## 😄Spring Authorization Server (3) 集成第三方【gitee、github】登录

建议集成gitee即可,github的网络请求不太稳定,梯子可能也会出现不稳定的情况

github集成

1. 在github中创建一个oauth应用

2. demo-authorizationserver 的授权服务器配置

  • 添加oauth配置

    yaml 复制代码
    spring:
      security:
        oauth2:
          client:
            registration:
              github: # 这个唯一就可以了 对应的也就是 {registrationId}
                provider: github # 换个对应如下的 provider
                client-id: 2205af0f0cc93e3a22ea #刚刚创建应用的client-id
                client-secret: 649d88df840a57d2591c4832b438cc9af2727240 #刚刚创建应用的client-secret
                redirect-uri: http://localhost:9000/login/oauth2/code/github # 模板 `{baseUrl}/login/oauth2/code/{registrationId}`
                scope: user:email, read:user #这个可以参考文档根据需要修改
                client-name: Sign in with GitHub
    
            provider:
              github:
                user-name-attribute: login

3. demo 示例

  • 我们现在访问客户端的主页:127.0.0.1:8080/index时,浏览器会重定向到:http://localhost:9000/login

  • 使用github登录

  • 我们自己的授权服务进行授权

  • 客户端成功访问

  • 客户端成功访问资源服务

gitee集成

1. 在gitee中创建一个第三方应用

  • 步骤如下

    • 找到gitee创建第三方应用的这个位置
    • 创建应用

2. demo-authorizationserver 的授权服务器配置

yaml 复制代码
spring:
  security:
    oauth2:
      client:
        registration:
          gitee:
            # 指定oauth登录提供者,该oauth登录由provider中的gitee来处理
            provider: gitee
            # 客户端名字
            client-name: Sign in with Gitee
            # 认证方式
            authorization-grant-type: authorization_code
            # 客户端id,使用自己的gitee的客户端id
            client-id: 29b85c97ed682910eaa4276d84a0c4532f00b962e1b9fe8552520129e65ae432
            # 客户端秘钥,使用自己的gitee的客户端秘钥
            client-secret: 8c6df920482a83d4662a34b76a9c3a62c8e80713e4f2957bb0459c3ceb70d73b
            # 回调地址 与gitee 配置的回调地址一致才行
            redirect-uri: http://192.168.56.1:9000/login/oauth2/code/gitee
            # 申请scope列表
            scope:
              - emails
              - user_info

        provider:
          gitee:
          # 设置用户信息名称对应的字段属性
          user-name-attribute: login
          # 获取token的地址
          token-uri: https://gitee.com/oauth/token
          # 获取用户信息的地址
          user-info-uri: https://gitee.com/api/v5/user
          # 发起授权申请的地址
          authorization-uri: https://gitee.com/oauth/authorize

3. demo示例

总结

  1. http://192.168.56.1:9000/login/oauth2/code/github,是spring-security-oauth2-client提供的一个模板 URL {baseUrl}/login/oauth2/code/{registrationId} , 第三方应用配置的回调调用 对应OAuth2LoginAuthenticationFilter 做后续处理, 在spring-security的源码中通过login/oauth2/code能搜索到 OAuth2LoginAuthenticationFilter。

    java 复制代码
    public class OAuth2LoginAuthenticationFilter extends AbstractAuthenticationProcessingFilter {
    
               //The default URI where this Filter processes authentication requests.
               public static final String DEFAULT_FILTER_PROCESSES_URI = "/login/oauth2/code/*";
                ...
               @Override
               public Authentication attemptAuthentication(HttpServletRequest request, HttpServletResponse response)
                       throws AuthenticationException {
                   ...
               }
    
    }
  2. 第三方回调地址 一定要与授权服务器(demo-authorizationserver)的yml中的回调地址一致,否则出现异常。

  3. demo-client的 spring.security.oauth2.client.provider.issuer-uri 配置一定不要与 demo-authorizationserver服务在同一个域下,例如当前demo-client 是 http://127.0.0.1:8080,那么 spring.security.oauth2.client.provider.issuer-uri 配http://192.168.56.1:9000,就不要配置 http://127.0.0.1:9000 后面详细有时间再好好讲讲这个的原因(大概就是seesion的原因,未认证请求前,授权服务器会保存客户端的授权请求,一旦授权成功后,就会删除seesion中的授权请求....)。

相关推荐
需要8269 分钟前
MySQL MVCC 与事务隔离级别:从一条 update 看版本链
java·数据库·spring boot·mysql·spring cloud
RuoyiOffice15 分钟前
SpringBoot3 企业薪酬核算:考勤、绩效与薪资规则如何算出一张可解释的工资单
spring boot·vue3·规则引擎·hrm·ruoyi office·薪酬核算·薪资试算
阿狗童鞋2 小时前
SpringBoot微服务实战指南
spring boot·后端·微服务
程序猿乐锅2 小时前
【黑马点评 | 第九篇】秒杀优化-异步实现
java·spring boot·redis·后端·spring·中间件·mybatis
Wx-bishekaifayuan2 小时前
springboot户外登山社交小程序19787-计算机课程设计、毕业设计
spring boot·后端·python·spring·elasticsearch·django·课程设计
+VX:Fegn08952 小时前
计算机毕业设计|基于springboot + vue外卖点餐系统(源码+数据库+文档)
数据库·vue.js·spring boot·后端·课程设计
FYKJ_20102 小时前
springboot刑事案件管理系统03047-计算机课程设计、毕业设计
vue.js·spring boot·python·mysql·typescript·spark·django
小辰爱喝汤3 小时前
新闻管理系统|SpringBoot + Vue 毕业设计完整方案
spring boot·毕业设计·课程设计
FYKJ_20103 小时前
springboot助农产品销售商城05829-计算机课程设计、毕业设计
java·spring boot·python·mysql·spark·django
Wx-bishekaifayuan4 小时前
springboot社区扶贫救助管理系统13300-计算机课程设计、毕业设计
spring boot·后端·python·django·课程设计·express·旅游