JWTクレームをSpring Authoritiesにマッピングする
JwtAuthenticationConverterを使って、リソースサーバーがJWTクレームをSpring SecurityのGrantedAuthoritiesに変換し、きめ細かなアクセス制御を実現する方法を学びます。
「JWTクレームをSpring Authoritiesにマッピングする」はCoddyKit上の無料Spring Security 6 & JWT Authenticationレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSpring Security 6 & JWT Authentication学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Spring Security 6 & JWT Authenticationコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
From Claims to Authorities
A resource server validates a JWT, but to enforce access it needs Spring GrantedAuthority objects. The bridge between raw claims and authorities is the JwtAuthenticationConverter.
The Default Scope Mapping
By default Spring reads the scope or scp claim, splits it on spaces, and prefixes each value with SCOPE_. So a scope of read becomes the authority SCOPE_read.
// scope: 'read write' -> SCOPE_read, SCOPE_writeChecking Scope Authorities
You can require these authorities in your security config or with annotations.
http.authorizeHttpRequests(auth -> auth
.requestMatchers('/api/data').hasAuthority('SCOPE_read'));The Problem with Roles
Many identity providers put roles in a custom claim like roles or realm_access.roles, not in scope. The default converter ignores those, so you must customize it.
Building a Custom Converter
Create a JwtGrantedAuthoritiesConverter and point it at the claim that holds your roles.
JwtGrantedAuthoritiesConverter c = new JwtGrantedAuthoritiesConverter();
c.setAuthoritiesClaimName('roles');
c.setAuthorityPrefix('ROLE_');Wrapping in JwtAuthenticationConverter
Wrap the authorities converter inside a JwtAuthenticationConverter, which produces the final authentication token.
JwtAuthenticationConverter conv = new JwtAuthenticationConverter();
conv.setJwtGrantedAuthoritiesConverter(c);Registering the Converter
Tell the resource server to use your converter inside the JWT configuration.
http.oauth2ResourceServer(o -> o
.jwt(j -> j.jwtAuthenticationConverter(conv)));Nested Claims
Some providers nest roles, e.g. Keycloak uses realm_access.roles. The simple converter cannot read nested paths, so write a lambda converter that drills into the structure.
Converter<Jwt, Collection<GrantedAuthority>> conv = jwt -> {
Map<String,Object> realm = jwt.getClaim('realm_access');
List<String> roles = (List<String>) realm.get('roles');
return roles.stream()
.map(r -> new SimpleGrantedAuthority('ROLE_' + r))
.collect(Collectors.toList());
};Combining Scopes and Roles
You may want both scope-based and role-based authorities. Merge two converters' results so a single principal carries both SCOPE_ and ROLE_ authorities.
Customizing the Principal Name
By default the principal name is the sub claim. Override setPrincipalClaimName if you prefer to identify users by, say, preferred_username.
conv.setPrincipalClaimName('preferred_username');Verifying the Mapping
Test with a mock JWT that carries the roles claim and assert the request succeeds only when the expected authority is present.
mockMvc.perform(get('/api/admin')
.with(jwt().authorities(new SimpleGrantedAuthority('ROLE_admin'))))
.andExpect(status().isOk());Quick Check
Test your understanding of claim-to-authority mapping.
Recap
You learned to map JWT claims to Spring authorities:
- Default mapping turns
scopeintoSCOPE_authorities - Use
JwtGrantedAuthoritiesConverterto read custom role claims - Write a lambda converter for nested claims like
realm_access.roles - Register it via
jwtAuthenticationConverter
This gives your resource server precise, claim-driven access control.
AI チューターと学ぶ Java — 無料
ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。
- コース
- 12
- レッスン
- 48
よくある質問
「JWTクレームをSpring Authoritiesにマッピングする」レッスンは無料ですか?
はい。「JWTクレームをSpring Authoritiesにマッピングする」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Spring Security 6 & JWT Authenticationコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Spring Security 6 & JWT Authenticationコースには全4レッスンが含まれています。
「JWTクレームをSpring Authoritiesにマッピングする」で何を学びますか?
JwtAuthenticationConverterを使って、リソースサーバーがJWTクレームをSpring SecurityのGrantedAuthoritiesに変換し、きめ細かなアクセス制御を実現する方法を学びます。 ブラウザで直接実行するハンズオンコードでSpring Security 6 & JWT Authenticationを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Spring Security 6 & JWT Authenticationを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのSpring Security 6 & JWT Authenticationは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。
「JWTクレームをSpring Authoritiesにマッピングする」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このSpring Security 6 & JWT Authenticationレッスンでコードを書いて実行できますか?
はい。すべてのSpring Security 6 & JWT Authenticationレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- リソースサーバーのセットアップ
- JWTのデコードと検証
- スコープとクレームの適用
- JWTクレームをSpring Authoritiesにマッピングする