Class LinkingOAuth2UserService
- All Implemented Interfaces:
OAuth2UserService<OAuth2UserRequest, OAuth2User>
Signs the user of an identity provider in as a user of the application's own.
LinkingOAuth2UserService linking = new LinkingOAuth2UserService(identities, users);
linking.setCreateUsers(true);
http.oauth2Login(oauth2 -> oauth2
.userService(linking)
.oidcUserService(linking.oidc()));
Who the provider's user is here is decided in this order:
-
An identity -- this provider, this subject -- that is tied to a local user already signs in as that user. Nothing else about the provider's answer is consulted: not the email, which may have changed since.
-
Otherwise the provider must say the user's email address is one it has verified. An address it does not vouch for is refused with
EMAIL_NOT_VERIFIED, whether or not anybody here has it: tying an account to an address somebody merely typed at a provider would hand that account to them.A provider whose registration names a
ClientRegistration.ProviderDetails.getUserEmailsUri()-- GitHub, whose user carries no such flag and often no address -- is asked there instead, with the user's access token: the address is the one the list marks bothprimaryandverified, and whatever the user info said of an address is not consulted. No such entry, or a list that cannot be read (theuser:emailscope was not granted), is refused the same way. -
A verified address that is the name of a local user ties the identity to that user, and signs in as them.
-
A verified address nobody here has makes a new local user of that name -- when
setCreateUsers(boolean)allows it and the users are aUserDetailsManager-- and is refused withACCOUNT_NOT_FOUNDotherwise.
The user that comes back is named after the local account and has its authorities, with the provider's attributes beside them; a second factor and remember-me, which go by name, then apply to it exactly as they do to a sign-in with a password.
A new user has a password nobody knows: 256 random bits under an encoding id no encoder has. They sign in through the provider until they set one.
-
Field Summary
Fields -
Constructor Summary
ConstructorsConstructorDescriptionLinkingOAuth2UserService(FederatedIdentityRepository identities, UserDetailsService users) -
Method Summary
Modifier and TypeMethodDescriptionloadUser(OAuth2UserRequest userRequest) The user.oidc()This service for a provider with OpenID Connect.voidsetCreateUsers(boolean createUsers) Whether a verified address nobody here has becomes a new local user.voidsetEmailAttributes(String emailAttribute, String emailVerifiedAttribute) The attributes that hold the address and whether it is verified;emailandemail_verifiedunless set.voidsetNewUserAuthorities(Collection<? extends GrantedAuthority> authorities) What a new user is granted;ROLE_USERunless set.voidWhat reads the user from a provider without OpenID Connect.voidWhat reads the user from an OpenID Connect provider.
-
Field Details
-
EMAIL_NOT_VERIFIED
The provider does not vouch for the user's email address.- See Also:
-
ACCOUNT_NOT_FOUND
Nobody here has the address, and new users are not made.- See Also:
-
ACCOUNT_UNAVAILABLE
The local user the identity is tied to cannot sign in.- See Also:
-
-
Constructor Details
-
LinkingOAuth2UserService
- Parameters:
users- the application's users; aUserDetailsManagerto let new ones be made
-
-
Method Details
-
setCreateUsers
public void setCreateUsers(boolean createUsers) Whether a verified address nobody here has becomes a new local user. Off unless set. -
setNewUserAuthorities
What a new user is granted;ROLE_USERunless set. -
setEmailAttributes
-
setOAuth2UserService
What reads the user from a provider without OpenID Connect. -
setOidcUserService
What reads the user from an OpenID Connect provider. -
loadUser
Description copied from interface:OAuth2UserServiceThe user.
OAuth2AuthenticationException: to refuse the sign-in
- Specified by:
loadUserin interfaceOAuth2UserService<OAuth2UserRequest, OAuth2User>
-
oidc
This service for a provider with OpenID Connect.
-