VeryWall 认证中心

接入文档

让任何网站 / 应用通过 VeryWall 实现“一次登录、全网通行”。本文档使用标准 OAuth 2.1 授权码模式。

第 1 步:登记你的应用

联系管理员在 管理控制台 登记站点,获得:

本仓库自带的 sample-client/ 子工程即是一个可运行的接入示例(client_id=demo-web):cd sample-client && mvn spring-boot:run(端口 8090),浏览器打开 http://127.0.0.1:8090 即可体验完整登录 / 登出。

第 2 步:Spring Boot 应用接入(示例)

# application.yml
spring:
  security:
    oauth2:
      client:
        registration:
          verywall:
            client-id: demo-web
            client-secret: demo-web-secret
            # offline_access:需要后台刷新令牌(refresh_token)时申请
            scope: openid, profile, email, offline_access
            authorization-grant-type: authorization_code
            redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
        provider:
          verywall:
            issuer-uri: https://sso.veryware.com

依赖:spring-boot-starter-oauth2-client + spring-boot-starter-thymeleaf。之后在需要登录的接口放行前加登录跳转,或直接保护路由:

@Controller
public class HomeController {
    // 访问 /profile 未登录时自动跳转 VeryWall 登录
    @GetMapping("/profile")
    public String profile(@AuthenticationPrincipal OidcUser user, Model model) {
        model.addAttribute("name", user.getFullName());
        model.addAttribute("email", user.getEmail());
        model.addAttribute("claims", user.getClaims());
        return "profile";
    }
}

第 3 步:其他语言 / 通用协议

所有端点均可从 OIDC Discovery 自动发现:

GET https://sso.veryware.com/.well-known/openid-configuration

手工发起授权(浏览器跳转):

GET https://sso.veryware.com/oauth2/authorize?response_type=code
    &client_id=demo-web
    &redirect_uri=http://127.0.0.1:8090/login/oauth2/code/verywall
    &scope=openid%20profile%20email
    &state=随机值防CSRF

用授权码换取令牌(服务器端,HTTP Basic 携带 client 凭据):

POST https://sso.veryware.com/oauth2/token
Authorization: Basic base64(demo-web:demo-web-secret)
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code
&code=上一步得到的code
&redirect_uri=http://127.0.0.1:8090/login/oauth2/code/verywall

校验并读取用户信息(JWT 使用 https://sso.veryware.com/oauth2/jwks 的公钥验签;也可调用 UserInfo 端点):

GET https://sso.veryware.com/userinfo
Authorization: Bearer <access_token>

常用说明