oauth2.0 security之client_secret(appSecret)明文存储

170 阅读1分钟

oauth2.0 security之client_secret(appSecret)明文存储

代码调整

public class AuthorizationServerConfig extends AuthorizationServerConfigurerAdapter {
    ...
    @Override
    public void configure(ClientDetailsServiceConfigurer clients) throws Exception {
                            clients.jdbc(dataSource).passwordEncoder(PasswordEncoderFactories.createDelegatingPasswordEncoder());
    }
}
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    ...
    @Bean
    public PasswordEncoder passwordEncoder() {
        return PasswordEncoderFactories.createDelegatingPasswordEncoder();
    }
}

使用方式

前端请求: image.png 数据库:

image.png