Spring Boot 4 Complete Guide · درس

دمج OAuth2 وتسجيل الدخول الاجتماعي

فوّضوا المصادقة إلى مزوّدين موثوقين مثل Google وGitHub باستخدام دعم عميل OAuth2 في Spring Security.

الدرس 4 من 413 خطوة

دمج OAuth2 وتسجيل الدخول الاجتماعي درس مجاني في Spring Boot 4 Complete Guide على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Spring Boot 4 Complete Guide، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Spring Boot 4 Complete Guide 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

What Is OAuth2?

OAuth2 is a protocol that lets users grant your app limited access to their identity at another provider, without sharing their password. It powers Login with Google, GitHub, and more.

Roles in OAuth2

Three players matter: the user (resource owner), your app (the client), and the authorization server (the provider). Spring orchestrates the handshake between them.

The Authorization Code Flow

The most common flow redirects the user to the provider, who returns an authorization code. Your app exchanges that code for tokens behind the scenes.

  • Redirect to provider
  • User approves
  • Receive code, exchange for token

Adding the OAuth2 Client Starter

Spring Security ships an OAuth2 client starter that handles the entire flow for you. Add the dependency to get started.

<dependency>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-oauth2-client</artifactId>
</dependency>

Registering a Provider

Configure your client ID and secret in properties. Spring already knows the endpoints for common providers like Google.

spring.security.oauth2.client.registration.google.client-id=YOUR_ID
spring.security.oauth2.client.registration.google.client-secret=YOUR_SECRET

Enabling Login

Call oauth2Login() in your security configuration to wire up the login page and callback handling automatically.

http.authorizeHttpRequests(a -> a.anyRequest().authenticated())
    .oauth2Login(Customizer.withDefaults());

Reading the Authenticated User

After login, inject the OAuth2User to access profile attributes like name and email returned by the provider.

@GetMapping("/me")
public String me(@AuthenticationPrincipal OAuth2User user) {
    return user.getAttribute("email");
}

Mapping Provider Roles

Providers return their own attributes. You often map them to your application's authorities so your existing access rules still apply.

OAuth2 vs OpenID Connect

OAuth2 is about authorization, while OpenID Connect adds an identity layer with an ID token. Most social logins use OIDC under the hood for authentication.

Persisting Users

On first login you typically create a local user record keyed by the provider's unique ID, linking the external identity to your own data model.

Security Considerations

Always validate redirect URIs, keep client secrets out of source control, and request only the scopes you actually need.

Quick Check

Test your understanding of OAuth2 login.

Recap

You added OAuth2 client support, registered a provider, enabled oauth2Login(), and read the authenticated user. Social login lets you offload password handling to trusted providers.

البدء مجانًا

تعلم Java مع معلم ذكاء اصطناعي — مجانًا

اكتب وقم بتشغيل أكوادك الفعلية في المتصفح، واحصل على مساعدة فورية من معلم ذكاء اصطناعي متاح 24/7، واستمر من حيث توقفت على الويب أو في التطبيق.

الدورات
21
الدروس
84

الأسئلة الشائعة

هل درس «دمج OAuth2 وتسجيل الدخول الاجتماعي» مجاني؟

نعم — نص درس «دمج OAuth2 وتسجيل الدخول الاجتماعي» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Spring Boot 4 Complete Guide، انتقل إلى CoddyKit PRO. تتضمن دورة Spring Boot 4 Complete Guide 4 دروس في المجموع.

ماذا ستتعلم في «دمج OAuth2 وتسجيل الدخول الاجتماعي»؟

فوّضوا المصادقة إلى مزوّدين موثوقين مثل Google وGitHub باستخدام دعم عميل OAuth2 في Spring Security. تتمرن على Spring Boot 4 Complete Guide مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Spring Boot 4 Complete Guide؟

لا تُشترط خبرة سابقة. Spring Boot 4 Complete Guide على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «دمج OAuth2 وتسجيل الدخول الاجتماعي»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Spring Boot 4 Complete Guide هذا؟

نعم. كل درس في Spring Boot 4 Complete Guide يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. أساسيات Spring Security
  2. المصادقة والتفويض
  3. الأمان المستند إلى JWT
  4. دمج OAuth2 وتسجيل الدخول الاجتماعي
← العودة إلى Spring Boot 4 Complete Guide