Mapeando declarações JWT para autoridades do Spring
Aprenda como um servidor de recursos converte declarações JWT em GrantedAuthorities do Spring Security usando JwtAuthenticationConverter para obter um controle de acesso detalhado.
Mapeando declarações JWT para autoridades do Spring é uma aula grátis de Spring Security 6 & JWT Authentication no CoddyKit. Esta é a aula 4 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Spring Security 6 & JWT Authentication, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Spring Security 6 & JWT Authentication inclui 4 aulas no total.
Partes desta aula ainda não foram traduzidas e aparecem em inglês.
From Claims to Authorities
A resource server validates a JWT, but to enforce access it needs Spring GrantedAuthority objects. The bridge between raw claims and authorities is the JwtAuthenticationConverter.
The Default Scope Mapping
By default Spring reads the scope or scp claim, splits it on spaces, and prefixes each value with SCOPE_. So a scope of read becomes the authority SCOPE_read.
// scope: 'read write' -> SCOPE_read, SCOPE_writeChecking Scope Authorities
You can require these authorities in your security config or with annotations.
http.authorizeHttpRequests(auth -> auth
.requestMatchers('/api/data').hasAuthority('SCOPE_read'));The Problem with Roles
Many identity providers put roles in a custom claim like roles or realm_access.roles, not in scope. The default converter ignores those, so you must customize it.
Building a Custom Converter
Create a JwtGrantedAuthoritiesConverter and point it at the claim that holds your roles.
JwtGrantedAuthoritiesConverter c = new JwtGrantedAuthoritiesConverter();
c.setAuthoritiesClaimName('roles');
c.setAuthorityPrefix('ROLE_');Wrapping in JwtAuthenticationConverter
Wrap the authorities converter inside a JwtAuthenticationConverter, which produces the final authentication token.
JwtAuthenticationConverter conv = new JwtAuthenticationConverter();
conv.setJwtGrantedAuthoritiesConverter(c);Registering the Converter
Tell the resource server to use your converter inside the JWT configuration.
http.oauth2ResourceServer(o -> o
.jwt(j -> j.jwtAuthenticationConverter(conv)));Nested Claims
Some providers nest roles, e.g. Keycloak uses realm_access.roles. The simple converter cannot read nested paths, so write a lambda converter that drills into the structure.
Converter<Jwt, Collection<GrantedAuthority>> conv = jwt -> {
Map<String,Object> realm = jwt.getClaim('realm_access');
List<String> roles = (List<String>) realm.get('roles');
return roles.stream()
.map(r -> new SimpleGrantedAuthority('ROLE_' + r))
.collect(Collectors.toList());
};Combining Scopes and Roles
You may want both scope-based and role-based authorities. Merge two converters' results so a single principal carries both SCOPE_ and ROLE_ authorities.
Customizing the Principal Name
By default the principal name is the sub claim. Override setPrincipalClaimName if you prefer to identify users by, say, preferred_username.
conv.setPrincipalClaimName('preferred_username');Verifying the Mapping
Test with a mock JWT that carries the roles claim and assert the request succeeds only when the expected authority is present.
mockMvc.perform(get('/api/admin')
.with(jwt().authorities(new SimpleGrantedAuthority('ROLE_admin'))))
.andExpect(status().isOk());Quick Check
Test your understanding of claim-to-authority mapping.
Recap
You learned to map JWT claims to Spring authorities:
- Default mapping turns
scopeintoSCOPE_authorities - Use
JwtGrantedAuthoritiesConverterto read custom role claims - Write a lambda converter for nested claims like
realm_access.roles - Register it via
jwtAuthenticationConverter
This gives your resource server precise, claim-driven access control.
Aprenda Java com um tutor de IA — grátis
Escreva e execute código real no seu navegador, obtenha ajuda instantânea de um tutor de IA 24/7 e continue de onde parou na web ou no app.
- Cursos
- 12
- Aulas
- 48
Perguntas Frequentes
A aula “Mapeando declarações JWT para autoridades do Spring” é grátis?
Sim — o texto completo de “Mapeando declarações JWT para autoridades do Spring” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Spring Security 6 & JWT Authentication, atualize para CoddyKit PRO. O curso de Spring Security 6 & JWT Authentication inclui 4 aulas no total.
O que vou aprender em “Mapeando declarações JWT para autoridades do Spring”?
Aprenda como um servidor de recursos converte declarações JWT em GrantedAuthorities do Spring Security usando JwtAuthenticationConverter para obter um controle de acesso detalhado. Você pratica Spring Security 6 & JWT Authentication com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.
Preciso ter experiência prévia para começar Spring Security 6 & JWT Authentication?
Nenhuma experiência prévia é necessária. Spring Security 6 & JWT Authentication no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 4 de 4.
Quanto tempo leva a aula “Mapeando declarações JWT para autoridades do Spring”?
A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.
Posso escrever e executar código nesta aula de Spring Security 6 & JWT Authentication?
Sim. Cada aula de Spring Security 6 & JWT Authentication inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.
Todas as aulas deste curso
- Configuração de um servidor de recursos
- Decodificação e validação de JWTs
- Imposição de escopos e declarações
- Mapeando declarações JWT para autoridades do Spring