0Pricing
Spring Security 6 & JWT Authentication · บทเรียน

การตั้งค่าไคลเอ็นต์ OAuth2

กำหนดค่าแอปพลิเคชันของคุณให้ทำหน้าที่เป็นไคลเอ็นต์ OAuth2 โดยระบุรายละเอียดการลงทะเบียนสำหรับผู้ให้บริการต่าง ๆ

การตั้งค่าไคลเอ็นต์ OAuth2 เป็นบทเรียน Spring Security 6 & JWT Authentication ฟรีบน CoddyKit นี่คือบทเรียนที่ 1 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Spring Security 6 & JWT Authentication และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

What is an OAuth2 Client?

In OAuth2, an OAuth2 Client is an application that wants to access resources on behalf of a user from a Resource Server. Think of it as your app asking permission to use another service (like Google or GitHub) on your behalf.

It's not the user, but an application acting for the user.

Why Configure Our App?

To use an external service's API (e.g., getting user profiles, posting updates), your application needs to be recognized by that service. This recognition process is called client registration.

  • Your app gets a unique identity.
  • The service knows who is requesting access.
  • It enables secure communication and authorization.

Key Client Registration Details

When you register your application with an OAuth2 Authorization Server (the service that grants access), you'll typically provide and receive:

  • Client ID: A public identifier for your application.
  • Client Secret: A confidential key used to authenticate your app.
  • Redirect URI(s): Where the Authorization Server sends the user back after authorization.

Spring Security as an OAuth2 Client

Spring Security makes it incredibly easy to configure your Spring Boot application to act as an OAuth2 Client. It handles much of the complex OAuth2 flow automatically.

All you need to do is provide the necessary registration details for the external service you want to connect to.

Client Configuration File

Spring Security's OAuth2 client configuration lives primarily in your application.yml or application.properties file.

You'll use two main prefixes:

  • spring.security.oauth2.client.registration: Defines details about your app's registration with a specific provider.
  • spring.security.oauth2.client.provider: Defines details about the OAuth2 provider itself (e.g., its authorization endpoint).

Setting Up a Provider

Under spring.security.oauth2.client.provider.[provider-name], you define the endpoints of the external OAuth2 service. For example, for a provider named github:

  • authorization-uri: Where users go to authorize your app.
  • token-uri: Where your app exchanges codes for tokens.
  • user-info-uri: Where your app fetches user details.

Often, Spring Boot can auto-configure these for popular providers if you just provide the client-id and client-secret.

Registering Your Client App

Under spring.security.oauth2.client.registration.[registration-id], you specify your app's unique registration details for a given provider. The registration-id acts as a unique name for your specific client configuration.

  • provider: Links to a defined provider (e.g., github).
  • client-id: Your app's public ID.
  • client-secret: Your app's secret key.
  • redirect-uri: The callback URL.
  • scope: Permissions your app requests (e.g., read:user).
  • authorization-grant-type: The OAuth2 flow used (e.g., authorization_code).

Example: GitHub Client Setup

Let's look at a concrete example using GitHub. You would first register your application on GitHub's developer settings to get a Client ID and Client Secret.

Then, configure your application.yml:

spring:
  security:
    oauth2:
      client:
        registration:
          github:
            client-id: your-github-client-id
            client-secret: your-github-client-secret
            redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
            scope: read:user,user:email
        provider:
          github:
            authorization-uri: https://github.com/login/oauth/authorize
            token-uri: https://github.com/login/oauth/access_token
            user-info-uri: https://api.github.com/user

Minimal Spring Boot App

To enable OAuth2 client functionality, ensure you have the spring-boot-starter-oauth2-client dependency. Spring Boot will automatically detect the configuration and set up the necessary filters.

Here's a basic Spring Boot application entry point:

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
import java.security.Principal;

@SpringBootApplication
@RestController
public class Oauth2ClientApp {

    public static void main(String[] args) {
        SpringApplication.run(Oauth2ClientApp.class, args);
    }

    @GetMapping("/")
    public String welcome(Principal principal) {
        if (principal != null) {
            return "Hello, " + principal.getName() + "! You are logged in with OAuth2.";
        }
        return "Hello! Please log in with OAuth2.";
    }
}

The Automated OAuth2 Flow

Once configured, Spring Security automatically:

  • Redirects unauthenticated users to the configured Authorization Server's login page.
  • Handles the authorization code exchange after the user grants permission.
  • Fetches user details from the user-info-uri.
  • Populates the SecurityContext with the authenticated user.

This significantly simplifies implementing OAuth2 client logic.

Quick Check: Client Config

You're setting up a Spring Boot application to act as an OAuth2 client for an external service. Which of the following properties is primarily used to identify your application to the external service, and should be kept confidential?

Recap: OAuth2 Client Setup

You've learned how to configure your Spring Boot application as an OAuth2 Client. We covered:

  • The role of an OAuth2 Client.
  • Key configuration properties like client-id and client-secret.
  • How to use application.yml for client and provider registration.
  • Spring Security's automatic handling of the OAuth2 flow.

Next, we'll dive into integrating specific social login providers like Google and GitHub in more detail!

คำถามที่พบบ่อย

บทเรียน “การตั้งค่าไคลเอ็นต์ OAuth2” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “การตั้งค่าไคลเอ็นต์ OAuth2” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Spring Security 6 & JWT Authentication ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “การตั้งค่าไคลเอ็นต์ OAuth2”

กำหนดค่าแอปพลิเคชันของคุณให้ทำหน้าที่เป็นไคลเอ็นต์ OAuth2 โดยระบุรายละเอียดการลงทะเบียนสำหรับผู้ให้บริการต่าง ๆ คุณปฏิบัติ Spring Security 6 & JWT Authentication ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Spring Security 6 & JWT Authentication หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Spring Security 6 & JWT Authentication บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 1 จากทั้งหมด 4 บทเรียน

บทเรียน “การตั้งค่าไคลเอ็นต์ OAuth2” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Spring Security 6 & JWT Authentication นี้ได้ไหม

ได้ บทเรียน Spring Security 6 & JWT Authentication ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. การตั้งค่าไคลเอ็นต์ OAuth2
  2. การผสานรวมการเข้าสู่ระบบผ่านโซเชียล
  3. ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง
  4. การเข้าถึงผู้ใช้ OAuth2 ที่ผ่านการตรวจสอบสิทธิ์
← กลับไปที่ Spring Security 6 & JWT Authentication