diff --git a/oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/authentication/JwtGrantedAuthoritiesConverter.java b/oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/authentication/JwtGrantedAuthoritiesConverter.java index a0d1dc43a2..6ca21b2bdb 100644 --- a/oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/authentication/JwtGrantedAuthoritiesConverter.java +++ b/oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/authentication/JwtGrantedAuthoritiesConverter.java @@ -53,7 +53,7 @@ public final class JwtGrantedAuthoritiesConverter implements Converter authoritiesClaimNames = WELL_KNOWN_AUTHORITIES_CLAIM_NAMES; /** * Extract {@link GrantedAuthority}s from the given {@link Jwt}. @@ -102,14 +102,11 @@ public void setAuthoritiesClaimDelimiter(String authoritiesClaimDelimiter) { */ public void setAuthoritiesClaimName(String authoritiesClaimName) { Assert.hasText(authoritiesClaimName, "authoritiesClaimName cannot be empty"); - this.authoritiesClaimName = authoritiesClaimName; + this.authoritiesClaimNames = Collections.singletonList(authoritiesClaimName); } private String getAuthoritiesClaimName(Jwt jwt) { - if (this.authoritiesClaimName != null) { - return this.authoritiesClaimName; - } - for (String claimName : WELL_KNOWN_AUTHORITIES_CLAIM_NAMES) { + for (String claimName : this.authoritiesClaimNames) { if (jwt.hasClaim(claimName)) { return claimName; }