Merge remote-tracking branch 'origin/3.1.x'

This commit is contained in:
Olga Maciaszek-Sharma
2022-05-18 13:21:17 +02:00
6 changed files with 79 additions and 156 deletions

View File

@@ -1,76 +0,0 @@
/*
* Copyright 2002-2022 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.cloud.config.server.config;
import org.apache.commons.logging.Log;
import org.apache.commons.logging.LogFactory;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.autoconfigure.AutoConfigureAfter;
import org.springframework.boot.autoconfigure.condition.ConditionalOnBean;
import org.springframework.boot.autoconfigure.condition.ConditionalOnMissingBean;
import org.springframework.boot.context.properties.EnableConfigurationProperties;
import org.springframework.cloud.bootstrap.encrypt.KeyProperties;
import org.springframework.cloud.config.server.encryption.LocatorTextEncryptor;
import org.springframework.cloud.config.server.encryption.TextEncryptorLocator;
import org.springframework.cloud.context.encrypt.EncryptorFactory;
import org.springframework.context.ApplicationContext;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.crypto.encrypt.Encryptors;
import org.springframework.security.crypto.encrypt.TextEncryptor;
import org.springframework.util.StringUtils;
/**
* Default text encryption auto-configuration.
*
* @author Olga Maciaszek-Sharma
* @since 3.1.2
*/
@Configuration(proxyBeanMethods = false)
@AutoConfigureAfter(RsaEncryptionAutoConfiguration.class)
@EnableConfigurationProperties
public class DefaultTextEncryptionAutoConfiguration {
private static final Log LOG = LogFactory.getLog(DefaultTextEncryptionAutoConfiguration.class);
@Autowired
ApplicationContext context;
@Bean
@ConditionalOnMissingBean
public KeyProperties keyProperties() {
return new KeyProperties();
}
@Bean
@ConditionalOnMissingBean(TextEncryptor.class)
@ConditionalOnBean(TextEncryptorLocator.class)
public TextEncryptor defaultLocatorBasedTextEncryptor(TextEncryptorLocator locator) {
return new LocatorTextEncryptor(locator);
}
@Bean
@ConditionalOnMissingBean(TextEncryptor.class)
public TextEncryptor defaultTextEncryptor(KeyProperties key) {
if (StringUtils.hasText(key.getKey())) {
return new EncryptorFactory(key.getSalt()).create(key.getKey());
}
return Encryptors.noOpText();
}
}

View File

@@ -17,20 +17,33 @@
package org.springframework.cloud.config.server.config;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.autoconfigure.AutoConfigureAfter;
import org.springframework.boot.autoconfigure.condition.ConditionalOnBean;
import org.springframework.boot.autoconfigure.condition.ConditionalOnClass;
import org.springframework.boot.autoconfigure.condition.ConditionalOnMissingBean;
import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty;
import org.springframework.boot.context.properties.EnableConfigurationProperties;
import org.springframework.cloud.bootstrap.encrypt.KeyProperties;
import org.springframework.cloud.bootstrap.encrypt.KeyProperties.KeyStore;
import org.springframework.cloud.bootstrap.encrypt.RsaProperties;
import org.springframework.cloud.config.server.encryption.CipherEnvironmentEncryptor;
import org.springframework.cloud.config.server.encryption.EnvironmentEncryptor;
import org.springframework.cloud.config.server.encryption.KeyStoreTextEncryptorLocator;
import org.springframework.cloud.config.server.encryption.LocatorTextEncryptor;
import org.springframework.cloud.config.server.encryption.SingleTextEncryptorLocator;
import org.springframework.cloud.config.server.encryption.TextEncryptorLocator;
import org.springframework.cloud.context.encrypt.EncryptorFactory;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.Import;
import org.springframework.security.crypto.encrypt.Encryptors;
import org.springframework.security.crypto.encrypt.TextEncryptor;
import org.springframework.security.rsa.crypto.KeyStoreKeyFactory;
import org.springframework.security.rsa.crypto.RsaAlgorithm;
import org.springframework.security.rsa.crypto.RsaSecretEncryptor;
import org.springframework.util.StringUtils;
/**
* Auto-configuration for text encryptors and environment encryptors (non-web stuff).
* Auto configuration for text encryptors and environment encryptors (non-web stuff).
* Users can provide beans of the same type as any or all of the beans defined here in
* application code to override the default behaviour.
*
@@ -41,14 +54,14 @@ import org.springframework.security.crypto.encrypt.TextEncryptor;
*
*/
@Configuration(proxyBeanMethods = false)
@AutoConfigureAfter(DefaultTextEncryptionAutoConfiguration.class)
@EnableConfigurationProperties
@Import(SingleTextEncryptorConfiguration.class)
public class EncryptionAutoConfiguration {
@Bean
@ConditionalOnBean(TextEncryptor.class)
@ConditionalOnMissingBean(TextEncryptorLocator.class)
public SingleTextEncryptorLocator singleTextEncryptorLocator(TextEncryptor encryptor) {
return new SingleTextEncryptorLocator(encryptor);
@ConditionalOnMissingBean
public KeyProperties keyProperties() {
return new KeyProperties();
}
@Bean
@@ -63,4 +76,57 @@ public class EncryptionAutoConfiguration {
return new CipherEnvironmentEncryptor(locator);
}
@Bean
@ConditionalOnMissingBean(TextEncryptor.class)
public TextEncryptor defaultTextEncryptor(@Autowired(required = false) TextEncryptorLocator locator,
KeyProperties key) {
if (locator != null) {
return new LocatorTextEncryptor(locator);
}
if (StringUtils.hasText(key.getKey())) {
return new EncryptorFactory(key.getSalt()).create(key.getKey());
}
return Encryptors.noOpText();
}
@Configuration(proxyBeanMethods = false)
@ConditionalOnClass(RsaSecretEncryptor.class)
@ConditionalOnProperty(prefix = "encrypt.key-store", value = "location", matchIfMissing = false)
protected static class KeyStoreConfiguration {
@Autowired
private KeyProperties key;
@Autowired
private RsaProperties rsaProperties;
@Bean
@ConditionalOnMissingBean
public TextEncryptorLocator textEncryptorLocator() {
KeyStore keyStore = key.getKeyStore();
KeyStoreTextEncryptorLocator locator = new KeyStoreTextEncryptorLocator(
new KeyStoreKeyFactory(keyStore.getLocation(), keyStore.getPassword().toCharArray(),
key.getKeyStore().getType()),
keyStore.getSecret(), keyStore.getAlias());
RsaAlgorithm algorithm = this.rsaProperties.getAlgorithm();
locator.setRsaAlgorithm(algorithm);
locator.setSalt(this.rsaProperties.getSalt());
locator.setStrong(this.rsaProperties.isStrong());
return locator;
}
}
}
@ConditionalOnBean(TextEncryptor.class)
@ConditionalOnMissingBean(TextEncryptorLocator.class)
@Configuration(proxyBeanMethods = false)
class SingleTextEncryptorConfiguration {
@Bean
public SingleTextEncryptorLocator textEncryptorLocator(TextEncryptor encryptor) {
return new SingleTextEncryptorLocator(encryptor);
}
}

View File

@@ -1,66 +0,0 @@
/*
* Copyright 2002-2022 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.cloud.config.server.config;
import org.springframework.boot.autoconfigure.condition.ConditionalOnClass;
import org.springframework.boot.autoconfigure.condition.ConditionalOnMissingBean;
import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty;
import org.springframework.boot.context.properties.EnableConfigurationProperties;
import org.springframework.cloud.bootstrap.encrypt.KeyProperties;
import org.springframework.cloud.bootstrap.encrypt.RsaProperties;
import org.springframework.cloud.config.server.encryption.KeyStoreTextEncryptorLocator;
import org.springframework.cloud.config.server.encryption.TextEncryptorLocator;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.rsa.crypto.KeyStoreKeyFactory;
import org.springframework.security.rsa.crypto.RsaAlgorithm;
import org.springframework.security.rsa.crypto.RsaSecretEncryptor;
/**
* Auto-configuration for RSA encryption.
*
* @author Olga Maciaszek-Sharma
* @since 3.1.2
*/
@Configuration(proxyBeanMethods = false)
@ConditionalOnProperty(prefix = "encrypt.key-store", value = "location")
@ConditionalOnClass(RsaSecretEncryptor.class)
@EnableConfigurationProperties
public class RsaEncryptionAutoConfiguration {
@Bean
@ConditionalOnMissingBean
public KeyProperties keyProperties() {
return new KeyProperties();
}
@Bean
@ConditionalOnMissingBean
public TextEncryptorLocator textEncryptorLocator(KeyProperties key, RsaProperties rsaProperties) {
KeyProperties.KeyStore keyStore = key.getKeyStore();
KeyStoreTextEncryptorLocator locator = new KeyStoreTextEncryptorLocator(
new KeyStoreKeyFactory(keyStore.getLocation(), keyStore.getPassword().toCharArray(),
key.getKeyStore().getType()),
keyStore.getSecret(), keyStore.getAlias());
RsaAlgorithm algorithm = rsaProperties.getAlgorithm();
locator.setRsaAlgorithm(algorithm);
locator.setSalt(rsaProperties.getSalt());
locator.setStrong(rsaProperties.isStrong());
return locator;
}
}

View File

@@ -1,8 +1,6 @@
# Bootstrap components
org.springframework.cloud.bootstrap.BootstrapConfiguration=\
org.springframework.cloud.config.server.bootstrap.ConfigServerBootstrapConfiguration,\
org.springframework.cloud.config.server.config.DefaultTextEncryptionAutoConfiguration,\
org.springframework.cloud.config.server.config.RsaEncryptionAutoConfiguration,\
org.springframework.cloud.config.server.config.EncryptionAutoConfiguration
# Environment PostProcessor
@@ -13,8 +11,6 @@ org.springframework.cloud.config.server.bootstrap.ConfigServerBootstrapApplicati
org.springframework.boot.autoconfigure.EnableAutoConfiguration=\
org.springframework.cloud.config.server.config.ConfigServerAutoConfiguration,\
org.springframework.cloud.config.server.config.EncryptionAutoConfiguration,\
org.springframework.cloud.config.server.config.DefaultTextEncryptionAutoConfiguration,\
org.springframework.cloud.config.server.config.RsaEncryptionAutoConfiguration,\
org.springframework.cloud.config.server.config.VaultEncryptionAutoConfiguration
org.springframework.boot.diagnostics.FailureAnalyzer=\
org.springframework.cloud.config.server.diagnostics.GitUriFailureAnalyzer

View File

@@ -34,9 +34,11 @@ class ProxyHostCredentialsProviderTest {
ProxyHostProperties withoutCredentials = proxyHost("bad.proxy", 666, null, null);
ProxyHostProperties goodProxy = proxyHost("good.proxy", 888, "user", "P@s$W0rd!");
ProxyHostCredentialsProvider provider = new ProxyHostCredentialsProvider(withoutConnection, withoutCredentials, goodProxy);
ProxyHostCredentialsProvider provider = new ProxyHostCredentialsProvider(withoutConnection, withoutCredentials,
goodProxy);
Map<AuthScope, Credentials> credentials = (Map<AuthScope, Credentials>) ReflectionTestUtils.getField(provider, "credMap");
Map<AuthScope, Credentials> credentials = (Map<AuthScope, Credentials>) ReflectionTestUtils.getField(provider,
"credMap");
assertThat(credentials).hasSize(1);
Map.Entry<AuthScope, Credentials> entry = credentials.entrySet().iterator().next();
assertThat(entry.getKey().getHost()).isEqualTo("good.proxy");

View File

@@ -79,7 +79,8 @@ class SchemeBasedRoutePlannerTest {
@Test
void determineProxy_should_return_null_when_provided_proxies_are_incomplete() {
SchemeBasedRoutePlanner planner = new SchemeBasedRoutePlanner(buildProxyProperties("", 777), buildProxyProperties("host", 0));
SchemeBasedRoutePlanner planner = new SchemeBasedRoutePlanner(buildProxyProperties("", 777),
buildProxyProperties("host", 0));
final HttpHost result = planner.determineProxy(target("https"), anyRequest(), anyContext());