Commit a09ee17c authored by Denis Washington's avatar Denis Washington Committed by Stephane Nicoll

Add OAuth2 server implementation section to docs

As auto-configuration for Spring Security OAuth has been removed
from Spring Boot 2.0 and Spring Security 5 doesn't have OAuth
2.0 Authorization / Resource Server support yet, it has not
been obvious at all how to implement an OAUth 2.0 server with
Spring Boot 2.0.

For that reason, this new section briefly explains the current
temporary situation and points to the spring-security-oauth2-autoconfigure
module that restores the auto-configuration support for OAuth
2.0 Authorization and Resource Servers.

Closes gh-12491
parent efeede9f
...@@ -3193,6 +3193,17 @@ In other words, the two configurations in the following example use the Google p ...@@ -3193,6 +3193,17 @@ In other words, the two configurations in the following example use the Google p
[[boot-features-security-oauth2-server]]
==== Server
Currently, Spring Security does not provide support for implementing an OAuth 2.0
Authorization Server or Resource Server. However, this functionality is available from
the https://projects.spring.io/spring-security-oauth/[Spring Security OAuth] project,
which will eventually be superseded by Spring Security completely. Until then, you can
use the `spring-security-oauth2-autoconfigure` module to easily set up an OAuth 2.0 server;
see its https://docs.spring.io/spring-security-oauth2-boot[documentation] for instructions.
[[boot-features-security-actuator]] [[boot-features-security-actuator]]
=== Actuator Security === Actuator Security
For security purposes, all actuators other than `/health` and `/info` are disabled by For security purposes, all actuators other than `/health` and `/info` are disabled by
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment