This commit is contained in:
Phillip Webb
2017-02-27 14:02:05 -08:00
parent 47fd5f4fac
commit 5867cd6175
19 changed files with 113 additions and 80 deletions

View File

@@ -109,24 +109,7 @@ public class EmbeddedLdapAutoConfiguration {
this.embeddedProperties.getCredential().getUsername(),
this.embeddedProperties.getCredential().getPassword());
}
if (!this.embeddedProperties.getValidation().isEnabled()) {
config.setSchema(null);
}
else {
Resource schema = this.embeddedProperties.getValidation().getSchema();
if (schema != null) {
try {
config.setSchema(Schema.mergeSchemas(Schema.getDefaultStandardSchema(),
Schema.getSchema(schema.getInputStream())));
}
catch (Exception ex) {
throw new IllegalStateException(
"Unable to load schema " + schema.getDescription(), ex);
}
}
}
setSchema(config);
InMemoryListenerConfig listenerConfig = InMemoryListenerConfig
.createLDAPConfig("LDAP", this.embeddedProperties.getPort());
config.setListenerConfigs(listenerConfig);
@@ -137,6 +120,29 @@ public class EmbeddedLdapAutoConfiguration {
return this.server;
}
private void setSchema(InMemoryDirectoryServerConfig config) {
if (!this.embeddedProperties.getValidation().isEnabled()) {
config.setSchema(null);
return;
}
Resource schema = this.embeddedProperties.getValidation().getSchema();
if (schema != null) {
setSchema(config, schema);
}
}
private void setSchema(InMemoryDirectoryServerConfig config, Resource resource) {
try {
Schema defaultSchema = Schema.getDefaultStandardSchema();
Schema schema = Schema.getSchema(resource.getInputStream());
config.setSchema(Schema.mergeSchemas(defaultSchema, schema));
}
catch (Exception ex) {
throw new IllegalStateException(
"Unable to load schema " + resource.getDescription(), ex);
}
}
private boolean hasCredentials(Credential credential) {
return StringUtils.hasText(credential.getUsername())
&& StringUtils.hasText(credential.getPassword());

View File

@@ -203,31 +203,36 @@ public class ResourceServerProperties implements Validator, BeanFactoryAware {
return;
}
ResourceServerProperties resource = (ResourceServerProperties) target;
validate(resource, errors);
}
private void validate(ResourceServerProperties target, Errors errors) {
if ((StringUtils.hasText(this.jwt.getKeyUri())
|| StringUtils.hasText(this.jwt.getKeyValue()))
&& StringUtils.hasText(this.jwk.getKeySetUri())) {
errors.reject("ambiguous.keyUri", "Only one of jwt.keyUri (or jwt.keyValue) and jwk.keySetUri should be configured.");
errors.reject("ambiguous.keyUri",
"Only one of jwt.keyUri (or jwt.keyValue) and "
+ "jwk.keySetUri should be configured.");
}
else {
if (StringUtils.hasText(this.clientId)) {
if (!StringUtils.hasText(this.clientSecret)) {
if (!StringUtils.hasText(resource.getUserInfoUri())) {
if (!StringUtils.hasText(target.getUserInfoUri())) {
errors.rejectValue("userInfoUri", "missing.userInfoUri",
"Missing userInfoUri (no client secret available)");
}
}
else {
if (isPreferTokenInfo()
&& !StringUtils.hasText(resource.getTokenInfoUri())) {
&& !StringUtils.hasText(target.getTokenInfoUri())) {
if (StringUtils.hasText(getJwt().getKeyUri())
|| StringUtils.hasText(getJwt().getKeyValue())
|| StringUtils.hasText(getJwk().getKeySetUri())) {
// It's a JWT decoder
return;
}
if (!StringUtils.hasText(resource.getUserInfoUri())) {
if (!StringUtils.hasText(target.getUserInfoUri())) {
errors.rejectValue("tokenInfoUri", "missing.tokenInfoUri",
"Missing tokenInfoUri and userInfoUri and there is no "
+ "JWT verifier key");
@@ -236,7 +241,6 @@ public class ResourceServerProperties implements Validator, BeanFactoryAware {
}
}
}
}
private int countBeans(Class<?> type) {
@@ -294,9 +298,8 @@ public class ResourceServerProperties implements Validator, BeanFactoryAware {
public class Jwk {
/**
* The URI to get verification keys to verify the JWT token.
* This can be set when the authorization server returns a
* set of verification keys.
* The URI to get verification keys to verify the JWT token. This can be set when
* the authorization server returns a set of verification keys.
*/
private String keySetUri;

