You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
82 lines
2.9 KiB
82 lines
2.9 KiB
/* |
|
* Copyright 2020-2024 the original author or authors. |
|
* |
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
|
* you may not use this file except in compliance with the License. |
|
* You may obtain a copy of the License at |
|
* |
|
* https://www.apache.org/licenses/LICENSE-2.0 |
|
* |
|
* Unless required by applicable law or agreed to in writing, software |
|
* distributed under the License is distributed on an "AS IS" BASIS, |
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|
* See the License for the specific language governing permissions and |
|
* limitations under the License. |
|
*/ |
|
package sample.sociallogin; |
|
|
|
import org.springframework.context.annotation.Bean; |
|
import org.springframework.context.annotation.Configuration; |
|
import org.springframework.core.annotation.Order; |
|
import org.springframework.http.MediaType; |
|
import org.springframework.security.config.Customizer; |
|
import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
|
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; |
|
import org.springframework.security.oauth2.server.authorization.config.annotation.web.configurers.OAuth2AuthorizationServerConfigurer; |
|
import org.springframework.security.web.SecurityFilterChain; |
|
import org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint; |
|
import org.springframework.security.web.util.matcher.MediaTypeRequestMatcher; |
|
|
|
@Configuration |
|
@EnableWebSecurity |
|
public class SecurityConfig { |
|
|
|
@Bean // <1> |
|
@Order(1) |
|
public SecurityFilterChain authorizationServerSecurityFilterChain(HttpSecurity http) |
|
throws Exception { |
|
OAuth2AuthorizationServerConfigurer authorizationServerConfigurer = |
|
OAuth2AuthorizationServerConfigurer.authorizationServer(); |
|
|
|
// @formatter:off |
|
http |
|
.securityMatcher(authorizationServerConfigurer.getEndpointsMatcher()) |
|
.with(authorizationServerConfigurer, (authorizationServer) -> |
|
authorizationServer |
|
.oidc(Customizer.withDefaults()) // Enable OpenID Connect 1.0 |
|
) |
|
.authorizeHttpRequests((authorize) -> |
|
authorize |
|
.anyRequest().authenticated() |
|
) |
|
// Redirect to the OAuth 2.0 Login endpoint when not authenticated |
|
// from the authorization endpoint |
|
.exceptionHandling((exceptions) -> exceptions |
|
.defaultAuthenticationEntryPointFor( // <2> |
|
new LoginUrlAuthenticationEntryPoint("/oauth2/authorization/my-client"), |
|
new MediaTypeRequestMatcher(MediaType.TEXT_HTML) |
|
) |
|
); |
|
// @formatter:on |
|
|
|
return http.build(); |
|
} |
|
|
|
@Bean // <3> |
|
@Order(2) |
|
public SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) |
|
throws Exception { |
|
// @formatter:off |
|
http |
|
.authorizeHttpRequests((authorize) -> authorize |
|
.anyRequest().authenticated() |
|
) |
|
// OAuth2 Login handles the redirect to the OAuth 2.0 Login endpoint |
|
// from the authorization server filter chain |
|
.oauth2Login(Customizer.withDefaults()); // <4> |
|
// @formatter:on |
|
|
|
return http.build(); |
|
} |
|
|
|
}
|
|
|