尽管 authorizeRequests().anyRequest().permitAll() spring-security 返回 401

我正在使用 spring-securityspring-security-oauth2(JWT 访问令牌)进行身份验证和授权.这个想法是让所有请求通过,但能够区分经过身份验证的用户和未经身份验证的用户.一旦我启用 @EnableResourceServer 我配置的 HttpSecurity 似乎被忽略.并且请求返回 401:

I'm using spring-security and spring-security-oauth2 (JWT access tokens) for authentication and authorization. The idea is to let all requests through, but to be able to distinguish between authenticated users and unauthenticated users. As soon as I enable @EnableResourceServer my configured HttpSecurity seems to get ignored. And requests return 401:

    "error": "unauthorized",
    "error_description": "Full authentication is required to access this resource"


public class Application {

    public static void main(final String[] args) {
        new SpringApplicationBuilder(Application.class).bannerMode(Banner.Mode.OFF).run(args);

    public static class SecurityConfig extends WebSecurityConfigurerAdapter implements JwtAccessTokenConverterConfigurer {

        protected void configure(final HttpSecurity http) throws Exception {

        public void configure(final JwtAccessTokenConverter converter) {
            final DefaultAccessTokenConverter conv = new DefaultAccessTokenConverter();


        public UserAuthenticationConverter userAuthenticationConverter() {
            return new ResourceAuthenticationConverter();


你快到了.这是一个简单的修复 - @EnableResourceServer 的 javadoc 提供了答案:

You're almost there. It's an easy fix - the javadoc of @EnableResourceServer provides the answer:

用户应该添加这个注解并提供一个@Bean 类型ResourceServerConfigurer(例如,通过 ResourceServerConfigurerAdapter)指定资源的详细信息(URL 路径和资源id).

Users should add this annotation and provide a @Bean of type ResourceServerConfigurer (e.g. via ResourceServerConfigurerAdapter) that specifies the details of the resource (URL paths and resource id).

但是,您使用的是 WebSecurityConfigurerAdapter.只需将其改为ResourceServerConfigurerAdapter,增强configure的可见性:

You're using a WebSecurityConfigurerAdapter however. Just change it to ResourceServerConfigurerAdapter and enhance the visibility of configure:

public static class SecurityConfig extends ResourceServerConfigurerAdapter implements JwtAccessTokenConverterConfigurer {
// snip
        public void configure(final HttpSecurity http) throws Exception {
// snip
