尝试解码 jwt 令牌时出现“尝试解码 Jwt 时发生错误:无法检索远程 JWK 集:”错误

Hay*_*yan 5 java spring oauth-2.0 jwt

这是我的资源服务器的安全配置文件

    @Configuration
@EnableWebSecurity
public class SecureSecurityConfiguration extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
                .sessionManagement()
                .sessionCreationPolicy(STATELESS)
                .and()
                .authorizeRequests()
                .anyRequest()
                .permitAll()
                .antMatchers("api/**")
                .authenticated()
                .and()
                .oauth2ResourceServer()
                .jwt();
    }
}
Run Code Online (Sandbox Code Playgroud)

这些是 Spring Boot 应用程序(资源服务器应用程序)的依赖项。

<dependency>
        <groupId>org.springframework.security</groupId>
        <artifactId>spring-security-oauth2-core</artifactId>
        <version>5.5.3</version>
    </dependency>

    <dependency>
        <groupId>org.springframework.security.oauth.boot</groupId>
        <artifactId>spring-security-oauth2-autoconfigure</artifactId>
        <version>2.1.6.RELEASE</version>
    </dependency>

    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
    </dependency>
Run Code Online (Sandbox Code Playgroud)

这是配置 yml 文件中的 jwk-set-url,我的应用程序在启动时连接到该文件

    spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          jwk-set-uri: http://localhost:8083/.well-known/openid-configuration/jwks
Run Code Online (Sandbox Code Playgroud)

现在通过邮递员,当我通过邮递员从身份验证服务器获取令牌并尝试向我的服务器请求时,我收到这种错误

Bearer error="invalid_token", error_description="An error occurred while attempting to decode the Jwt: Couldn't retrieve remote JWK set: org.springframework.web.client.HttpClientErrorException$NotFound: 404 null", error_uri="https://tools.ietf.org/html/rfc6750#section-3.1"
Run Code Online (Sandbox Code Playgroud)

谁遇到过这样的问题?

小智 -2

在 SSL 属性选项卡中将“主机名验证”更改为“无”。