【发布时间】:2015-04-10 18:48:00
【问题描述】:
我有一个 ios 应用程序,它与在 Grails 上开发的 REST API 进行通信。为了保护 REST API,我决定使用 oAuth 2.0 'Resource Owner Password' 流程。为了让 grails 应用程序充当 oAuth 2.0 提供者,我使用以下 http://grails.org/plugin/spring-security-oauth2-provider 对于id为'client',secret为'1234',用户名为'user',密码为'password'的Client,获取token的请求如下
POST /oauth2-test/oauth/token HTTP/1.1
Host: 192.168.1.113:8080
Authorization: Basic Y2xpZW50OjEyMzQ=
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
grant_type=password&scope=read&username=user&password=password
收到的响应是
{
"error": "unauthorized",
"error_description": "Full authentication is required to access this resource"
}
我对 Spring Security 和 oAuth 2.0 提供程序插件的 config.groovy 编辑如下所示
// Added by the Spring Security Core plugin:
grails.plugin.springsecurity.userLookup.userDomainClassName = 'test.User'
grails.plugin.springsecurity.userLookup.authorityJoinClassName = 'test.UserRole'
grails.plugin.springsecurity.authority.className = 'test.Role'
grails.plugin.springsecurity.controllerAnnotations.staticRules = [
'/': ['permitAll'],
'/index': ['permitAll'],
'/index.gsp': ['permitAll'],
'/assets/**': ['permitAll'],
'/**/js/**': ['permitAll'],
'/**/css/**': ['permitAll'],
'/**/images/**': ['permitAll'],
'/**/favicon.ico': ['permitAll'],
'/oauth/authorize.dispatch': ["isFullyAuthenticated() and (request.getMethod().equals('GET') or request.getMethod().equals('POST'))"],
'/oauth/token.dispatch' : ["isFullyAuthenticated() and request.getMethod().equals('POST')"]
]
// Added by the Spring Security OAuth2 Provider plugin:
grails.plugin.springsecurity.oauthProvider.clientLookup.className = 'test.Client'
grails.plugin.springsecurity.oauthProvider.authorizationCodeLookup.className = 'test.AuthorizationCode'
grails.plugin.springsecurity.oauthProvider.accessTokenLookup.className = 'test.AccessToken'
grails.plugin.springsecurity.oauthProvider.refreshTokenLookup.className = 'test.RefreshToken'
grails.plugin.springsecurity.providerNames = [
'clientCredentialsAuthenticationProvider',
'daoAuthenticationProvider',
'anonymousAuthenticationProvider',
'rememberMeAuthenticationProvider'
]
grails.exceptionresolver.params.exclude = ['password', 'client_secret']
grails.plugin.springsecurity.filterChain.chainMap = [
'/oauth/token': 'JOINED_FILTERS,-oauth2ProviderFilter,-securityContextPersistenceFilter,-logoutFilter,-rememberMeAuthenticationFilter',
'/api/**': 'JOINED_FILTERS,-securityContextPersistenceFilter,-logoutFilter,-rememberMeAuthenticationFilter',
'/**': 'JOINED_FILTERS,-statelessSecurityContextPersistenceFilter,-oauth2ProviderFilter,-clientCredentialsTokenEndpointFilter'
]
- 我做错了什么?我了解 oAuth 2.0 主要用于 授权而不是身份验证。所以我必须明确添加 用于身份验证的过滤器?我从 Grails 开始,没有任何 在 Springs 上的经验以及如何操作的任何帮助表示赞赏?
- grant_type 'password' 是否需要客户端身份验证?授予
输入“密码”应该用户身份验证不够吗?即使它 需要对客户端进行身份验证,它将使用基本身份验证 根据我的理解。所以我需要明确添加一个基本的 身份验证过滤器?
【问题讨论】:
-
您是否在 Authorization 标头中传递了 client_id 和 client_secret?您是否尝试在请求中传递它们?
-
是的,我在 Authorization 标头中传递了 client_id 和 client_secret。是的,尝试将它们作为 x-www-form-urlencoded 在请求中传递并得到相同的结果.. 没有变化。
-
请问您是如何解决这个问题的?
-
Github上有一篇关于Spring Security OAuth2 Provider插件如何正确支持HTTP Basic Authentication的讨论:github.com/bluesliverx/grails-spring-security-oauth2-provider/…
标签: grails spring-security oauth-2.0 grails-plugin spring-security-oauth2