Remove unused properties and constants
Since the autoconfig totally backs off in the presence of a WebSecurityConfigurerAdapter, there is no need to order them ahead of/after the one provided by Spring Boot. See gh-7958
This commit is contained in:
@@ -1,42 +0,0 @@
|
||||
/*
|
||||
* Copyright 2012-2015 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.boot.autoconfigure.security;
|
||||
|
||||
/**
|
||||
* Security authorization modes as specified in {@link SecurityProperties}.
|
||||
*
|
||||
* @author Phillip Webb
|
||||
* @since 1.2.2
|
||||
*/
|
||||
public enum SecurityAuthorizeMode {
|
||||
|
||||
/**
|
||||
* Must be a member of one of the security roles.
|
||||
*/
|
||||
ROLE,
|
||||
|
||||
/**
|
||||
* Must be an authenticated user.
|
||||
*/
|
||||
AUTHENTICATED,
|
||||
|
||||
/**
|
||||
* No security authorization is setup.
|
||||
*/
|
||||
NONE
|
||||
|
||||
}
|
||||
@@ -34,14 +34,6 @@ import org.springframework.core.Ordered;
|
||||
@ConfigurationProperties(prefix = "security")
|
||||
public class SecurityProperties implements SecurityPrerequisite {
|
||||
|
||||
/**
|
||||
* Order before the basic authentication access control provided by Boot. This is a
|
||||
* useful place to put user-defined access rules if you want to override the default
|
||||
* access rules.
|
||||
*/
|
||||
public static final int ACCESS_OVERRIDE_ORDER = SecurityProperties.BASIC_AUTH_ORDER
|
||||
- 2;
|
||||
|
||||
/**
|
||||
* Order applied to the WebSecurityConfigurerAdapter that is used to configure basic
|
||||
* authentication for application endpoints. If you want to add your own
|
||||
|
||||
@@ -33,8 +33,7 @@ import org.springframework.security.oauth2.config.annotation.web.configuration.E
|
||||
* {@link WebSecurityConfigurerAdapter} provided by the user and annotated with
|
||||
* {@code @EnableOAuth2Sso}, it is enhanced by adding an authentication filter and an
|
||||
* authentication entry point. If the user only has {@code @EnableOAuth2Sso} but not on a
|
||||
* WebSecurityConfigurerAdapter then one is added with all paths secured and with an order
|
||||
* that puts it ahead of the default HTTP Basic security chain in Spring Boot.
|
||||
* WebSecurityConfigurerAdapter then one is added with all paths secured.
|
||||
*
|
||||
* @author Dave Syer
|
||||
* @since 1.3.0
|
||||
|
||||
@@ -17,31 +17,26 @@
|
||||
package org.springframework.boot.autoconfigure.security.oauth2.client;
|
||||
|
||||
import org.springframework.boot.autoconfigure.condition.ConditionOutcome;
|
||||
import org.springframework.boot.autoconfigure.security.SecurityProperties;
|
||||
import org.springframework.boot.autoconfigure.security.oauth2.client.OAuth2SsoDefaultConfiguration.NeedsWebSecurityCondition;
|
||||
import org.springframework.context.ApplicationContext;
|
||||
import org.springframework.context.annotation.ConditionContext;
|
||||
import org.springframework.context.annotation.Conditional;
|
||||
import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.core.Ordered;
|
||||
import org.springframework.core.type.AnnotatedTypeMetadata;
|
||||
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
|
||||
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
|
||||
import org.springframework.util.ClassUtils;
|
||||
|
||||
/**
|
||||
* Configuration for OAuth2 Single Sign On (SSO). If the user only has
|
||||
* {@code @EnableOAuth2Sso} but not on a {@code WebSecurityConfigurerAdapter} then one is
|
||||
* added with all paths secured and with an order that puts it ahead of the default HTTP
|
||||
* Basic security chain in Spring Boot.
|
||||
* added with all paths secured.
