Spring Security 中构造函数的参数1需要一个类型为的Bean,但找不到该Bean

3wabscal  于 2022-11-29  发布在  Spring
关注(0)|答案(1)|浏览(223)

我已经被困了一段时间了。我正在通过添加Jwt来修改我的Spring Security项目。目前,我正在尝试让JwtEncoder和JwtDecoder在SecurityConfig中工作,我需要RSAPrivateKey和RSAPublicKey来实现这些方法。为了获得这些键值,我使用了一个带有@ConfigurationProperties注解的记录。但是将此记录放入SecurityConfig中给我带来了一些问题:

***************************
APPLICATION FAILED TO START
***************************

Description:

Parameter 1 of constructor in com.ssl.app.security.config.SecurityConfig required a bean of type 'com.ssl.app.security.config.RsaKeyProperties' that could not be found.

Action:

Consider defining a bean of type 'com.ssl.app.security.config.RsaKeyProperties' in your configuration.

这是我的安全配置

import com.nimbusds.jose.jwk.JWK;
import com.nimbusds.jose.jwk.JWKSet;
import com.nimbusds.jose.jwk.RSAKey;
import com.nimbusds.jose.jwk.source.ImmutableJWKSet;
import com.nimbusds.jose.jwk.source.JWKSource;
import com.nimbusds.jose.proc.SecurityContext;
import com.ssl.app.security.filters.LoginAuthFilter;
import com.ssl.app.utility.ConsoleUtil;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.boot.context.properties.EnableConfigurationProperties;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configurers.oauth2.server.resource.OAuth2ResourceServerConfigurer;
import org.springframework.security.config.http.SessionCreationPolicy;
import org.springframework.security.oauth2.jwt.JwtDecoder;
import org.springframework.security.oauth2.jwt.JwtEncoder;
import org.springframework.security.oauth2.jwt.NimbusJwtDecoder;
import org.springframework.security.oauth2.jwt.NimbusJwtEncoder;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;


@Configuration
//@AllArgsConstructor
@EnableWebSecurity
//@EnableConfigurationProperties
public class SecurityConfig {
    private final LoginAuthFilter loginAuthFilter;
    private final RsaKeyProperties rsaKeyProperties;


    public SecurityConfig(LoginAuthFilter loginAuthFilter, RsaKeyProperties rsaKeyProperties) {
        this.loginAuthFilter = loginAuthFilter;
        this.rsaKeyProperties = rsaKeyProperties;
    }


    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        return http
                .csrf(csrf -> csrf.disable())
                .authorizeRequests(auth -> auth
                        .anyRequest().authenticated()
                )
                .oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt) // get config_class :: method
                .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
                .addFilterBefore(loginAuthFilter, UsernamePasswordAuthenticationFilter.class)
                .build();
    }


    @Bean
    JwtDecoder jwtDecoder() {
        ConsoleUtil.PrintRow(this.getClass().getSimpleName(),"Decode publicKey", "true");
        // Get public key and decode and return
        return NimbusJwtDecoder.withPublicKey(rsaKeyProperties.publicKey()).build();

    }


    @Bean
    JwtEncoder jwtEncoder() {
        ConsoleUtil.PrintRow(this.getClass().getSimpleName(),"Encode jwt", true);

        JWK jwk = new RSAKey.Builder(rsaKeyProperties.publicKey()).privateKey(rsaKeyProperties.privateKey()).build();
        JWKSource<SecurityContext> jwks = new ImmutableJWKSet<>(new JWKSet(jwk));
        return new NimbusJwtEncoder(jwks);
    }

}

记录

import org.springframework.boot.context.properties.ConfigurationProperties;

import java.security.interfaces.RSAPrivateKey;
import java.security.interfaces.RSAPublicKey;

@ConfigurationProperties(prefix ="rsa")
public record RsaKeyProperties(RSAPublicKey publicKey, RSAPrivateKey privateKey) {
}

我尝试将@EnableConfigurationProperties和EnableAutoConfiguration添加到SecurityConfig中,但是没有效果。@Value注解也不起作用。SecurityConfig需要一个bean,但是什么bean?

相关问题