Integrazione di OAuth2 e social login
Deleghi l'autenticazione a provider affidabili come Google e GitHub usando il supporto client OAuth2 di Spring Security.
Integrazione di OAuth2 e social login è una lezione Spring Boot 4 Complete Guide gratuita su CoddyKit. Questa è la lezione 4 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Spring Boot 4 Complete Guide, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Spring Boot 4 Complete Guide include 4 lezioni in totale.
Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.
What Is OAuth2?
OAuth2 is a protocol that lets users grant your app limited access to their identity at another provider, without sharing their password. It powers Login with Google, GitHub, and more.
Roles in OAuth2
Three players matter: the user (resource owner), your app (the client), and the authorization server (the provider). Spring orchestrates the handshake between them.
The Authorization Code Flow
The most common flow redirects the user to the provider, who returns an authorization code. Your app exchanges that code for tokens behind the scenes.
- Redirect to provider
- User approves
- Receive code, exchange for token
Adding the OAuth2 Client Starter
Spring Security ships an OAuth2 client starter that handles the entire flow for you. Add the dependency to get started.
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-oauth2-client</artifactId>
</dependency>Registering a Provider
Configure your client ID and secret in properties. Spring already knows the endpoints for common providers like Google.
spring.security.oauth2.client.registration.google.client-id=YOUR_ID
spring.security.oauth2.client.registration.google.client-secret=YOUR_SECRETEnabling Login
Call oauth2Login() in your security configuration to wire up the login page and callback handling automatically.
http.authorizeHttpRequests(a -> a.anyRequest().authenticated())
.oauth2Login(Customizer.withDefaults());Reading the Authenticated User
After login, inject the OAuth2User to access profile attributes like name and email returned by the provider.
@GetMapping("/me")
public String me(@AuthenticationPrincipal OAuth2User user) {
return user.getAttribute("email");
}Mapping Provider Roles
Providers return their own attributes. You often map them to your application's authorities so your existing access rules still apply.
OAuth2 vs OpenID Connect
OAuth2 is about authorization, while OpenID Connect adds an identity layer with an ID token. Most social logins use OIDC under the hood for authentication.
Persisting Users
On first login you typically create a local user record keyed by the provider's unique ID, linking the external identity to your own data model.
Security Considerations
Always validate redirect URIs, keep client secrets out of source control, and request only the scopes you actually need.
Quick Check
Test your understanding of OAuth2 login.
Recap
You added OAuth2 client support, registered a provider, enabled oauth2Login(), and read the authenticated user. Social login lets you offload password handling to trusted providers.
Impara Java con un tutor IA — gratis
Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.
- Corsi
- 21
- Lezioni
- 84
Domande Frequenti
La lezione «Integrazione di OAuth2 e social login» è gratuita?
Sì — il testo completo di «Integrazione di OAuth2 e social login» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Spring Boot 4 Complete Guide, passa a CoddyKit PRO. Il corso Spring Boot 4 Complete Guide include 4 lezioni in totale.
Cosa imparerò in «Integrazione di OAuth2 e social login»?
Deleghi l'autenticazione a provider affidabili come Google e GitHub usando il supporto client OAuth2 di Spring Security. Eserciti Spring Boot 4 Complete Guide con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.
Ho bisogno di esperienza per iniziare Spring Boot 4 Complete Guide?
Non è richiesta alcuna esperienza precedente. Spring Boot 4 Complete Guide su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 4 di 4.
Quanto tempo richiede la lezione «Integrazione di OAuth2 e social login»?
La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.
Posso scrivere ed eseguire codice in questa lezione Spring Boot 4 Complete Guide?
Sì. Ogni lezione Spring Boot 4 Complete Guide include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.
Tutte le lezioni di questo corso
- Fondamenti di Spring Security
- Autenticazione e autorizzazione
- Sicurezza basata su JWT
- Integrazione di OAuth2 e social login