77 | echo location of your Java installation. >&2 78 | echo. 79 | goto error 80 | 81 | @REM ==== END VALIDATION ==== 82 | 83 | :init 84 | 85 | @REM Find the project base dir, i.e. the directory that contains the folder ".mvn". 86 | @REM Fallback to current working directory if not found. 87 | 88 | set MAVEN_PROJECTBASEDIR=%MAVEN_BASEDIR% 89 | IF NOT "%MAVEN_PROJECTBASEDIR%"=="" goto endDetectBaseDir 90 | 91 | set EXEC_DIR=%CD% 92 | set WDIR=%EXEC_DIR% 93 | :findBaseDir 94 | IF EXIST "%WDIR%"\.mvn goto baseDirFound 95 | cd .. 96 | IF "%WDIR%"=="%CD%" goto baseDirNotFound 97 | set WDIR=%CD% 98 | goto findBaseDir 99 | 100 | :baseDirFound 101 | set MAVEN_PROJECTBASEDIR=%WDIR% 102 | cd "%EXEC_DIR%" 103 | goto endDetectBaseDir 104 | 105 | :baseDirNotFound 106 | set MAVEN_PROJECTBASEDIR=%EXEC_DIR% 107 | cd "%EXEC_DIR%" 108 | 109 | :endDetectBaseDir 110 | 111 | IF NOT EXIST "%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config" goto endReadAdditionalConfig 112 | 113 | @setlocal EnableExtensions EnableDelayedExpansion 114 | for /F "usebackq delims=" %%a in ("%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config") do set JVM_CONFIG_MAVEN_PROPS=!JVM_CONFIG_MAVEN_PROPS! %%a 115 | @endlocal & set JVM_CONFIG_MAVEN_PROPS=%JVM_CONFIG_MAVEN_PROPS% 116 | 117 | :endReadAdditionalConfig 118 | 119 | SET MAVEN_JAVA_EXE="%JAVA_HOME%\bin\java.exe" 120 | set WRAPPER_JAR="%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.jar" 121 | set WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain 122 | 123 | set DOWNLOAD_URL="https://repo.maven.apache.org/maven2/io/takari/maven-wrapper/0.4.2/maven-wrapper-0.4.2.jar" 124 | FOR /F "tokens=1,2 delims==" %%A IN (%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.properties) DO ( 125 | IF "%%A"=="wrapperUrl" SET DOWNLOAD_URL=%%B 126 | ) 127 | 128 | @REM Extension to allow automatically downloading the maven-wrapper.jar from Maven-central 129 | @REM This allows using the maven wrapper in projects that prohibit checking in binary data. 130 | if exist %WRAPPER_JAR% ( 131 | echo Found %WRAPPER_JAR% 132 | ) else ( 133 | echo Couldn't find %WRAPPER_JAR%, downloading it ... 134 | echo Downloading from: %DOWNLOAD_URL% 135 | powershell -Command "(New-Object Net.WebClient).DownloadFile('%DOWNLOAD_URL%', '%WRAPPER_JAR%')" 136 | echo Finished downloading %WRAPPER_JAR% 137 | ) 138 | @REM End of extension 139 | 140 | %MAVEN_JAVA_EXE% %JVM_CONFIG_MAVEN_PROPS% %MAVEN_OPTS% %MAVEN_DEBUG_OPTS% -classpath %WRAPPER_JAR% "-Dmaven.multiModuleProjectDirectory=%MAVEN_PROJECTBASEDIR%" %WRAPPER_LAUNCHER% %MAVEN_CONFIG% %* 141 | if ERRORLEVEL 1 goto error 142 | goto end 143 | 144 | :error 145 | set ERROR_CODE=1 146 | 147 | :end 148 | @endlocal & set ERROR_CODE=%ERROR_CODE% 149 | 150 | if not "%MAVEN_SKIP_RC%" == "" goto skipRcPost 151 | @REM check for post script, once with legacy .bat ending and once with .cmd ending 152 | if exist "%HOME%\mavenrc_post.bat" call "%HOME%\mavenrc_post.bat" 153 | if exist "%HOME%\mavenrc_post.cmd" call "%HOME%\mavenrc_post.cmd" 154 | :skipRcPost 155 | 156 | @REM pause the script if MAVEN_BATCH_PAUSE is set to 'on' 157 | if "%MAVEN_BATCH_PAUSE%" == "on" pause 158 | 159 | if "%MAVEN_TERMINATE_CMD%" == "on" exit %ERROR_CODE% 160 | 161 | exit /B %ERROR_CODE% 162 | -------------------------------------------------------------------------------- /pom.xml: -------------------------------------------------------------------------------- 1 | 2 | 4 | 4.0.0 5 | 6 | org.springframework.boot 7 | spring-boot-starter-parent 8 | 1.5.13.RELEASE 9 | 10 | 11 | com.banling 12 | oauth2-server 13 | 1.0 14 | oauth2-server 15 | springboot Oauth2 Server sample :: Oauth2 Authorization Server and Resource Server, combine with Security. 