Skip to content

Commit cc0e6f0

Browse files
committed
Add sample for OAuth2 RestClient interceptor
Closes gh-294
1 parent 2770555 commit cc0e6f0

38 files changed

+1891
-1
lines changed

README.adoc

+2
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,8 @@ Samples for https://github.com/spring-projects/spring-security
4040

4141
** https://github.com/spring-projects/spring-security-samples/tree/main/servlet/spring-boot/java/oauth2/resource-server/static[Static]
4242

43+
* RestClient - https://github.com/spring-projects/spring-security-samples/tree/main/servlet/spring-boot/java/oauth2/restclient[Spring Boot]
44+
4345
* WebClient - https://github.com/spring-projects/spring-security-samples/tree/main/servlet/spring-boot/java/oauth2/webclient[Spring Boot] | https://github.com/spring-projects/spring-security-samples/tree/main/reactive/webflux/java/oauth2/webclient[WebFlux]
4446

4547
=== SAML 2.0

servlet/spring-boot/java/oauth2/authorization-server/src/main/resources/application.yml

+29-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,11 @@
11
server:
22
port: 9000
33

4+
logging:
5+
level:
6+
org.springframework.security: trace
7+
8+
49
spring:
510
security:
611
user:
@@ -28,14 +33,37 @@ spring:
2833
- "openid"
2934
- "profile"
3035
require-authorization-consent: true
36+
login-client-with-messaging:
37+
registration:
38+
client-id: "login-client-with-messaging"
39+
client-secret: "{noop}with-messages"
40+
client-authentication-methods:
41+
- "client_secret_basic"
42+
authorization-grant-types:
43+
- "authorization_code"
44+
- "refresh_token"
45+
redirect-uris:
46+
- "http://127.0.0.1:8080/login/oauth2/code/login-client-with-messaging"
47+
- "http://127.0.0.1:8080/authorized"
48+
scopes:
49+
- "openid"
50+
- "profile"
51+
- "message:read"
52+
- "message:write"
53+
require-authorization-consent: true
3154
messaging-client:
3255
registration:
3356
client-id: "messaging-client"
3457
client-secret: "{noop}secret"
3558
client-authentication-methods:
3659
- "client_secret_basic"
3760
authorization-grant-types:
61+
- "authorization_code"
62+
- "refresh_token"
3863
- "client_credentials"
64+
redirect-uris:
65+
- "http://127.0.0.1:8080/authorized"
3966
scopes:
4067
- "message:read"
41-
- "message:write"
68+
- "message:write"
69+
require-authorization-consent: true
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
plugins {
2+
alias(libs.plugins.org.springframework.boot)
3+
alias(libs.plugins.io.spring.dependency.management)
4+
id 'java'
5+
}
6+
7+
repositories {
8+
mavenCentral()
9+
maven { url "https://repo.spring.io/milestone" }
10+
maven { url "https://repo.spring.io/snapshot" }
11+
}
12+
13+
14+
dependencies {
15+
implementation 'org.springframework.boot:spring-boot-starter-oauth2-resource-server'
16+
implementation 'org.springframework.boot:spring-boot-starter-web'
17+
18+
testImplementation 'org.springframework.boot:spring-boot-starter-test'
19+
testImplementation 'org.springframework.security:spring-security-test'
20+
}
21+
22+
tasks.withType(Test).configureEach {
23+
useJUnitPlatform()
24+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
version=6.1.1
2+
spring-security.version=6.4.0-SNAPSHOT
3+
org.gradle.jvmargs=-Xmx6g -XX:+HeapDumpOnOutOfMemoryError
4+
org.gradle.caching=true
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
[versions]
2+
org-springframework-boot = "3.4.0-SNAPSHOT"
3+
4+
[libraries]
5+
org-springframework-spring-framework-bom = "org.springframework:spring-framework-bom:6.2.0-M6"
6+
org-springframework-security-spring-security-bom = "org.springframework.security:spring-security-bom:6.4.0-SNAPSHOT"
7+
org-springframework-data-spring-data-bom = "org.springframework.data:spring-data-bom:2024.0.2"
8+
9+
[plugins]
10+
io-spring-dependency-management = { id = "io.spring.dependency-management", version = "1.1.6" }
11+
org-springframework-boot = { id = "org.springframework.boot", version.ref = "org-springframework-boot" }
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
distributionBase=GRADLE_USER_HOME
2+
distributionPath=wrapper/dists
3+
distributionUrl=https\://services.gradle.org/distributions/gradle-8.3-bin.zip
4+
networkTimeout=10000
5+
zipStoreBase=GRADLE_USER_HOME
6+
zipStorePath=wrapper/dists
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,244 @@
