Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Sign in / Register
Toggle navigation
S
spring-boot
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
DEMO
spring-boot
Commits
4194baad
Commit
4194baad
authored
Jun 07, 2018
by
Madhura Bhave
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Don't log p/w when AuthenticationManagerBuilder configured
Fixes gh-12872
parent
f7ff8dd1
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
31 additions
and
0 deletions
+31
-0
UserDetailsServiceAutoConfiguration.java
...security/servlet/UserDetailsServiceAutoConfiguration.java
+2
-0
UserDetailsServiceAutoConfigurationTests.java
...ity/servlet/UserDetailsServiceAutoConfigurationTests.java
+29
-0
No files found.
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/security/servlet/UserDetailsServiceAutoConfiguration.java
View file @
4194baad
...
@@ -30,6 +30,7 @@ import org.springframework.boot.autoconfigure.condition.ConditionalOnMissingBean
...
@@ -30,6 +30,7 @@ import org.springframework.boot.autoconfigure.condition.ConditionalOnMissingBean
import
org.springframework.boot.autoconfigure.security.SecurityProperties
;
import
org.springframework.boot.autoconfigure.security.SecurityProperties
;
import
org.springframework.context.annotation.Bean
;
import
org.springframework.context.annotation.Bean
;
import
org.springframework.context.annotation.Configuration
;
import
org.springframework.context.annotation.Configuration
;
import
org.springframework.context.annotation.Lazy
;
import
org.springframework.security.authentication.AuthenticationManager
;
import
org.springframework.security.authentication.AuthenticationManager
;
import
org.springframework.security.authentication.AuthenticationProvider
;
import
org.springframework.security.authentication.AuthenticationProvider
;
import
org.springframework.security.config.annotation.ObjectPostProcessor
;
import
org.springframework.security.config.annotation.ObjectPostProcessor
;
...
@@ -67,6 +68,7 @@ public class UserDetailsServiceAutoConfiguration {
...
@@ -67,6 +68,7 @@ public class UserDetailsServiceAutoConfiguration {
@Bean
@Bean
@ConditionalOnMissingBean
(
type
=
"org.springframework.security.oauth2.client.registration.ClientRegistrationRepository"
)
@ConditionalOnMissingBean
(
type
=
"org.springframework.security.oauth2.client.registration.ClientRegistrationRepository"
)
@Lazy
public
InMemoryUserDetailsManager
inMemoryUserDetailsManager
(
public
InMemoryUserDetailsManager
inMemoryUserDetailsManager
(
SecurityProperties
properties
,
SecurityProperties
properties
,
ObjectProvider
<
PasswordEncoder
>
passwordEncoder
)
{
ObjectProvider
<
PasswordEncoder
>
passwordEncoder
)
{
...
...
spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/security/servlet/UserDetailsServiceAutoConfigurationTests.java
View file @
4194baad
...
@@ -34,7 +34,9 @@ import org.springframework.security.authentication.AuthenticationProvider;
...
@@ -34,7 +34,9 @@ import org.springframework.security.authentication.AuthenticationProvider;
import
org.springframework.security.authentication.ProviderManager
;
import
org.springframework.security.authentication.ProviderManager
;
import
org.springframework.security.authentication.TestingAuthenticationProvider
;
import
org.springframework.security.authentication.TestingAuthenticationProvider
;
import
org.springframework.security.authentication.TestingAuthenticationToken
;
import
org.springframework.security.authentication.TestingAuthenticationToken
;
import
org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder
;
import
org.springframework.security.config.annotation.web.configuration.EnableWebSecurity
;
import
org.springframework.security.config.annotation.web.configuration.EnableWebSecurity
;
import
org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter
;
import
org.springframework.security.core.userdetails.User
;
import
org.springframework.security.core.userdetails.User
;
import
org.springframework.security.core.userdetails.UserDetailsService
;
import
org.springframework.security.core.userdetails.UserDetailsService
;
import
org.springframework.security.crypto.password.PasswordEncoder
;
import
org.springframework.security.crypto.password.PasswordEncoder
;
...
@@ -149,6 +151,14 @@ public class UserDetailsServiceAutoConfigurationTests {
...
@@ -149,6 +151,14 @@ public class UserDetailsServiceAutoConfigurationTests {
.
doesNotHaveBean
(
InMemoryUserDetailsManager
.
class
)));
.
doesNotHaveBean
(
InMemoryUserDetailsManager
.
class
)));
}
}
@Test
public
void
generatedPasswordShouldNotBePrintedIfAuthenticationManagerBuilderIsUsed
()
{
this
.
contextRunner
.
withUserConfiguration
(
TestConfigWithAuthenticationManagerBuilder
.
class
)
.
run
(((
context
)
->
assertThat
(
this
.
outputCapture
.
toString
())
.
doesNotContain
(
"Using generated security password: "
)));
}
private
void
testPasswordEncoding
(
Class
<?>
configClass
,
String
providedPassword
,
private
void
testPasswordEncoding
(
Class
<?>
configClass
,
String
providedPassword
,
String
expectedPassword
)
{
String
expectedPassword
)
{
this
.
contextRunner
.
withUserConfiguration
(
configClass
)
this
.
contextRunner
.
withUserConfiguration
(
configClass
)
...
@@ -227,4 +237,23 @@ public class UserDetailsServiceAutoConfigurationTests {
...
@@ -227,4 +237,23 @@ public class UserDetailsServiceAutoConfigurationTests {
}
}
@Configuration
@Import
(
TestSecurityConfiguration
.
class
)
protected
static
class
TestConfigWithAuthenticationManagerBuilder
{
@Bean
public
WebSecurityConfigurerAdapter
webSecurityConfigurerAdapter
()
{
return
new
WebSecurityConfigurerAdapter
()
{
@Override
protected
void
configure
(
AuthenticationManagerBuilder
auth
)
throws
Exception
{
auth
.
inMemoryAuthentication
().
withUser
(
"hero"
).
password
(
"{noop}hero"
)
.
roles
(
"HERO"
,
"USER"
).
and
().
withUser
(
"user"
)
.
password
(
"{noop}user"
).
roles
(
"USER"
);
}
};
}
}
}
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment