Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Sign in / Register
Toggle navigation
S
spring-boot
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
DEMO
spring-boot
Commits
178746d6
Commit
178746d6
authored
Aug 13, 2019
by
Madhura Bhave
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Update Opaque Token Client Name following upstream changes
Closes gh-17846
parent
c178c9dd
Changes
12
Show whitespace changes
Inline
Side-by-side
Showing
12 changed files
with
57 additions
and
60 deletions
+57
-60
ReactiveOAuth2ResourceServerAutoConfiguration.java
...active/ReactiveOAuth2ResourceServerAutoConfiguration.java
+2
-2
ReactiveOAuth2ResourceServerOpaqueTokenConfiguration.java
...ReactiveOAuth2ResourceServerOpaqueTokenConfiguration.java
+8
-9
OAuth2ResourceServerAutoConfiguration.java
...source/servlet/OAuth2ResourceServerAutoConfiguration.java
+2
-2
OAuth2ResourceServerOpaqueTokenConfiguration.java
...servlet/OAuth2ResourceServerOpaqueTokenConfiguration.java
+10
-10
ReactiveUserDetailsServiceAutoConfiguration.java
...reactive/ReactiveUserDetailsServiceAutoConfiguration.java
+3
-3
UserDetailsServiceAutoConfiguration.java
...security/servlet/UserDetailsServiceAutoConfiguration.java
+1
-1
ReactiveOAuth2ResourceServerAutoConfigurationTests.java
...e/ReactiveOAuth2ResourceServerAutoConfigurationTests.java
+8
-9
OAuth2ResourceServerAutoConfigurationTests.java
...e/servlet/OAuth2ResourceServerAutoConfigurationTests.java
+8
-8
ReactiveUserDetailsServiceAutoConfigurationTests.java
...ive/ReactiveUserDetailsServiceAutoConfigurationTests.java
+8
-9
UserDetailsServiceAutoConfigurationTests.java
...ity/servlet/UserDetailsServiceAutoConfigurationTests.java
+4
-4
pom.xml
spring-boot-project/spring-boot-dependencies/pom.xml
+1
-1
spring-boot-features.adoc
...ing-boot-docs/src/main/asciidoc/spring-boot-features.adoc
+2
-2
No files found.
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/security/oauth2/resource/reactive/ReactiveOAuth2ResourceServerAutoConfiguration.java
View file @
178746d6
...
@@ -29,7 +29,7 @@ import org.springframework.security.config.annotation.web.reactive.EnableWebFlux
...
@@ -29,7 +29,7 @@ import org.springframework.security.config.annotation.web.reactive.EnableWebFlux
import
org.springframework.security.oauth2.jwt.ReactiveJwtDecoder
;
import
org.springframework.security.oauth2.jwt.ReactiveJwtDecoder
;
import
org.springframework.security.oauth2.server.resource.BearerTokenAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.BearerTokenAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveO
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveO
paqueTokenIntrospector
;
/**
/**
* {@link EnableAutoConfiguration Auto-configuration} for Reactive OAuth2 resource server
* {@link EnableAutoConfiguration Auto-configuration} for Reactive OAuth2 resource server
...
@@ -54,7 +54,7 @@ public class ReactiveOAuth2ResourceServerAutoConfiguration {
...
@@ -54,7 +54,7 @@ public class ReactiveOAuth2ResourceServerAutoConfiguration {
}
}
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
@ConditionalOnClass
({
OAuth2IntrospectionAuthenticationToken
.
class
,
ReactiveO
Auth2TokenIntrospectionClient
.
class
})
@ConditionalOnClass
({
OAuth2IntrospectionAuthenticationToken
.
class
,
ReactiveO
paqueTokenIntrospector
.
class
})
@Import
({
ReactiveOAuth2ResourceServerOpaqueTokenConfiguration
.
OpaqueTokenIntrospectionClientConfiguration
.
class
,
@Import
({
ReactiveOAuth2ResourceServerOpaqueTokenConfiguration
.
OpaqueTokenIntrospectionClientConfiguration
.
class
,
ReactiveOAuth2ResourceServerOpaqueTokenConfiguration
.
WebSecurityConfiguration
.
class
})
ReactiveOAuth2ResourceServerOpaqueTokenConfiguration
.
WebSecurityConfiguration
.
class
})
static
class
OpaqueTokenConfiguration
{
static
class
OpaqueTokenConfiguration
{
...
...
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/security/oauth2/resource/reactive/ReactiveOAuth2ResourceServerOpaqueTokenConfiguration.java
View file @
178746d6
...
@@ -24,29 +24,28 @@ import org.springframework.context.annotation.Bean;
...
@@ -24,29 +24,28 @@ import org.springframework.context.annotation.Bean;
import
org.springframework.context.annotation.Configuration
;
import
org.springframework.context.annotation.Configuration
;
import
org.springframework.security.config.web.server.ServerHttpSecurity
;
import
org.springframework.security.config.web.server.ServerHttpSecurity
;
import
org.springframework.security.config.web.server.ServerHttpSecurity.OAuth2ResourceServerSpec
;
import
org.springframework.security.config.web.server.ServerHttpSecurity.OAuth2ResourceServerSpec
;
import
org.springframework.security.oauth2.server.resource.introspection.NimbusReactiveO
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.NimbusReactiveO
paqueTokenIntrospector
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveO
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveO
paqueTokenIntrospector
;
import
org.springframework.security.web.server.SecurityWebFilterChain
;
import
org.springframework.security.web.server.SecurityWebFilterChain
;
/**
/**
* Configures a {@link ReactiveO
Auth2TokenIntrospectionClient
} when a token introspection
* Configures a {@link ReactiveO
paqueTokenIntrospector
} when a token introspection
* endpoint is available. Also configures a {@link SecurityWebFilterChain} if a
* endpoint is available. Also configures a {@link SecurityWebFilterChain} if a
* {@link ReactiveO
Auth2TokenIntrospectionClient
} bean is found.
* {@link ReactiveO
paqueTokenIntrospector
} bean is found.
*
*
* @author Madhura Bhave
* @author Madhura Bhave
*/
*/
class
ReactiveOAuth2ResourceServerOpaqueTokenConfiguration
{
class
ReactiveOAuth2ResourceServerOpaqueTokenConfiguration
{
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
@ConditionalOnMissingBean
(
ReactiveO
Auth2TokenIntrospectionClient
.
class
)
@ConditionalOnMissingBean
(
ReactiveO
paqueTokenIntrospector
.
class
)
static
class
OpaqueTokenIntrospectionClientConfiguration
{
static
class
OpaqueTokenIntrospectionClientConfiguration
{
@Bean
@Bean
@ConditionalOnProperty
(
name
=
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri"
)
@ConditionalOnProperty
(
name
=
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri"
)
NimbusReactiveOAuth2TokenIntrospectionClient
oAuth2TokenIntrospectionClient
(
NimbusReactiveOpaqueTokenIntrospector
opaqueTokenIntrospector
(
OAuth2ResourceServerProperties
properties
)
{
OAuth2ResourceServerProperties
properties
)
{
OAuth2ResourceServerProperties
.
Opaquetoken
opaqueToken
=
properties
.
getOpaquetoken
();
OAuth2ResourceServerProperties
.
Opaquetoken
opaqueToken
=
properties
.
getOpaquetoken
();
return
new
NimbusReactiveO
Auth2TokenIntrospectionClient
(
opaqueToken
.
getIntrospectionUri
(),
return
new
NimbusReactiveO
paqueTokenIntrospector
(
opaqueToken
.
getIntrospectionUri
(),
opaqueToken
.
getClientId
(),
opaqueToken
.
getClientSecret
());
opaqueToken
.
getClientId
(),
opaqueToken
.
getClientSecret
());
}
}
...
@@ -57,7 +56,7 @@ class ReactiveOAuth2ResourceServerOpaqueTokenConfiguration {
...
@@ -57,7 +56,7 @@ class ReactiveOAuth2ResourceServerOpaqueTokenConfiguration {
static
class
WebSecurityConfiguration
{
static
class
WebSecurityConfiguration
{
@Bean
@Bean
@ConditionalOnBean
(
ReactiveO
Auth2TokenIntrospectionClient
.
class
)
@ConditionalOnBean
(
ReactiveO
paqueTokenIntrospector
.
class
)
SecurityWebFilterChain
springSecurityFilterChain
(
ServerHttpSecurity
http
)
{
SecurityWebFilterChain
springSecurityFilterChain
(
ServerHttpSecurity
http
)
{
http
.
authorizeExchange
((
exchanges
)
->
exchanges
.
anyExchange
().
authenticated
());
http
.
authorizeExchange
((
exchanges
)
->
exchanges
.
anyExchange
().
authenticated
());
http
.
oauth2ResourceServer
(
OAuth2ResourceServerSpec:
:
opaqueToken
);
http
.
oauth2ResourceServer
(
OAuth2ResourceServerSpec:
:
opaqueToken
);
...
...
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/security/oauth2/resource/servlet/OAuth2ResourceServerAutoConfiguration.java
View file @
178746d6
...
@@ -28,7 +28,7 @@ import org.springframework.context.annotation.Import;
...
@@ -28,7 +28,7 @@ import org.springframework.context.annotation.Import;
import
org.springframework.security.oauth2.jwt.JwtDecoder
;
import
org.springframework.security.oauth2.jwt.JwtDecoder
;
import
org.springframework.security.oauth2.server.resource.authentication.JwtAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.JwtAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.introspection.O
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.O
paqueTokenIntrospector
;
/**
/**
* {@link EnableAutoConfiguration Auto-configuration} for OAuth2 resource server support.
* {@link EnableAutoConfiguration Auto-configuration} for OAuth2 resource server support.
...
@@ -52,7 +52,7 @@ public class OAuth2ResourceServerAutoConfiguration {
...
@@ -52,7 +52,7 @@ public class OAuth2ResourceServerAutoConfiguration {
}
}
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
@ConditionalOnClass
({
OAuth2IntrospectionAuthenticationToken
.
class
,
O
Auth2TokenIntrospectionClient
.
class
})
@ConditionalOnClass
({
OAuth2IntrospectionAuthenticationToken
.
class
,
O
paqueTokenIntrospector
.
class
})
@Import
({
OAuth2ResourceServerOpaqueTokenConfiguration
.
OpaqueTokenIntrospectionClientConfiguration
.
class
,
@Import
({
OAuth2ResourceServerOpaqueTokenConfiguration
.
OpaqueTokenIntrospectionClientConfiguration
.
class
,
OAuth2ResourceServerOpaqueTokenConfiguration
.
OAuth2WebSecurityConfigurerAdapter
.
class
})
OAuth2ResourceServerOpaqueTokenConfiguration
.
OAuth2WebSecurityConfigurerAdapter
.
class
})
static
class
OpaqueTokenConfiguration
{
static
class
OpaqueTokenConfiguration
{
...
...
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/security/oauth2/resource/servlet/OAuth2ResourceServerOpaqueTokenConfiguration.java
View file @
178746d6
...
@@ -24,13 +24,13 @@ import org.springframework.context.annotation.Configuration;
...
@@ -24,13 +24,13 @@ import org.springframework.context.annotation.Configuration;
import
org.springframework.security.config.annotation.web.builders.HttpSecurity
;
import
org.springframework.security.config.annotation.web.builders.HttpSecurity
;
import
org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter
;
import
org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter
;
import
org.springframework.security.config.annotation.web.configurers.oauth2.server.resource.OAuth2ResourceServerConfigurer
;
import
org.springframework.security.config.annotation.web.configurers.oauth2.server.resource.OAuth2ResourceServerConfigurer
;
import
org.springframework.security.oauth2.server.resource.introspection.NimbusO
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.NimbusO
paqueTokenIntrospector
;
import
org.springframework.security.oauth2.server.resource.introspection.O
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.O
paqueTokenIntrospector
;
/**
/**
* Configures a {@link O
Auth2TokenIntrospectionClient} when a token introspection endpoint
* Configures a {@link O
paqueTokenIntrospector} when a token introspection endpoint is
*
is
available. Also configures a {@link WebSecurityConfigurerAdapter} if a
* available. Also configures a {@link WebSecurityConfigurerAdapter} if a
* {@link O
Auth2TokenIntrospectionClient
} bean is found.
* {@link O
paqueTokenIntrospector
} bean is found.
*
*
* @author Madhura Bhave
* @author Madhura Bhave
*/
*/
...
@@ -38,15 +38,15 @@ import org.springframework.security.oauth2.server.resource.introspection.OAuth2T
...
@@ -38,15 +38,15 @@ import org.springframework.security.oauth2.server.resource.introspection.OAuth2T
class
OAuth2ResourceServerOpaqueTokenConfiguration
{
class
OAuth2ResourceServerOpaqueTokenConfiguration
{
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
@ConditionalOnMissingBean
(
O
Auth2TokenIntrospectionClient
.
class
)
@ConditionalOnMissingBean
(
O
paqueTokenIntrospector
.
class
)
static
class
OpaqueTokenIntrospectionClientConfiguration
{
static
class
OpaqueTokenIntrospectionClientConfiguration
{
@Bean
@Bean
@ConditionalOnProperty
(
name
=
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri"
)
@ConditionalOnProperty
(
name
=
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri"
)
NimbusO
Auth2TokenIntrospectionClient
oAuth2TokenIntrospectionClient
(
OAuth2ResourceServerProperties
properties
)
{
NimbusO
paqueTokenIntrospector
opaqueTokenIntrospector
(
OAuth2ResourceServerProperties
properties
)
{
OAuth2ResourceServerProperties
.
Opaquetoken
opaqueToken
=
properties
.
getOpaquetoken
();
OAuth2ResourceServerProperties
.
Opaquetoken
opaqueToken
=
properties
.
getOpaquetoken
();
return
new
NimbusO
Auth2TokenIntrospectionClient
(
opaqueToken
.
getIntrospectionUri
(),
return
new
NimbusO
paqueTokenIntrospector
(
opaqueToken
.
getIntrospectionUri
(),
opaqueToken
.
getClientId
(),
opaqueToken
.
getClient
Id
(),
opaqueToken
.
getClient
Secret
());
opaqueToken
.
getClientSecret
());
}
}
}
}
...
@@ -56,7 +56,7 @@ class OAuth2ResourceServerOpaqueTokenConfiguration {
...
@@ -56,7 +56,7 @@ class OAuth2ResourceServerOpaqueTokenConfiguration {
static
class
OAuth2WebSecurityConfigurerAdapter
{
static
class
OAuth2WebSecurityConfigurerAdapter
{
@Bean
@Bean
@ConditionalOnBean
(
O
Auth2TokenIntrospectionClient
.
class
)
@ConditionalOnBean
(
O
paqueTokenIntrospector
.
class
)
WebSecurityConfigurerAdapter
opaqueTokenWebSecurityConfigurerAdapter
()
{
WebSecurityConfigurerAdapter
opaqueTokenWebSecurityConfigurerAdapter
()
{
return
new
WebSecurityConfigurerAdapter
()
{
return
new
WebSecurityConfigurerAdapter
()
{
...
...
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/security/reactive/ReactiveUserDetailsServiceAutoConfiguration.java
View file @
178746d6
...
@@ -48,9 +48,9 @@ import org.springframework.util.StringUtils;
...
@@ -48,9 +48,9 @@ import org.springframework.util.StringUtils;
*/
*/
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
@ConditionalOnClass
({
ReactiveAuthenticationManager
.
class
})
@ConditionalOnClass
({
ReactiveAuthenticationManager
.
class
})
@ConditionalOnMissingBean
(
value
=
{
ReactiveAuthenticationManager
.
class
,
ReactiveUserDetailsService
.
class
},
type
=
{
@ConditionalOnMissingBean
(
value
=
{
ReactiveAuthenticationManager
.
class
,
ReactiveUserDetailsService
.
class
},
"org.springframework.security.oauth2.jwt.ReactiveJwtDecoder"
,
type
=
{
"org.springframework.security.oauth2.jwt.ReactiveJwtDecoder"
,
"org.springframework.security.oauth2.server.resource.introspection.ReactiveOAuth2TokenIntrospectionClient
"
})
"org.springframework.security.oauth2.server.resource.introspection.ReactiveOpaqueTokenIntrospector
"
})
@ConditionalOnWebApplication
(
type
=
ConditionalOnWebApplication
.
Type
.
REACTIVE
)
@ConditionalOnWebApplication
(
type
=
ConditionalOnWebApplication
.
Type
.
REACTIVE
)
public
class
ReactiveUserDetailsServiceAutoConfiguration
{
public
class
ReactiveUserDetailsServiceAutoConfiguration
{
...
...
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/security/servlet/UserDetailsServiceAutoConfiguration.java
View file @
178746d6
...
@@ -58,7 +58,7 @@ import org.springframework.util.StringUtils;
...
@@ -58,7 +58,7 @@ import org.springframework.util.StringUtils;
@ConditionalOnMissingBean
(
@ConditionalOnMissingBean
(
value
=
{
AuthenticationManager
.
class
,
AuthenticationProvider
.
class
,
UserDetailsService
.
class
},
value
=
{
AuthenticationManager
.
class
,
AuthenticationProvider
.
class
,
UserDetailsService
.
class
},
type
=
{
"org.springframework.security.oauth2.jwt.JwtDecoder"
,
type
=
{
"org.springframework.security.oauth2.jwt.JwtDecoder"
,
"org.springframework.security.oauth2.server.resource.introspection.O
Auth2TokenIntrospectionClient
"
})
"org.springframework.security.oauth2.server.resource.introspection.O
paqueTokenIntrospector
"
})
public
class
UserDetailsServiceAutoConfiguration
{
public
class
UserDetailsServiceAutoConfiguration
{
private
static
final
String
NOOP_PASSWORD_PREFIX
=
"{noop}"
;
private
static
final
String
NOOP_PASSWORD_PREFIX
=
"{noop}"
;
...
...
spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/security/oauth2/resource/reactive/ReactiveOAuth2ResourceServerAutoConfigurationTests.java
View file @
178746d6
...
@@ -48,8 +48,7 @@ import org.springframework.security.oauth2.server.resource.BearerTokenAuthentica
...
@@ -48,8 +48,7 @@ import org.springframework.security.oauth2.server.resource.BearerTokenAuthentica
import
org.springframework.security.oauth2.server.resource.authentication.JwtReactiveAuthenticationManager
;
import
org.springframework.security.oauth2.server.resource.authentication.JwtReactiveAuthenticationManager
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionReactiveAuthenticationManager
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionReactiveAuthenticationManager
;
import
org.springframework.security.oauth2.server.resource.introspection.OAuth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveOpaqueTokenIntrospector
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveOAuth2TokenIntrospectionClient
;
import
org.springframework.security.web.server.MatcherSecurityWebFilterChain
;
import
org.springframework.security.web.server.MatcherSecurityWebFilterChain
;
import
org.springframework.security.web.server.SecurityWebFilterChain
;
import
org.springframework.security.web.server.SecurityWebFilterChain
;
import
org.springframework.security.web.server.authentication.AuthenticationWebFilter
;
import
org.springframework.security.web.server.authentication.AuthenticationWebFilter
;
...
@@ -252,17 +251,17 @@ class ReactiveOAuth2ResourceServerAutoConfigurationTests {
...
@@ -252,17 +251,17 @@ class ReactiveOAuth2ResourceServerAutoConfigurationTests {
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
.
run
((
context
)
->
{
.
run
((
context
)
->
{
assertThat
(
context
).
hasSingleBean
(
ReactiveO
Auth2TokenIntrospectionClient
.
class
);
assertThat
(
context
).
hasSingleBean
(
ReactiveO
paqueTokenIntrospector
.
class
);
assertFilterConfiguredWithOpaqueTokenAuthenticationManager
(
context
);
assertFilterConfiguredWithOpaqueTokenAuthenticationManager
(
context
);
});
});
}
}
@Test
@Test
void
o
Auth2TokenIntrospectionClient
IsConditionalOnMissingBean
()
{
void
o
paqueTokenIntrospector
IsConditionalOnMissingBean
()
{
this
.
contextRunner
this
.
contextRunner
.
withPropertyValues
(
.
withPropertyValues
(
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
)
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
)
.
withUserConfiguration
(
O
Auth2TokenIntrospectionClient
Config
.
class
)
.
withUserConfiguration
(
O
paqueTokenIntrospector
Config
.
class
)
.
run
((
this
::
assertFilterConfiguredWithOpaqueTokenAuthenticationManager
));
.
run
((
this
::
assertFilterConfiguredWithOpaqueTokenAuthenticationManager
));
}
}
...
@@ -286,7 +285,7 @@ class ReactiveOAuth2ResourceServerAutoConfigurationTests {
...
@@ -286,7 +285,7 @@ class ReactiveOAuth2ResourceServerAutoConfigurationTests {
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
,
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
.
run
((
context
)
->
assertThat
(
context
).
doesNotHaveBean
(
OAuth2TokenIntrospectionClient
.
class
));
.
run
((
context
)
->
assertThat
(
context
).
doesNotHaveBean
(
ReactiveOpaqueTokenIntrospector
.
class
));
}
}
@Test
@Test
...
@@ -406,11 +405,11 @@ class ReactiveOAuth2ResourceServerAutoConfigurationTests {
...
@@ -406,11 +405,11 @@ class ReactiveOAuth2ResourceServerAutoConfigurationTests {
}
}
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
static
class
O
Auth2TokenIntrospectionClient
Config
{
static
class
O
paqueTokenIntrospector
Config
{
@Bean
@Bean
ReactiveO
Auth2TokenIntrospectionClient
decoder
()
{
ReactiveO
paqueTokenIntrospector
decoder
()
{
return
mock
(
ReactiveO
Auth2TokenIntrospectionClient
.
class
);
return
mock
(
ReactiveO
paqueTokenIntrospector
.
class
);
}
}
}
}
...
...
spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/security/oauth2/resource/servlet/OAuth2ResourceServerAutoConfigurationTests.java
View file @
178746d6
...
@@ -44,7 +44,7 @@ import org.springframework.security.config.annotation.web.configuration.EnableWe
...
@@ -44,7 +44,7 @@ import org.springframework.security.config.annotation.web.configuration.EnableWe
import
org.springframework.security.oauth2.jwt.JwtDecoder
;
import
org.springframework.security.oauth2.jwt.JwtDecoder
;
import
org.springframework.security.oauth2.server.resource.authentication.JwtAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.JwtAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.authentication.OAuth2IntrospectionAuthenticationToken
;
import
org.springframework.security.oauth2.server.resource.introspection.O
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.O
paqueTokenIntrospector
;
import
org.springframework.security.oauth2.server.resource.web.BearerTokenAuthenticationFilter
;
import
org.springframework.security.oauth2.server.resource.web.BearerTokenAuthenticationFilter
;
import
org.springframework.security.web.FilterChainProxy
;
import
org.springframework.security.web.FilterChainProxy
;
import
org.springframework.security.web.SecurityFilterChain
;
import
org.springframework.security.web.SecurityFilterChain
;
...
@@ -266,17 +266,17 @@ class OAuth2ResourceServerAutoConfigurationTests {
...
@@ -266,17 +266,17 @@ class OAuth2ResourceServerAutoConfigurationTests {
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
.
run
((
context
)
->
{
.
run
((
context
)
->
{
assertThat
(
context
).
hasSingleBean
(
O
Auth2TokenIntrospectionClient
.
class
);
assertThat
(
context
).
hasSingleBean
(
O
paqueTokenIntrospector
.
class
);
assertThat
(
getBearerTokenFilter
(
context
)).
isNotNull
();
assertThat
(
getBearerTokenFilter
(
context
)).
isNotNull
();
});
});
}
}
@Test
@Test
void
o
Auth2TokenIntrospectionClient
IsConditionalOnMissingBean
()
{
void
o
paqueTokenIntrospector
IsConditionalOnMissingBean
()
{
this
.
contextRunner
this
.
contextRunner
.
withPropertyValues
(
.
withPropertyValues
(
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
)
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
)
.
withUserConfiguration
(
O
Auth2TokenIntrospectionClient
Config
.
class
)
.
withUserConfiguration
(
O
paqueTokenIntrospector
Config
.
class
)
.
run
((
context
)
->
assertThat
(
getBearerTokenFilter
(
context
)).
isNotNull
());
.
run
((
context
)
->
assertThat
(
getBearerTokenFilter
(
context
)).
isNotNull
());
}
}
...
@@ -287,7 +287,7 @@ class OAuth2ResourceServerAutoConfigurationTests {
...
@@ -287,7 +287,7 @@ class OAuth2ResourceServerAutoConfigurationTests {
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
,
"spring.security.oauth2.resourceserver.opaquetoken.introspection-uri=https://check-token.com"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-id=my-client-id"
,
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
"spring.security.oauth2.resourceserver.opaquetoken.client-secret=my-client-secret"
)
.
run
((
context
)
->
assertThat
(
context
).
doesNotHaveBean
(
O
Auth2TokenIntrospectionClient
.
class
));
.
run
((
context
)
->
assertThat
(
context
).
doesNotHaveBean
(
O
paqueTokenIntrospector
.
class
));
}
}
@Test
@Test
...
@@ -387,11 +387,11 @@ class OAuth2ResourceServerAutoConfigurationTests {
...
@@ -387,11 +387,11 @@ class OAuth2ResourceServerAutoConfigurationTests {
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
@EnableWebSecurity
@EnableWebSecurity
static
class
O
Auth2TokenIntrospectionClient
Config
{
static
class
O
paqueTokenIntrospector
Config
{
@Bean
@Bean
O
Auth2TokenIntrospectionClient
decoder
()
{
O
paqueTokenIntrospector
decoder
()
{
return
mock
(
O
Auth2TokenIntrospectionClient
.
class
);
return
mock
(
O
paqueTokenIntrospector
.
class
);
}
}
}
}
...