|
||||
*
|
||||
* @author Dave Syer
|
||||
* @since 1.3.0
|
||||
*/
|
||||
@Configuration
|
||||
@Conditional(NeedsWebSecurityCondition.class)
|
||||
public class OAuth2SsoDefaultConfiguration extends WebSecurityConfigurerAdapter
|
||||
implements Ordered {
|
||||
public class OAuth2SsoDefaultConfiguration extends WebSecurityConfigurerAdapter {
|
||||
|
||||
private final ApplicationContext applicationContext;
|
||||
|
||||
@@ -59,21 +54,6 @@ public class OAuth2SsoDefaultConfiguration extends WebSecurityConfigurerAdapter
|
||||
new SsoSecurityConfigurer(this.applicationContext).configure(http);
|
||||
}
|
||||
|
||||
@Override
|
||||
public int getOrder() {
|
||||
if (this.sso.getFilterOrder() != null) {
|
||||
return this.sso.getFilterOrder();
|
||||
}
|
||||
if (ClassUtils.isPresent(
|
||||
"org.springframework.boot.actuate.autoconfigure.ManagementServerProperties",
|
||||
null)) {
|
||||
// If > BASIC_AUTH_ORDER then the existing rules for the actuator
|
||||
// endpoints will take precedence. This value is < BASIC_AUTH_ORDER.
|
||||
return SecurityProperties.ACCESS_OVERRIDE_ORDER - 5;
|
||||
}
|
||||
return SecurityProperties.ACCESS_OVERRIDE_ORDER;
|
||||
}
|
||||
|
||||
protected static class NeedsWebSecurityCondition extends EnableOAuth2SsoCondition {
|
||||
|
||||
@Override
|
||||
|
||||
@@ -35,12 +35,6 @@ public class OAuth2SsoProperties {
|
||||
*/
|
||||
private String loginPath = DEFAULT_LOGIN_PATH;
|
||||
|
||||
/**
|
||||
* Filter order to apply if not providing an explicit WebSecurityConfigurerAdapter (in
|
||||
* which case the order can be provided there instead).
|
||||
*/
|
||||
private Integer filterOrder;
|
||||
|
||||
public String getLoginPath() {
|
||||
return this.loginPath;
|
||||
}
|
||||
@@ -49,12 +43,4 @@ public class OAuth2SsoProperties {
|
||||
this.loginPath = loginPath;
|
||||
}
|
||||
|
||||
public Integer getFilterOrder() {
|
||||
return this.filterOrder;
|
||||
}
|
||||
|
||||
public void setFilterOrder(Integer filterOrder) {
|
||||
this.filterOrder = filterOrder;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -19,8 +19,6 @@ package org.springframework.boot.autoconfigure.security.oauth2.resource;
|
||||
import java.util.Map;
|
||||
|
||||
import org.springframework.beans.BeanUtils;
|
||||
import org.springframework.beans.BeansException;
|
||||
import org.springframework.beans.factory.config.BeanPostProcessor;
|
||||
import org.springframework.boot.autoconfigure.condition.ConditionMessage;
|
||||
import org.springframework.boot.autoconfigure.condition.ConditionOutcome;
|
||||
import org.springframework.boot.autoconfigure.condition.ConditionalOnBean;
|
||||
@@ -32,8 +30,6 @@ import org.springframework.boot.autoconfigure.security.SecurityProperties;
|
||||
import org.springframework.boot.autoconfigure.security.oauth2.resource.OAuth2ResourceServerConfiguration.ResourceServerCondition;
|
||||
import org.springframework.boot.context.properties.bind.Bindable;
|
||||
import org.springframework.boot.context.properties.bind.Binder;
|
||||
import org.springframework.context.ApplicationContext;
|
||||
import org.springframework.context.ApplicationContextAware;
|
||||
import org.springframework.context.annotation.Bean;
|
||||
import org.springframework.context.annotation.Condition;
|
||||
import org.springframework.context.annotation.ConditionContext;
|
||||
@@ -85,12 +81,6 @@ public class OAuth2ResourceServerConfiguration {
|
||||
return new ResourceSecurityConfigurer(this.resource);
|
||||
}
|
||||
|
||||
@Bean
|
||||
public static ResourceServerFilterChainOrderProcessor resourceServerFilterChainOrderProcessor(
|
||||
ResourceServerProperties properties) {
|
||||
return new ResourceServerFilterChainOrderProcessor(properties);
|
||||
}
|
||||
|
||||
protected static class ResourceSecurityConfigurer
|
||||
extends ResourceServerConfigurerAdapter {
|
||||
|
||||
@@ -113,45 +103,6 @@ public class OAuth2ResourceServerConfiguration {
|
||||
|
||||
}
|
||||
|
||||
private static final class ResourceServerFilterChainOrderProcessor
|
||||
implements BeanPostProcessor, ApplicationContextAware {
|
||||
|
||||
private final ResourceServerProperties properties;
|
||||
|
||||
private ApplicationContext context;
|
||||
|
||||
private ResourceServerFilterChainOrderProcessor(