16 | 17 | 18 | 1.8 19 | 20 | 21 | 22 | 23 | org.springframework.boot 24 | spring-boot-starter-security 25 | 26 | 27 | org.springframework.boot 28 | spring-boot-starter-web 29 | 30 | 31 | 32 | org.springframework.security.oauth 33 | spring-security-oauth2 34 | 2.3.4.RELEASE 35 | 36 | 37 | 38 | org.springframework.boot 39 | spring-boot-starter-test 40 | test 41 | 42 | 43 | org.springframework.security 44 | spring-security-test 45 | test 46 | 47 | 48 | 49 | 50 | 51 | 52 | org.springframework.boot 53 | spring-boot-maven-plugin 54 | 55 | 56 | 57 | 58 | 59 | -------------------------------------------------------------------------------- /src/main/java/com/banling/oauth2server/Oauth2ServerApplication.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server; 2 | 3 | import org.springframework.boot.SpringApplication; 4 | import org.springframework.boot.autoconfigure.SpringBootApplication; 5 | 6 | @SpringBootApplication 7 | public class Oauth2ServerApplication { 8 | 9 | public static void main(String[] args) { 10 | SpringApplication.run(Oauth2ServerApplication.class, args); 11 | } 12 | 13 | } 14 | 15 | -------------------------------------------------------------------------------- /src/main/java/com/banling/oauth2server/config/AuthServerConfig.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server.config; 2 | 3 | import org.springframework.beans.factory.annotation.Autowired; 4 | import org.springframework.context.annotation.Bean; 5 | import org.springframework.context.annotation.Configuration; 6 | import org.springframework.security.authentication.AuthenticationManager; 7 | import org.springframework.security.oauth2.config.annotation.configurers.ClientDetailsServiceConfigurer; 8 | import org.springframework.security.oauth2.config.annotation.web.configuration.AuthorizationServerConfigurerAdapter; 9 | import org.springframework.security.oauth2.config.annotation.web.configuration.EnableAuthorizationServer; 10 | import org.springframework.security.oauth2.config.annotation.web.configurers.AuthorizationServerEndpointsConfigurer; 11 | import org.springframework.security.oauth2.config.annotation.web.configurers.AuthorizationServerSecurityConfigurer; 12 | import org.springframework.security.oauth2.provider.approval.ApprovalStore; 13 | import org.springframework.security.oauth2.provider.approval.TokenApprovalStore; 14 | import org.springframework.security.oauth2.provider.token.TokenStore; 15 | import org.springframework.security.oauth2.provider.token.store.InMemoryTokenStore; 16 | 17 | @Configuration 18 | @EnableAuthorizationServer 19 | public class AuthServerConfig extends AuthorizationServerConfigurerAdapter{ 20 | 21 | @Autowired 22 | private TokenStore tokenStore; 23 | 24 | @Autowired 25 | private AuthenticationManager authenticationManager; 26 | 27 | @Autowired 28 | private ApprovalStore approvalStore; 29 | 30 | @Override 31 | public void configure(ClientDetailsServiceConfigurer clients) throws Exception { 32 | //添加客户端信息 33 | //使用内存存储OAuth客户端信息 34 | clients.inMemory() 35 | // client_id 36 | .withClient("client") 37 | // client_secret 38 | .secret("secret") 39 | // 该client允许的授权类型,不同的类型,则获得token的方式不一样。 40 | .authorizedGrantTypes("authorization_code","implicit","refresh_token") 41 | .resourceIds("resourceId") 42 | //回调uri,在authorization_code与implicit授权方式时,用以接收服务器的返回信息 43 | .redirectUris("http://localhost:8090/") 44 | // 允许的授权范围 45 | .scopes("app","test"); 46 | } 47 | 48 | @Override 49 | public void configure(AuthorizationServerEndpointsConfigurer endpoints) throws Exception { 50 | endpoints.tokenStore(tokenStore).approvalStore(approvalStore) 51 | .authenticationManager(authenticationManager); 52 | } 53 | 54 | @Override 55 | public void configure(AuthorizationServerSecurityConfigurer security) throws Exception { 56 | security.realm("OAuth2-Sample") 57 | .allowFormAuthenticationForClients() 58 | .tokenKeyAccess("permitAll()") 59 | .checkTokenAccess("isAuthenticated()"); 60 | } 61 | 62 | @Bean 63 | public TokenStore tokenStore() { 64 | //token保存在内存中(也可以保存在数据库、Redis中)。 65 | //如果保存在中间件(数据库、Redis),那么资源服务器与认证服务器可以不在同一个工程中。 