...
spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/security/reactive/ReactiveUserDetailsServiceAutoConfigurationTests.java
View file @
178746d6
...
@@ -35,7 +35,7 @@ import org.springframework.security.core.userdetails.User;
...
@@ -35,7 +35,7 @@ import org.springframework.security.core.userdetails.User;
import
org.springframework.security.core.userdetails.UserDetails
;
import
org.springframework.security.core.userdetails.UserDetails
;
import
org.springframework.security.crypto.password.PasswordEncoder
;
import
org.springframework.security.crypto.password.PasswordEncoder
;
import
org.springframework.security.oauth2.jwt.ReactiveJwtDecoder
;
import
org.springframework.security.oauth2.jwt.ReactiveJwtDecoder
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveO
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.ReactiveO
paqueTokenIntrospector
;
import
static
org
.
assertj
.
core
.
api
.
Assertions
.
assertThat
;
import
static
org
.
assertj
.
core
.
api
.
Assertions
.
assertThat
;
import
static
org
.
mockito
.
Mockito
.
mock
;
import
static
org
.
mockito
.
Mockito
.
mock
;
...
@@ -86,9 +86,8 @@ class ReactiveUserDetailsServiceAutoConfigurationTests {
...
@@ -86,9 +86,8 @@ class ReactiveUserDetailsServiceAutoConfigurationTests {
@Test
@Test
void
doesNotConfigureDefaultUserIfResourceServerWithOpaqueIsUsed
()
{
void
doesNotConfigureDefaultUserIfResourceServerWithOpaqueIsUsed
()
{
this
.
contextRunner
.
withUserConfiguration
(
ReactiveOAuth2TokenIntrospectionClientConfiguration
.
class
)
this
.
contextRunner
.
withUserConfiguration
(
ReactiveOpaqueTokenIntrospectorConfiguration
.
class
).
run
((
context
)
->
{
.
run
((
context
)
->
{
assertThat
(
context
).
hasSingleBean
(
ReactiveOpaqueTokenIntrospector
.
class
);
assertThat
(
context
).
hasSingleBean
(
ReactiveOAuth2TokenIntrospectionClient
.
class
);
assertThat
(
context
).
doesNotHaveBean
(
ReactiveUserDetailsService
.
class
);
assertThat
(
context
).
doesNotHaveBean
(
ReactiveUserDetailsService
.
class
);
});
});
}
}
...
@@ -180,11 +179,11 @@ class ReactiveUserDetailsServiceAutoConfigurationTests {
...
@@ -180,11 +179,11 @@ class ReactiveUserDetailsServiceAutoConfigurationTests {
}
}
@Configuration
(
proxyBeanMethods
=
false
)
@Configuration
(
proxyBeanMethods
=
false
)
static
class
ReactiveO
Auth2TokenIntrospectionClient
Configuration
{
static
class
ReactiveO
paqueTokenIntrospector
Configuration
{
@Bean
@Bean
ReactiveO
Auth2TokenIntrospectionClient
introspectionClient
()
{
ReactiveO
paqueTokenIntrospector
introspectionClient
()
{
return
mock
(
ReactiveO
Auth2TokenIntrospectionClient
.
class
);
return
mock
(
ReactiveO
paqueTokenIntrospector
.
class
);
}
}
}
}
...
...
spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/security/servlet/UserDetailsServiceAutoConfigurationTests.java
View file @
178746d6
...
@@ -43,7 +43,7 @@ import org.springframework.security.core.userdetails.UserDetailsService;
...
@@ -43,7 +43,7 @@ import org.springframework.security.core.userdetails.UserDetailsService;
import
org.springframework.security.crypto.password.PasswordEncoder
;
import
org.springframework.security.crypto.password.PasswordEncoder
;
import
org.springframework.security.oauth2.client.registration.ClientRegistrationRepository
;
import
org.springframework.security.oauth2.client.registration.ClientRegistrationRepository
;
import
org.springframework.security.oauth2.jwt.JwtDecoder
;
import
org.springframework.security.oauth2.jwt.JwtDecoder
;
import
org.springframework.security.oauth2.server.resource.introspection.O
Auth2TokenIntrospectionClient
;
import
org.springframework.security.oauth2.server.resource.introspection.O
paqueTokenIntrospector
;
import
org.springframework.security.provisioning.InMemoryUserDetailsManager
;
import
org.springframework.security.provisioning.InMemoryUserDetailsManager
;
import
static
org
.
assertj
.
core
.
api
.