1+
#!/bin/sh
2+
3+
#
4+
# Copyright © 2015-2021 the original authors.
5+
#
6+
# Licensed under the Apache License, Version 2.0 (the "License");
7+
# you may not use this file except in compliance with the License.
8+
# You may obtain a copy of the License at
9+
#
10+
# https://www.apache.org/licenses/LICENSE-2.0
11+
#
12+
# Unless required by applicable law or agreed to in writing, software
13+
# distributed under the License is distributed on an "AS IS" BASIS,
14+
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15+
# See the License for the specific language governing permissions and
16+
# limitations under the License.
17+
#
18+
19+
##############################################################################
20+
#
21+
# Gradle start up script for POSIX generated by Gradle.
22+
#
23+
# Important for running:
24+
#
25+
# (1) You need a POSIX-compliant shell to run this script. If your /bin/sh is
26+
# noncompliant, but you have some other compliant shell such as ksh or
27+
# bash, then to run this script, type that shell name before the whole
28+
# command line, like:
29+
#
30+
# ksh Gradle
31+
#
32+
# Busybox and similar reduced shells will NOT work, because this script
33+
# requires all of these POSIX shell features:
34+
# * functions;
35+
# * expansions «$var», «${var}», «${var:-default}», «${var+SET}»,
36+
# «${var#prefix}», «${var%suffix}», and «$( cmd )»;
37+
# * compound commands having a testable exit status, especially «case»;
38+
# * various built-in commands including «command», «set», and «ulimit».
39+
#
40+
# Important for patching:
41+
#
42+
# (2) This script targets any POSIX shell, so it avoids extensions provided
43+
# by Bash, Ksh, etc; in particular arrays are avoided.
44+
#
45+
# The "traditional" practice of packing multiple parameters into a
46+
# space-separated string is a well documented source of bugs and security
47+
# problems, so this is (mostly) avoided, by progressively accumulating
48+
# options in "$@", and eventually passing that to Java.
49+
#
50+
# Where the inherited environment variables (DEFAULT_JVM_OPTS, JAVA_OPTS,
51+
# and GRADLE_OPTS) rely on word-splitting, this is performed explicitly;
52+
# see the in-line comments for details.
53+
#
54+
# There are tweaks for specific operating systems such as AIX, CygWin,
55+
# Darwin, MinGW, and NonStop.
56+
#
57+
# (3) This script is generated from the Groovy template
58+
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
59+
# within the Gradle project.
60+
#
61+
# You can find Gradle at https://github.com/gradle/gradle/.
62+
#
63+
##############################################################################
64+
65+
# Attempt to set APP_HOME
66+
67+
# Resolve links: $0 may be a link
68+
app_path=$0
69+
70+
# Need this for daisy-chained symlinks.
71+
while
72+
APP_HOME=${app_path%"${app_path##*/}"} # leaves a trailing /; empty if no leading path
73+
[ -h "$app_path" ]
74+
do
75+
ls=$( ls -ld "$app_path" )
76+
link=${ls#*' -> '}
77+
case $link in #(
78+
/*) app_path=$link ;; #(
79+
*) app_path=$APP_HOME$link ;;
80+
esac
81+
done
82+
83+
# This is normally unused
84+
# shellcheck disable=SC2034
85+
APP_BASE_NAME=${0##*/}
86+
APP_HOME=$( cd "${APP_HOME:-./}" && pwd -P ) || exit
87+
88+
# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
89+
DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
90+
91+
# Use the maximum available, or set MAX_FD != -1 to use that value.
92+
MAX_FD=maximum
93+
94+
warn () {
95+
echo "$*"
96+
} >&2
97+
98+
die () {
99+
echo
100+
echo "$*"
101+
echo
102+
exit 1
103+
} >&2
104+
105+
# OS specific support (must be 'true' or 'false').
106+
cygwin=false
107+
msys=false
108+
darwin=false
109+
nonstop=false
110+
case "$( uname )" in #(
111+
CYGWIN* ) cygwin=true ;; #(
112+
Darwin* ) darwin=true ;; #(
113+
MSYS* | MINGW* ) msys=true ;; #(
114+
NONSTOP* ) nonstop=true ;;
115+
esac
116+
117+
CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
118+
119+
120+
# Determine the Java command to use to start the JVM.
121+
if [ -n "$JAVA_HOME" ] ; then
122+
if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
123+
# IBM's JDK on AIX uses strange locations for the executables
124+
JAVACMD=$JAVA_HOME/jre/sh/java
125+
else
126+