66 | //注意:如果不保存access_token,则没法通过access_token取得用户信息 67 | return new InMemoryTokenStore(); 68 | } 69 | 70 | @Bean 71 | public ApprovalStore approvalStore() throws Exception { 72 | TokenApprovalStore store = new TokenApprovalStore(); 73 | store.setTokenStore(tokenStore); 74 | return store; 75 | } 76 | } 77 | -------------------------------------------------------------------------------- /src/main/java/com/banling/oauth2server/config/ResServerConfig.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server.config; 2 | 3 | import org.springframework.beans.factory.annotation.Autowired; 4 | import org.springframework.context.annotation.Configuration; 5 | import org.springframework.security.config.annotation.web.builders.HttpSecurity; 6 | import org.springframework.security.config.http.SessionCreationPolicy; 7 | import org.springframework.security.oauth2.config.annotation.web.configuration.EnableResourceServer; 8 | import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter; 9 | import org.springframework.security.oauth2.config.annotation.web.configurers.ResourceServerSecurityConfigurer; 10 | import org.springframework.security.oauth2.provider.token.TokenStore; 11 | 12 | @Configuration 13 | @EnableResourceServer 14 | public class ResServerConfig extends ResourceServerConfigurerAdapter{ 15 | 16 | @Autowired 17 | private TokenStore tokenStore; 18 | 19 | @Override 20 | public void configure(ResourceServerSecurityConfigurer resources) throws Exception { 21 | resources 22 | .tokenStore(tokenStore) 23 | .resourceId("resourceId"); 24 | } 25 | 26 | @Override 27 | public void configure(HttpSecurity http) throws Exception { 28 | /* 29 | 注意: 30 | 1、必须先加上: .requestMatchers().antMatchers(...),表示对资源进行保护,也就是说,在访问前要进行OAuth认证。 31 | 2、接着:访问受保护的资源时,要具有哪里权限。 32 | ------------------------------------ 33 | 否则,请求只是被Security的拦截器拦截,请求根本到不了OAuth2的拦截器。 34 | 同时,还要注意先配置:security.oauth2.resource.filter-order=3,否则通过access_token取不到用户信息。 35 | ------------------------------------ 36 | requestMatchers()部分说明: 37 | Invoking requestMatchers() will not override previous invocations of :: 38 | mvcMatcher(String)}, requestMatchers(), antMatcher(String), regexMatcher(String), and requestMatcher(RequestMatcher). 39 | */ 40 | 41 | http 42 | // Since we want the protected resources to be accessible in the UI as well we need 43 | // session creation to be allowed (it's disabled by default in 2.0.6) 44 | //另外,如果不设置,那么在通过浏览器访问被保护的任何资源时,每次是不同的SessionID,并且将每次请求的历史都记录在OAuth2Authentication的details的中 45 | .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED) 46 | .and() 47 | .requestMatchers() 48 | .antMatchers("/user","/res/**") 49 | .and() 50 | .authorizeRequests() 51 | .antMatchers("/user","/res/**") 52 | .authenticated(); 53 | } 54 | } 55 | -------------------------------------------------------------------------------- /src/main/java/com/banling/oauth2server/config/SecurityConfig.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server.config; 2 | 3 | import org.springframework.beans.factory.annotation.Autowired; 4 | import org.springframework.context.annotation.Bean; 5 | import org.springframework.context.annotation.Configuration; 6 | import org.springframework.security.authentication.AuthenticationManager; 7 | import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; 8 | import org.springframework.security.config.annotation.web.builders.HttpSecurity; 9 | import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; 10 | import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; 11 | import org.springframework.security.web.util.matcher.AntPathRequestMatcher; 12 | 13 | @Configuration 14 | @EnableWebSecurity 15 | public class SecurityConfig extends WebSecurityConfigurerAdapter{ 16 | 17 | @Autowired 18 | public void globalUserDetails(AuthenticationManagerBuilder auth) throws Exception { 19 | //用户信息保存在内存中 20 | //在鉴定角色roler时,会默认加上ROLLER_前缀 21 | auth.inMemoryAuthentication().withUser("user").password("user").roles("USER").and() 