mirror of
https://github.com/spring-projects/spring-boot.git
synced 2026-10-09 02:49:02 +00:00
Reactive SecurityService#getUaaUrl() creates a new Mono on each invocation, so the resolved UAA URL is not reused across calls. During token validation, this can lead to duplicate /info requests when token keys are fetched and the issuer is validated in the same flow. Cache the resolved UAA URL after a successful lookup and add regression tests that verify reuse after success and retry after failure. Signed-off-by: LeeJiWon <dlwldnjs1009@gmail.com>