|
||||
ResourceServerProperties properties) {
|
||||
this.properties = properties;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setApplicationContext(ApplicationContext context)
|
||||
throws BeansException {
|
||||
this.context = context;
|
||||
}
|
||||
|
||||
@Override
|
||||
public Object postProcessBeforeInitialization(Object bean, String beanName)
|
||||
throws BeansException {
|
||||
return bean;
|
||||
}
|
||||
|
||||
@Override
|
||||
public Object postProcessAfterInitialization(Object bean, String beanName)
|
||||
throws BeansException {
|
||||
if (bean instanceof ResourceServerConfiguration) {
|
||||
if (this.context.getBeanNamesForType(ResourceServerConfiguration.class,
|
||||
false, false).length == 1) {
|
||||
ResourceServerConfiguration config = (ResourceServerConfiguration) bean;
|
||||
config.setOrder(this.properties.getFilterOrder());
|
||||
}
|
||||
}
|
||||
return bean;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
protected static class ResourceServerCondition extends SpringBootCondition
|
||||
implements ConfigurationCondition {
|
||||
|
||||
|
||||
@@ -25,7 +25,6 @@ import org.springframework.beans.factory.BeanFactory;
|
||||
import org.springframework.beans.factory.BeanFactoryAware;
|
||||
import org.springframework.beans.factory.BeanFactoryUtils;
|
||||
import org.springframework.beans.factory.ListableBeanFactory;
|
||||
import org.springframework.boot.autoconfigure.security.SecurityProperties;
|
||||
import org.springframework.boot.context.properties.ConfigurationProperties;
|
||||
import org.springframework.security.oauth2.common.DefaultOAuth2AccessToken;
|
||||
import org.springframework.security.oauth2.config.annotation.web.configuration.AuthorizationServerEndpointsConfiguration;
|
||||
@@ -84,12 +83,6 @@ public class ResourceServerProperties implements BeanFactoryAware {
|
||||
|
||||
private Jwk jwk = new Jwk();
|
||||
|
||||
/**
|
||||
* The order of the filter chain used to authenticate tokens. Default puts it after
|
||||
* the actuator endpoints and before the default HTTP basic filter chain (catchall).
|
||||
*/
|
||||
private int filterOrder = SecurityProperties.ACCESS_OVERRIDE_ORDER - 1;
|
||||
|
||||
public ResourceServerProperties() {
|
||||
this(null, null);
|
||||
}
|
||||
@@ -180,14 +173,6 @@ public class ResourceServerProperties implements BeanFactoryAware {
|
||||
return this.clientSecret;
|
||||
}
|
||||
|
||||
public int getFilterOrder() {
|
||||
return this.filterOrder;
|
||||
}
|
||||
|
||||
public void setFilterOrder(int filterOrder) {
|
||||
this.filterOrder = filterOrder;
|
||||
}
|
||||
|
||||
@PostConstruct
|
||||
public void validate() {
|
||||
if (countBeans(AuthorizationServerEndpointsConfiguration.class) > 0) {
|
||||
|
||||
@@ -28,7 +28,6 @@ import org.springframework.aop.support.AopUtils;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.boot.autoconfigure.http.HttpMessageConvertersAutoConfiguration;
|
||||
import org.springframework.boot.autoconfigure.security.SecurityAutoConfiguration;
|
||||
import org.springframework.boot.autoconfigure.security.SecurityProperties;
|
||||
import org.springframework.boot.autoconfigure.security.oauth2.authserver.OAuth2AuthorizationServerConfiguration;
|
||||
import org.springframework.boot.autoconfigure.security.oauth2.method.OAuth2MethodSecurityConfiguration;
|
||||
import org.springframework.boot.autoconfigure.security.oauth2.resource.OAuth2ResourceServerConfiguration;
|
||||
@@ -45,7 +44,6 @@ import org.springframework.context.annotation.AnnotationConfigApplicationContext
|
||||
import org.springframework.context.annotation.Bean;
|
||||
import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.context.annotation.Import;
|
||||
import org.springframework.core.annotation.Order;
|
||||
import org.springframework.http.HttpEntity;
|
||||
import org.springframework.http.HttpHeaders;
|
||||
import org.springframework.http.HttpMethod;
|
||||
@@ -492,7 +490,6 @@ public class OAuth2AutoConfigurationTests {
|
||||
}
|
||||
|
||||
@Configuration
|
||||
@Order(SecurityProperties.ACCESS_OVERRIDE_ORDER)
|
||||
protected static class TestSecurityConfiguration
|
||||
extends WebSecurityConfigurerAdapter {
|
||||
|
||||
|
||||
Reference in New Issue
Block a user