View File

@@ -26,9 +26,9 @@ import org.springframework.validation.Validator;
import org.springframework.validation.beanvalidation.SpringValidatorAdapter;
/**
* Wraps a {@link SpringValidatorAdapter} so that only the Spring's {@link Validator}
* type is exposed. This prevents such a bean to expose both the Spring and JSR-303
* validator contract at the same time.
* Wraps a {@link SpringValidatorAdapter} so that only the Spring's {@link Validator} type
* is exposed. This prevents such a bean to expose both the Spring and JSR-303 validator
* contract at the same time.
*
* @author Stephane Nicoll
*/
@@ -36,6 +36,7 @@ class SpringValidatorAdapterWrapper
implements Validator, ApplicationContextAware, InitializingBean, DisposableBean {
private final SpringValidatorAdapter target;
private final boolean managed;
SpringValidatorAdapterWrapper(SpringValidatorAdapter target, boolean managed) {
@@ -61,8 +62,8 @@ class SpringValidatorAdapterWrapper
public void setApplicationContext(ApplicationContext applicationContext)
throws BeansException {
if (!this.managed && this.target instanceof ApplicationContextAware) {
((ApplicationContextAware) this.target).setApplicationContext(
applicationContext);
((ApplicationContextAware) this.target)
.setApplicationContext(applicationContext);
}
}

View File

@@ -575,15 +575,17 @@ public class WebMvcAutoConfiguration {
try {
if (this.userDefinedValidator != null) {
if (this.userDefinedValidator instanceof javax.validation.Validator) {
return wrap((javax.validation.Validator) this.userDefinedValidator, false);
return wrap(
(javax.validation.Validator) this.userDefinedValidator,
false);
}
else {
return this.userDefinedValidator;
}
}
else {
return wrap(this.applicationContext.getBean(
javax.validation.Validator.class), true);
return wrap(this.applicationContext
.getBean(javax.validation.Validator.class), true);
}
}
catch (NoSuchBeanDefinitionException ex) {

View File

@@ -32,11 +32,11 @@ import static org.assertj.core.api.Assertions.assertThat;
*/
public class GroovyTemplateAvailabilityProviderTests {
private final TemplateAvailabilityProvider provider = new GroovyTemplateAvailabilityProvider();
private TemplateAvailabilityProvider provider = new GroovyTemplateAvailabilityProvider();
private final ResourceLoader resourceLoader = new DefaultResourceLoader();
private ResourceLoader resourceLoader = new DefaultResourceLoader();
private final MockEnvironment environment = new MockEnvironment();
private MockEnvironment environment = new MockEnvironment();
@Test
public void availabilityOfTemplateInDefaultLocation() {

View File

@@ -390,11 +390,13 @@ public class OAuth2AutoConfigurationTests {
}
@Test
public void resourceServerConditionWhenJwkConfigurationPresentShouldMatch() throws Exception {
public void resourceServerConditionWhenJwkConfigurationPresentShouldMatch()
throws Exception {
this.context = new AnnotationConfigEmbeddedWebApplicationContext();
EnvironmentTestUtils.addEnvironment(this.context,
"security.oauth2.resource.jwk.key-set-uri:http://my-auth-server/token_keys");
this.context.register(ResourceServerConfiguration.class, MinimalSecureWebApplication.class);
this.context.register(ResourceServerConfiguration.class,
MinimalSecureWebApplication.class);
this.context.refresh();
assertThat(countBeans(RESOURCE_SERVER_CONFIG)).isEqualTo(1);
}

View File

@@ -68,13 +68,15 @@ public class ResourceServerPropertiesTests {
}
@Test
public void validateWhenBothJwtAndJwtKeyConfigurationPresentShouldFail() throws Exception {
public void validateWhenBothJwtAndJwtKeyConfigurationPresentShouldFail()
throws Exception {
this.properties.getJwk().setKeySetUri("http://my-auth-server/token_keys");
this.properties.getJwt().setKeyUri("http://my-auth-server/token_key");
setListableBeanFactory();
Errors errors = mock(Errors.class);
this.properties.validate(this.properties, errors);
verify(errors).reject("ambiguous.keyUri", "Only one of jwt.keyUri (or jwt.keyValue) and jwk.keySetUri should be configured.");
verify(errors).reject("ambiguous.keyUri",
"Only one of jwt.keyUri (or jwt.keyValue) and jwk.keySetUri should be configured.");
}
@@ -89,14 +91,19 @@ public class ResourceServerPropertiesTests {
private void setListableBeanFactory() {
ListableBeanFactory beanFactory = new StaticWebApplicationContext() {
@Override
public String[] getBeanNamesForType(Class<?> type, boolean includeNonSingletons, boolean allowEagerInit) {
if (type.isAssignableFrom(ResourceServerTokenServicesConfiguration.class)) {
return new String[]{"ResourceServerTokenServicesConfiguration"};
public String[] getBeanNamesForType(Class<?> type,
boolean includeNonSingletons, boolean allowEagerInit) {
if (type.isAssignableFrom(
ResourceServerTokenServicesConfiguration.class)) {
return new String[] { "ResourceServerTokenServicesConfiguration" };
}
return new String[0];
}
};
this.properties.setBeanFactory(beanFactory);
}
}

View File

@@ -57,8 +57,8 @@ public class SpringValidatorAdapterWrapperTests {
SpringValidatorAdapterWrapper wrapper = load(
LocalValidatorFactoryBeanConfig.class);
assertThat(wrapper.supports(SampleData.class)).isTrue();
MapBindingResult errors = new MapBindingResult(
new HashMap<String, Object>(), "test");
MapBindingResult errors = new MapBindingResult(new HashMap<String, Object>(),
"test");
wrapper.validate(new SampleData(40), errors);
assertThat(errors.getErrorCount()).isEqualTo(1);
}
@@ -66,8 +66,8 @@ public class SpringValidatorAdapterWrapperTests {
@Test
public void wrapperInvokesCallbackOnNonManagedBean() {
load(NonManagedBeanConfig.class);
LocalValidatorFactoryBean validator = this.context.getBean(
NonManagedBeanConfig.class).validator;
LocalValidatorFactoryBean validator = this.context
.getBean(NonManagedBeanConfig.class).validator;
verify(validator, times(1)).setApplicationContext(any(ApplicationContext.class));
verify(validator, times(1)).afterPropertiesSet();
verify(validator, times(0)).destroy();
@@ -79,8 +79,8 @@ public class SpringValidatorAdapterWrapperTests {
@Test
public void wrapperDoesNotInvokeCallbackOnManagedBean() {
load(ManagedBeanConfig.class);
LocalValidatorFactoryBean validator = this.context.getBean(
ManagedBeanConfig.class).validator;
LocalValidatorFactoryBean validator = this.context
.getBean(ManagedBeanConfig.class).validator;
verify(validator, times(0)).setApplicationContext(any(ApplicationContext.class));
verify(validator, times(0)).afterPropertiesSet();
verify(validator, times(0)).destroy();
@@ -115,8 +115,8 @@ public class SpringValidatorAdapterWrapperTests {
@Configuration
static class NonManagedBeanConfig {
private final LocalValidatorFactoryBean validator
= mock(LocalValidatorFactoryBean.class);
private final LocalValidatorFactoryBean validator = mock(
LocalValidatorFactoryBean.class);
@Bean
public SpringValidatorAdapterWrapper wrapper() {
@@ -128,8 +128,8 @@ public class SpringValidatorAdapterWrapperTests {
@Configuration
static class ManagedBeanConfig {
private final LocalValidatorFactoryBean validator
= mock(LocalValidatorFactoryBean.class);
private final LocalValidatorFactoryBean validator = mock(
LocalValidatorFactoryBean.class);
@Bean
public SpringValidatorAdapterWrapper wrapper() {

View File

@@ -662,8 +662,8 @@ public class WebMvcAutoConfigurationTests {
.isEmpty();
assertThat(this.context.getBeansOfType(Validator.class)).hasSize(1);
Validator validator = this.context.getBean(Validator.class);
assertThat(validator).isSameAs(this.context.getBean(MvcValidator.class)
.validator);
assertThat(validator)
.isSameAs(this.context.getBean(MvcValidator.class).validator);
}
@Test
@@ -900,7 +900,7 @@ public class WebMvcAutoConfigurationTests {
@Configuration
protected static class MvcJsr303Validator extends WebMvcConfigurerAdapter {
private final LocalValidatorFactoryBean validator = new LocalValidatorFactoryBean();
private final LocalValidatorFactoryBean validator = new LocalValidatorFactoryBean();
@Override
public Validator getValidator() {