Class OAuth2LoginConfigurer
Sign-in through another identity provider, with OAuth2 or OpenID Connect.
http.authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
.oauth2Login(Customizer.withDefaults());
with, in application.properties,
cn1.security.oauth2.client.registration.google.client-id=...
cn1.security.oauth2.client.registration.google.client-secret=...
The providers are the application's
ClientRegistrationRepository bean, or the registrations the configuration
declares; see ClientRegistrations and
CommonOAuth2Provider.
A sign-in starts at GET /oauth2/authorization/{registrationId}, which
sends the browser to the provider, and ends at
/login/oauth2/code/{registrationId}, where the provider sends it back.
Every request carries a state, a PKCE challenge and, with OpenID Connect,
a nonce; the answer is taken only when it repeats the state this
browser was given, the code is exchanged with the PKCE verifier, and an ID
token is accepted only as
OidcIdTokenDecoderFactory describes and with that nonce in it.
Who the provider's user is here is the OAuth2UserService's to say; see
userService and oidcUserService, and
LinkingOAuth2UserService for
tying them to the application's own users. The sign-in then ends the way
every sign-in to a session does -- see SessionSignIn -- so a second factor
and remember-me apply to it.
A signed-in user goes back to the page that asked for the sign-in, or to
defaultSuccessUrl: nothing the provider or the request says chooses the
address. A refused one goes to /login?error, and is told nothing of why;
the reason, as an OAuth2 error code, is the
AuthenticationFailureHandler's to read from the exception.
A chain that serves no login page of its own serves a plain one at
GET /login with a link per provider, and sends a request that must sign
in straight to the provider when there is only one.
-
Method Summary
Modifier and TypeMethodDescriptionaccessTokenResponseClient(OAuth2AccessTokenResponseClient accessTokenResponseClient) What exchanges the code for tokens.authorizationEndpointBaseUri(String baseUri) The path a sign-in starts at, before the registration's id;/oauth2/authorizationunless set.authorizationRequestRepository(AuthorizationRequestRepository authorizationRequestRepository) Where a request waits while the user is at the provider, for every provider.authorizationRequestResolver(OAuth2AuthorizationRequestResolver authorizationRequestResolver) What decides that a request starts a sign-in and what is asked of the provider; seeDefaultOAuth2AuthorizationRequestResolver.clientRegistrationRepository(ClientRegistrationRepository clientRegistrationRepository) The providers, in place of the application's bean and the configuration.voidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.defaultSuccessUrl(String defaultSuccessUrl) Where a user goes after signing in when no page asked for the sign-in;/unless set.defaultSuccessUrl(String defaultSuccessUrl, boolean alwaysUse) failureHandler(AuthenticationFailureHandler failureHandler) What answers a refused sign-in.failureUrl(String failureUrl) Where a refused sign-in goes; the login page with?errorunless set.What verifies ID tokens.voidinit(HttpSecurity http) Shares what other parts need to know; nothing by default.The application's own login page: a path it serves, with a link to/oauth2/authorization/{registrationId}for each provider.oidcUserService(OAuth2UserService<OidcUserRequest, OidcUser> oidcUserService) What makes the user of an OpenID Connect provider.Lets everyone reach the login page and the failure page, whatever the authorization rules say.redirectionEndpointBaseUri(String baseUri) The path a provider answers at, before the registration's id;/login/oauth2/codeunless set.successHandler(AuthenticationSuccessHandler successHandler) userService(OAuth2UserService<OAuth2UserRequest, OAuth2User> userService) What makes the user of a provider without OpenID Connect.Methods inherited from class SecurityConfigurer
disable, getBuilder
-
Method Details
-
clientRegistrationRepository
public OAuth2LoginConfigurer clientRegistrationRepository(ClientRegistrationRepository clientRegistrationRepository) The providers, in place of the application's bean and the configuration. -
loginPage
The application's own login page: a path it serves, with a link to/oauth2/authorization/{registrationId}for each provider. -
authorizationRequestResolver
public OAuth2LoginConfigurer authorizationRequestResolver(OAuth2AuthorizationRequestResolver authorizationRequestResolver) What decides that a request starts a sign-in and what is asked of the provider; seeDefaultOAuth2AuthorizationRequestResolver. -
authorizationEndpointBaseUri
The path a sign-in starts at, before the registration's id;/oauth2/authorizationunless set. -
redirectionEndpointBaseUri
The path a provider answers at, before the registration's id;/login/oauth2/codeunless set. A registration's redirect address has to agree with it. -
authorizationRequestRepository
public OAuth2LoginConfigurer authorizationRequestRepository(AuthorizationRequestRepository authorizationRequestRepository) Where a request waits while the user is at the provider, for every provider. Unless set, the session -- and a signed cookie for a provider that answers with a posted form; seeCookieOAuth2AuthorizationRequestRepository. -
accessTokenResponseClient
public OAuth2LoginConfigurer accessTokenResponseClient(OAuth2AccessTokenResponseClient accessTokenResponseClient) What exchanges the code for tokens. -
userService
public OAuth2LoginConfigurer userService(OAuth2UserService<OAuth2UserRequest, OAuth2User> userService) What makes the user of a provider without OpenID Connect. -
oidcUserService
public OAuth2LoginConfigurer oidcUserService(OAuth2UserService<OidcUserRequest, OidcUser> oidcUserService) What makes the user of an OpenID Connect provider. -
idTokenDecoderFactory
What verifies ID tokens. -
defaultSuccessUrl
Where a user goes after signing in when no page asked for the sign-in;/unless set. -
defaultSuccessUrl
- Parameters:
alwaysUse- go there even when a page asked for the sign-in
-
successHandler
-
failureUrl
Where a refused sign-in goes; the login page with?errorunless set. -
failureHandler
What answers a refused sign-in. The exception it is given is anOAuth2AuthenticationExceptionwhose error says why. -
permitAll
Lets everyone reach the login page and the failure page, whatever the authorization rules say. Needed with aloginPageof the application's. -
init
Description copied from class:SecurityConfigurerShares what other parts need to know; nothing by default.- Overrides:
initin classSecurityConfigurer
-
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-