22 | .withUser("test").password("test").roles("TEST"); 23 | } 24 | 25 | @Override 26 | protected void configure(HttpSecurity http) throws Exception { 27 | http.formLogin() //登记界面,默认是permit All 28 | .and() 29 | .authorizeRequests().antMatchers("/","/home").permitAll() //不用身份认证可以访问 30 | .and() 31 | .authorizeRequests().anyRequest().authenticated() //其它的请求要求必须有身份认证 32 | .and() 33 | .csrf() //防止CSRF(跨站请求伪造)配置 34 | .requireCsrfProtectionMatcher(new AntPathRequestMatcher("/oauth/authorize")).disable(); 35 | } 36 | 37 | @Override 38 | @Bean 39 | public AuthenticationManager authenticationManagerBean() throws Exception { 40 | return super.authenticationManagerBean(); 41 | } 42 | } 43 | -------------------------------------------------------------------------------- /src/main/java/com/banling/oauth2server/web/HomeController.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server.web; 2 | 3 | import org.springframework.web.bind.annotation.RequestMapping; 4 | import org.springframework.web.bind.annotation.RestController; 5 | 6 | @RestController 7 | public class HomeController { 8 | 9 | @RequestMapping("/home") 10 | public String home() { 11 | return "home page"; 12 | } 13 | 14 | @RequestMapping("/") 15 | public String index() { 16 | return "index page"; 17 | } 18 | 19 | } 20 | -------------------------------------------------------------------------------- /src/main/java/com/banling/oauth2server/web/ResController.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server.web; 2 | import java.security.Principal; 3 | 4 | import org.springframework.web.bind.annotation.RequestMapping; 5 | import org.springframework.web.bind.annotation.RestController; 6 | 7 | @RestController() 8 | public class ResController { 9 | 10 | @RequestMapping("/res/getMsg") 11 | public String getMsg(String msg,Principal principal) {//principal中封装了客户端(用户,也就是clientDetails,区别于Security的UserDetails,其实clientDetails中也封装了UserDetails),不是必须的参数,除非你想得到用户信息,才加上principal。 12 | return "Get the msg: "+msg; 13 | } 14 | } 15 | -------------------------------------------------------------------------------- /src/main/java/com/banling/oauth2server/web/UserController.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server.web; 2 | 3 | import java.security.Principal; 4 | 5 | import org.springframework.web.bind.annotation.RequestMapping; 6 | import org.springframework.web.bind.annotation.RestController; 7 | 8 | @RestController 9 | public class UserController { 10 | 11 | @RequestMapping("/user") 12 | public Principal user(Principal principal) { 13 | //principal在经过security拦截后,是org.springframework.security.authentication.UsernamePasswordAuthenticationToken 14 | //在经OAuth2拦截后,是OAuth2Authentication 15 | return principal; 16 | } 17 | 18 | } 19 | -------------------------------------------------------------------------------- /src/main/resources/application.properties: -------------------------------------------------------------------------------- 1 | #have to set this order, in case of the request intercepted by Security Filter instead of OAuth Filter 2 | security.oauth2.resource.filter-order=3 3 | 4 | logging.pattern.level=debug -------------------------------------------------------------------------------- /src/test/java/com/banling/oauth2server/Oauth2ServerApplicationTests.java: -------------------------------------------------------------------------------- 1 | package com.banling.oauth2server; 2 | 3 | import org.junit.Test; 4 | import org.junit.runner.RunWith; 5 | import org.springframework.boot.test.context.SpringBootTest; 6 | import org.springframework.test.context.junit4.SpringRunner; 7 | 8 | @RunWith(SpringRunner.class) 9 | @SpringBootTest 10 | public class Oauth2ServerApplicationTests { 11 | 12 | @Test 13 | public void contextLoads() { 14 | } 15 | 16 | } 17 | 18 | --------------------------------------------------------------------------------