JAVACMD=$JAVA_HOME/bin/java
127+
fi
128+
if [ ! -x "$JAVACMD" ] ; then
129+
die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
130+
131+
Please set the JAVA_HOME variable in your environment to match the
132+
location of your Java installation."
133+
fi
134+
else
135+
JAVACMD=java
136+
which java >/dev/null 2>&1 || die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
137+
138+
Please set the JAVA_HOME variable in your environment to match the
139+
location of your Java installation."
140+
fi
141+
142+
# Increase the maximum file descriptors if we can.
143+
if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then
144+
case $MAX_FD in #(
145+
max*)
146+
# In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked.
147+
# shellcheck disable=SC3045
148+
MAX_FD=$( ulimit -H -n ) ||
149+
warn "Could not query maximum file descriptor limit"
150+
esac
151+
case $MAX_FD in #(
152+
'' | soft) :;; #(
153+
*)
154+
# In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked.
155+
# shellcheck disable=SC3045
156+
ulimit -n "$MAX_FD" ||
157+
warn "Could not set maximum file descriptor limit to $MAX_FD"
158+
esac
159+
fi
160+
161+
# Collect all arguments for the java command, stacking in reverse order:
162+
# * args from the command line
163+
# * the main class name
164+
# * -classpath
165+
# * -D...appname settings
166+
# * --module-path (only if needed)
167+
# * DEFAULT_JVM_OPTS, JAVA_OPTS, and GRADLE_OPTS environment variables.
168+
169+
# For Cygwin or MSYS, switch paths to Windows format before running java
170+
if "$cygwin" || "$msys" ; then
171+
APP_HOME=$( cygpath --path --mixed "$APP_HOME" )
172+
CLASSPATH=$( cygpath --path --mixed "$CLASSPATH" )
173+
174+
JAVACMD=$( cygpath --unix "$JAVACMD" )
175+
176+
# Now convert the arguments - kludge to limit ourselves to /bin/sh
177+
for arg do
178+
if
179+
case $arg in #(
180+
-*) false ;; # don't mess with options #(
181+
/?*) t=${arg#/} t=/${t%%/*} # looks like a POSIX filepath
182+
[ -e "$t" ] ;; #(
183+
*) false ;;
184+
esac
185+
then
186+
arg=$( cygpath --path --ignore --mixed "$arg" )
187+
fi
188+
# Roll the args list around exactly as many times as the number of
189+
# args, so each arg winds up back in the position where it started, but
190+
# possibly modified.
191+
#
192+
# NB: a `for` loop captures its iteration list before it begins, so
193+
# changing the positional parameters here affects neither the number of
194+
# iterations, nor the values presented in `arg`.
195+
shift # remove old arg
196+
set -- "$@" "$arg" # push replacement arg
197+
done
198+
fi
199+
200+
# Collect all arguments for the java command;
201+
# * $DEFAULT_JVM_OPTS, $JAVA_OPTS, and $GRADLE_OPTS can contain fragments of
202+
# shell script including quotes and variable substitutions, so put them in
203+
# double quotes to make sure that they get re-expanded; and
204+
# * put everything else in single quotes, so that it's not re-expanded.
205+
206+
set -- \
207+
"-Dorg.gradle.appname=$APP_BASE_NAME" \
208+
-classpath "$CLASSPATH" \
209+
org.gradle.wrapper.GradleWrapperMain \
210+
"$@"
211+
212+
# Stop when "xargs" is not available.
213+
if ! command -v xargs >/dev/null 2>&1
214+
then
215+
die "xargs is not available"
216+
fi
217+
218+
# Use "xargs" to parse quoted args.
219+
#
220+
# With -n1 it outputs one arg per line, with the quotes and backslashes removed.
221+
#
222+
# In Bash we could simply go:
223+
#
224+
# readarray ARGS < <( xargs -n1 <<<"$var" ) &&
225+
# set -- "${ARGS[@]}" "$@"
226+
#
227+
# but POSIX shell has neither arrays nor command substitution, so instead we
228+
# post-process each arg (as a line of input to sed) to backslash-escape any
229+
# character that might be a shell metacharacter, then use eval to reverse
230+
# that process (while maintaining the separation between arguments), and wrap
231+
# the whole thing up as a single "set" statement.
232+
#
233+
# This will of course break if any of these variables contains a newline or
234+
# an unmatched quote.
235+
#
236+
237+
eval "set -- $(
238+
printf '%s\n' "$DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS" |
239+
xargs -n1 |
240+
sed ' s~[^-[:alnum:]+,./:=@_]~\\&~g; ' |
241+
tr '\n' ' '
242+
)" '"$@"'
243+
244+
exec "$JAVACMD" "$@"

0 commit comments

Comments
 (0)