mirror of
https://github.com/spring-projects/spring-boot.git
synced 2026-10-05 08:49:15 +00:00
Start building against Spring Security 7.0.0-RC1 snapshots
See gh-47499
This commit is contained in:
+5
-1
@@ -153,7 +153,11 @@ class SecurityService {
|
||||
.uri(this.cloudControllerUrl + "/info")
|
||||
.retrieve()
|
||||
.bodyToMono(Map.class)
|
||||
.map((response) -> (String) response.get("token_endpoint"))
|
||||
.map((response) -> {
|
||||
String tokenEndpoint = (String) response.get("token_endpoint");
|
||||
Assert.state(tokenEndpoint != null, "No 'token_endpoint' found in response");
|
||||
return tokenEndpoint;
|
||||
})
|
||||
.cache()
|
||||
.onErrorMap((ex) -> new CloudFoundryAuthorizationException(Reason.SERVICE_UNAVAILABLE,
|
||||
"Unable to fetch token keys from UAA."));
|
||||
|
||||
+6
-1
@@ -33,6 +33,7 @@ import reactor.core.publisher.Mono;
|
||||
import org.springframework.boot.cloudfoundry.actuate.autoconfigure.endpoint.CloudFoundryAuthorizationException;
|
||||
import org.springframework.boot.cloudfoundry.actuate.autoconfigure.endpoint.CloudFoundryAuthorizationException.Reason;
|
||||
import org.springframework.boot.cloudfoundry.actuate.autoconfigure.endpoint.Token;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
/**
|
||||
* Validator used to ensure that a signed {@link Token} has not been tampered with.
|
||||
@@ -85,7 +86,11 @@ class TokenValidator {
|
||||
return this.securityService.fetchTokenKeys()
|
||||
.doOnSuccess(this::cacheTokenKeys)
|
||||
.filter((tokenKeys) -> tokenKeys.containsKey(keyId))
|
||||
.map((tokenKeys) -> tokenKeys.get(keyId))
|
||||
.map((tokenKeys) -> {
|
||||
String tokenKey = tokenKeys.get(keyId);
|
||||
Assert.state(tokenKey != null, "No token key found for '%s'".formatted(keyId));
|
||||
return tokenKey;
|
||||
})
|
||||
.switchIfEmpty(Mono.error(new CloudFoundryAuthorizationException(Reason.INVALID_KEY_ID,
|
||||
"Key Id present in token header does not match")));
|
||||
}
|
||||
|
||||
+1
-1
@@ -289,7 +289,7 @@ public class OAuth2AuthorizationServerProperties implements InitializingBean {
|
||||
* Whether the client is required to provide a proof key challenge and verifier
|
||||
* when performing the Authorization Code Grant flow.
|
||||
*/
|
||||
private boolean requireProofKey = false;
|
||||
private boolean requireProofKey = true;
|
||||
|
||||
/**
|
||||
* Whether authorization consent is required when the client requests access.
|
||||
|
||||
+5
-1
@@ -66,6 +66,7 @@ import org.springframework.security.config.BeanIds;
|
||||
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
|
||||
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
|
||||
import org.springframework.security.core.GrantedAuthority;
|
||||
import org.springframework.security.core.authority.FactorGrantedAuthority;
|
||||
import org.springframework.security.oauth2.core.DelegatingOAuth2TokenValidator;
|
||||
import org.springframework.security.oauth2.core.OAuth2TokenValidator;
|
||||
import org.springframework.security.oauth2.jwt.Jwt;
|
||||
@@ -674,7 +675,10 @@ class OAuth2ResourceServerAutoConfigurationTests {
|
||||
JwtAuthenticationConverter converter = context.getBean(JwtAuthenticationConverter.class);
|
||||
AbstractAuthenticationToken token = converter.convert(jwt);
|
||||
assertThat(token).isNotNull().extracting(AbstractAuthenticationToken::getName).isEqualTo(expectedPrincipal);
|
||||
assertThat(token.getAuthorities()).extracting(GrantedAuthority::getAuthority)
|
||||
assertThat(token.getAuthorities()
|
||||
.stream()
|
||||
.filter((authority) -> !(authority instanceof FactorGrantedAuthority)))
|
||||
.extracting(GrantedAuthority::getAuthority)
|
||||
.containsExactlyInAnyOrder(expectedAuthorities);
|
||||
assertThat(context).hasSingleBean(JwtDecoder.class);
|
||||
assertThat(getBearerTokenFilter(context)).isNotNull();
|
||||
|
||||
@@ -2533,7 +2533,7 @@ bom {
|
||||
releaseNotes("https://github.com/spring-projects/spring-restdocs/releases/tag/v{version}")
|
||||
}
|
||||
}
|
||||
library("Spring Security", "7.0.0-M3") {
|
||||
library("Spring Security", "7.0.0-SNAPSHOT") {
|
||||
considerSnapshots()
|
||||
group("org.springframework.security") {
|
||||
bom("spring-security-bom")
|
||||
|
||||
Reference in New Issue
Block a user