Assertions
.
assertThat
;
import
static
org
.
assertj
.
core
.
api
.
Assertions
.
assertThat
;
...
@@ -105,7 +105,7 @@ class UserDetailsServiceAutoConfigurationTests {
...
@@ -105,7 +105,7 @@ class UserDetailsServiceAutoConfigurationTests {
@Test
@Test
void
defaultUserNotCreatedIfResourceServerWithOpaqueIsUsed
()
{
void
defaultUserNotCreatedIfResourceServerWithOpaqueIsUsed
()
{
this
.
contextRunner
.
withUserConfiguration
(
TestConfigWithIntrospectionClient
.
class
).
run
((
context
)
->
{
this
.
contextRunner
.
withUserConfiguration
(
TestConfigWithIntrospectionClient
.
class
).
run
((
context
)
->
{
assertThat
(
context
).
hasSingleBean
(
O
Auth2TokenIntrospectionClient
.
class
);
assertThat
(
context
).
hasSingleBean
(
O
paqueTokenIntrospector
.
class
);
assertThat
(
context
).
doesNotHaveBean
(
UserDetailsService
.
class
);
assertThat
(
context
).
doesNotHaveBean
(
UserDetailsService
.
class
);
});
});
}
}
...
@@ -243,8 +243,8 @@ class UserDetailsServiceAutoConfigurationTests {
...
@@ -243,8 +243,8 @@ class UserDetailsServiceAutoConfigurationTests {
static
class
TestConfigWithIntrospectionClient
{
static
class
TestConfigWithIntrospectionClient
{
@Bean
@Bean
O
Auth2TokenIntrospectionClient
introspectionClient
()
{
O
paqueTokenIntrospector
introspectionClient
()
{
return
mock
(
O
Auth2TokenIntrospectionClient
.
class
);
return
mock
(
O
paqueTokenIntrospector
.
class
);
}
}
}
}
...
...
spring-boot-project/spring-boot-dependencies/pom.xml
View file @
178746d6
...
@@ -191,7 +191,7 @@
...
@@ -191,7 +191,7 @@
<spring-plugin.version>
2.0.0.M1
</spring-plugin.version>
<spring-plugin.version>
2.0.0.M1
</spring-plugin.version>
<spring-restdocs.version>
2.0.3.RELEASE
</spring-restdocs.version>
<spring-restdocs.version>
2.0.3.RELEASE
</spring-restdocs.version>
<spring-retry.version>
1.2.4.RELEASE
</spring-retry.version>
<spring-retry.version>
1.2.4.RELEASE
</spring-retry.version>
<spring-security.version>
5.2.0.
M4
</spring-security.version>
<spring-security.version>
5.2.0.
BUILD-SNAPSHOT
</spring-security.version>
<spring-session-bom.version>
Corn-M3
</spring-session-bom.version>
<spring-session-bom.version>
Corn-M3
</spring-session-bom.version>
<spring-ws.version>
3.0.7.RELEASE
</spring-ws.version>
<spring-ws.version>
3.0.7.RELEASE
</spring-ws.version>
<sqlite-jdbc.version>
3.28.0
</sqlite-jdbc.version>
<sqlite-jdbc.version>
3.28.0
</sqlite-jdbc.version>
...
...
spring-boot-project/spring-boot-docs/src/main/asciidoc/spring-boot-features.adoc
View file @
178746d6
...
@@ -3805,8 +3805,8 @@ to validate tokens via introspection:
...
@@ -3805,8 +3805,8 @@ to validate tokens via introspection:
Again, the same properties are applicable for both servlet and reactive applications.
Again, the same properties are applicable for both servlet and reactive applications.
Alternatively, you can define your own `O
Auth2TokenIntrospectionClient
` bean for servlet applications
Alternatively, you can define your own `O
paqueTokenIntrospector
` bean for servlet applications
or a `ReactiveO
Auth2TokenIntrospectionClient
` for reactive applications.
or a `ReactiveO
paqueTokenIntrospector
` for reactive applications.
==== Authorization Server
==== Authorization Server
Currently, Spring Security does not provide support for implementing an OAuth 2.0
Currently, Spring Security does not provide support for implementing an OAuth 2.0
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment