java - Spring Security OAuth2 改变JSON错误响应格式

标签 java spring spring-security spring-security-oauth2

我有一个基于 Spring Security OAuth2 的 RESTful 应用程序。我一直在尝试将默认的 Spring Security 消息传递格式从 XML 更改为 JSON,并且在这方面取得了部分成功。

例如 - 我想出了如何在请求不包含 Bearer token 时更改响应格式(下一行就是这样做的)

<bean id="oauthAuthenticationEntryPoint" class ="c.s.m.security.CustomAuthenticationEntryPoint" />

但我无法弄清楚如何捕获/更改以下两项的格式。

  1. 当在安全 URL 中传递无效 token 时,Spring Security 目前会返回。我在哪里更改此格式?

    {"error": "invalid_token","error_description": "Invalid access token: 144285e3-9563-420e-8ce"}
    
  2. 如何更改 BadCredentialsException JSON 格式?目前,它返回类似于上面的 JSON?

下面是我的applicationContext.xml

<sec:http pattern="/oauth/token" create-session="stateless"
    use-expressions="true" authentication-manager-ref="authenticationManager">
    <sec:csrf disabled="true" />
    <sec:anonymous enabled="false" />
    <sec:http-basic entry-point-ref="clientAuthenticationEntryPoint" />
    <sec:custom-filter ref="clientCredentialsTokenEndpointFilter" before="BASIC_AUTH_FILTER" />
    <sec:access-denied-handler ref="oauthAccessDeniedHandler" />
</sec:http>
<sec:authentication-manager alias="authenticationManager"
    erase-credentials="false">
    <sec:authentication-provider user-service-ref="clientDetailsUserService" />
</sec:authentication-manager>

<bean id="clientDetailsUserService" class="org.springframework.security.oauth2.provider.client.ClientDetailsUserDetailsService">
    <constructor-arg ref="clientDetails" />
</bean>

<!-- Entry point - Entry point Filter for token server -->

<bean id="clientAuthenticationEntryPoint" class="org.springframework.security.oauth2.provider.error.OAuth2AuthenticationEntryPoint">
    <property name="realmName" value="Oauth 2 security" />
    <property name="typeName" value="Basic" />
</bean>

<bean id="clientCredentialsTokenEndpointFilter" class="org.springframework.security.oauth2.provider.client.ClientCredentialsTokenEndpointFilter">
    <property name="authenticationManager" ref="authenticationManager" />
</bean>

<!-- Oauth handler Access Denied Handler -->

<bean id="oauthAccessDeniedHandler" class="c.s.m.security.CustomAccessDeniedHandler" />
    <!-- class="org.springframework.security.oauth2.provider.error.OAuth2AccessDeniedHandler" /> -->

<!-- Server resource -->

<sec:http pattern="/api/**" create-session="never"
    entry-point-ref="oauthAuthenticationEntryPoint" use-expressions="true" >
    <sec:csrf disabled="true" />
    <sec:anonymous enabled="false" />
    <sec:intercept-url pattern="/api/**" access="hasRole('ROLE_ADMIN')" />
    <sec:custom-filter ref="resourceServerFilter"
        before="PRE_AUTH_FILTER" />
    <sec:access-denied-handler ref="oauthAccessDeniedHandler" />
</sec:http>

<!-- Entry point resource -->

<bean id="oauthAuthenticationEntryPoint" class ="c.s.m.security.CustomAuthenticationEntryPoint" />          

<oauth:resource-server id="resourceServerFilter" resource-id="springsec" token-services-ref="tokenServices" />

<bean id="tokenServices"
    class="org.springframework.security.oauth2.provider.token.DefaultTokenServices" >
    <property name="tokenStore" ref="tokenStore" />
    <property name="supportRefreshToken" value="true" />
    <property name="accessTokenValiditySeconds" value="300000" />
    <property name="clientDetailsService" ref="clientDetails" />
</bean>    
<bean id="tokenStore"  class="org.springframework.security.oauth2.provider.token.store.JdbcTokenStore">
    <constructor-arg ref="dataSource" />
</bean>
<oauth:authorization-server client-details-service-ref="clientDetails" token-services-ref="tokenServices">
    <oauth:authorization-code />
    <oauth:implicit />
    <oauth:refresh-token />
    <oauth:client-credentials />
    <oauth:password authentication-manager-ref="userAuthenticationManager" />
</oauth:authorization-server>

<sec:authentication-manager id="userAuthenticationManager">
    <sec:authentication-provider ref="customUserDetailsService" />
</sec:authentication-manager>

最佳答案

在请求头中发送Accept: application/json即可解决问题。

关于java - Spring Security OAuth2 改变JSON错误响应格式,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/34529822/

相关文章:

spring - 自动连线……不止一个?

java - Spring 3.1 entityManagerFactory java.lang.NoSuchFieldError : NULL Error

spring - Vaadin 7.1 + Spring-Security 集成在 Tomcat 服务器中运行

java - 删除所有空格和空行

java - Java 中的 ISO 持续时间格式验证

java - JAVA 中的 SAML 请求和响应

java - Selenium WD |如何将 WebElement 列表中的所有值复制到字符串列表中?

java - spring 集成超时客户端

security - Apache Shiro "with JSF 2.0"!进展如何?

java - 登录后重定向到所需位置