Skip to content

Introduce AuthenticationConverterServerWebExchangeMatcher #8854

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jul 21, 2020
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -108,6 +108,7 @@
import org.springframework.security.web.server.ServerAuthenticationEntryPoint;
import org.springframework.security.web.server.WebFilterExchange;
import org.springframework.security.web.server.authentication.AnonymousAuthenticationWebFilter;
import org.springframework.security.web.server.authentication.AuthenticationConverterServerWebExchangeMatcher;
import org.springframework.security.web.server.authentication.AuthenticationWebFilter;
import org.springframework.security.web.server.authentication.HttpBasicServerAuthenticationEntryPoint;
import org.springframework.security.web.server.authentication.ReactivePreAuthenticatedAuthenticationManager;
Expand Down Expand Up @@ -179,8 +180,6 @@
import org.springframework.web.server.WebFilterChain;

import static org.springframework.security.web.server.DelegatingServerAuthenticationEntryPoint.DelegateEntry;
import static org.springframework.security.web.server.util.matcher.ServerWebExchangeMatcher.MatchResult.match;
import static org.springframework.security.web.server.util.matcher.ServerWebExchangeMatcher.MatchResult.notMatch;

/**
* A {@link ServerHttpSecurity} is similar to Spring Security's {@code HttpSecurity} but for WebFlux.
Expand Down Expand Up @@ -1629,8 +1628,7 @@ public class OAuth2ResourceServerSpec {
private ServerAuthenticationEntryPoint entryPoint = new BearerTokenServerAuthenticationEntryPoint();
private ServerAccessDeniedHandler accessDeniedHandler = new BearerTokenServerAccessDeniedHandler();
private ServerAuthenticationConverter bearerTokenConverter = new ServerBearerTokenAuthenticationConverter();
private BearerTokenServerWebExchangeMatcher bearerTokenServerWebExchangeMatcher =
new BearerTokenServerWebExchangeMatcher();
private AuthenticationConverterServerWebExchangeMatcher authenticationConverterServerWebExchangeMatcher;

private JwtSpec jwt;
private OpaqueTokenSpec opaqueToken;
Expand Down Expand Up @@ -1748,8 +1746,8 @@ public OAuth2ResourceServerSpec opaqueToken(Customizer<OpaqueTokenSpec> opaqueTo
}

protected void configure(ServerHttpSecurity http) {
this.bearerTokenServerWebExchangeMatcher
.setBearerTokenConverter(this.bearerTokenConverter);
this.authenticationConverterServerWebExchangeMatcher =
new AuthenticationConverterServerWebExchangeMatcher(this.bearerTokenConverter);

registerDefaultAccessDeniedHandler(http);
registerDefaultAuthenticationEntryPoint(http);
Expand Down Expand Up @@ -1794,7 +1792,7 @@ private void registerDefaultAccessDeniedHandler(ServerHttpSecurity http) {
if ( http.exceptionHandling != null ) {
http.defaultAccessDeniedHandlers.add(
new ServerWebExchangeDelegatingServerAccessDeniedHandler.DelegateEntry(
this.bearerTokenServerWebExchangeMatcher,
this.authenticationConverterServerWebExchangeMatcher,
OAuth2ResourceServerSpec.this.accessDeniedHandler
)
);
Expand All @@ -1805,7 +1803,7 @@ private void registerDefaultAuthenticationEntryPoint(ServerHttpSecurity http) {
if (http.exceptionHandling != null) {
http.defaultEntryPoints.add(
new DelegateEntry(
this.bearerTokenServerWebExchangeMatcher,
this.authenticationConverterServerWebExchangeMatcher,
OAuth2ResourceServerSpec.this.entryPoint
)
);
Expand All @@ -1820,27 +1818,7 @@ private void registerDefaultCsrfOverride(ServerHttpSecurity http) {
new AndServerWebExchangeMatcher(
CsrfWebFilter.DEFAULT_CSRF_MATCHER,
new NegatedServerWebExchangeMatcher(
this.bearerTokenServerWebExchangeMatcher)));
}
}

private class BearerTokenServerWebExchangeMatcher implements ServerWebExchangeMatcher {
ServerAuthenticationConverter bearerTokenConverter;

@Override
public Mono<MatchResult> matches(ServerWebExchange exchange) {
return this.bearerTokenConverter.convert(exchange)
.flatMap(this::nullAuthentication)
.onErrorResume(e -> notMatch());
}

public void setBearerTokenConverter(ServerAuthenticationConverter bearerTokenConverter) {
Assert.notNull(bearerTokenConverter, "bearerTokenConverter cannot be null");
this.bearerTokenConverter = bearerTokenConverter;
}

private Mono<MatchResult> nullAuthentication(Authentication authentication) {
return authentication == null ? notMatch() : match();
this.authenticationConverterServerWebExchangeMatcher)));
}
}

Expand Down Expand Up @@ -4034,4 +4012,5 @@ private String getKey() {
private AnonymousSpec() {}

}

}
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
/*
* Copyright 2002-2020 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package org.springframework.security.web.server.authentication;

import static org.springframework.security.web.server.util.matcher.ServerWebExchangeMatcher.MatchResult.match;
import static org.springframework.security.web.server.util.matcher.ServerWebExchangeMatcher.MatchResult.notMatch;

import org.springframework.security.core.Authentication;
import org.springframework.security.web.server.util.matcher.ServerWebExchangeMatcher;
import org.springframework.util.Assert;
import org.springframework.web.server.ServerWebExchange;

import reactor.core.publisher.Mono;

/**
* Matches if the {@link ServerAuthenticationConverter} can convert a {@link ServerWebExchange} to an {@link Authentication}.
*
* @author David Kovac
* @since 5.4
* @see ServerAuthenticationConverter
*/
public final class AuthenticationConverterServerWebExchangeMatcher implements ServerWebExchangeMatcher {
private final ServerAuthenticationConverter serverAuthenticationConverter;

public AuthenticationConverterServerWebExchangeMatcher(ServerAuthenticationConverter serverAuthenticationConverter) {
Assert.notNull(serverAuthenticationConverter, "serverAuthenticationConverter cannot be null");
this.serverAuthenticationConverter = serverAuthenticationConverter;
}

@Override
public Mono<MatchResult> matches(ServerWebExchange exchange) {
return this.serverAuthenticationConverter.convert(exchange)
.flatMap(a -> match())
.onErrorResume(e -> notMatch())
.switchIfEmpty(notMatch());
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
/*
* Copyright 2002-2020 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package org.springframework.security.web.server.authentication;

import static org.assertj.core.api.Assertions.assertThat;
import static org.assertj.core.api.Assertions.assertThatCode;
import static org.mockito.ArgumentMatchers.any;
import static org.mockito.Mockito.when;

import org.junit.Before;
import org.junit.Test;
import org.junit.runner.RunWith;
import org.mockito.Mock;
import org.mockito.junit.MockitoJUnitRunner;
import org.springframework.mock.http.server.reactive.MockServerHttpRequest;
import org.springframework.mock.web.server.MockServerWebExchange;
import org.springframework.security.core.Authentication;

import reactor.core.publisher.Mono;

/**
* @author David Kovac
* @since 5.4
*/
@RunWith(MockitoJUnitRunner.class)
public class AuthenticationConverterServerWebExchangeMatcherTests {
private MockServerWebExchange exchange;
private AuthenticationConverterServerWebExchangeMatcher matcher;
@Mock
private ServerAuthenticationConverter converter;
@Mock
private Authentication authentication;

@Before
public void setup() {
MockServerHttpRequest request = MockServerHttpRequest.get("/path").build();
exchange = MockServerWebExchange.from(request);
matcher = new AuthenticationConverterServerWebExchangeMatcher(converter);
}

@Test(expected = IllegalArgumentException.class)
public void constructorConverterWhenConverterNullThenThrowsException() {
new AuthenticationConverterServerWebExchangeMatcher(null);
}

@Test
public void matchesWhenNotEmptyThenReturnTrue() {
when(converter.convert(any())).thenReturn(Mono.just(authentication));

assertThat(matcher.matches(exchange).block().isMatch()).isTrue();
}

@Test
public void matchesWhenEmptyThenReturnFalse() {
when(converter.convert(any())).thenReturn(Mono.empty());

assertThat(matcher.matches(exchange).block().isMatch()).isFalse();
}

@Test
public void matchesWhenErrorThenReturnFalse() {
when(converter.convert(any())).thenReturn(Mono.error(new RuntimeException()));

assertThat(matcher.matches(exchange).block().isMatch()).isFalse();
}

@Test
public void matchesWhenNullThenThrowsException() {
when(this.converter.convert(any())).thenReturn(null);

assertThatCode(() -> matcher.matches(exchange).block())
.isInstanceOf(NullPointerException.class);
}

@Test
public void matchesWhenExceptionThenPropagates() {
when(this.converter.convert(any())).thenThrow(RuntimeException.class);

assertThatCode(() -> matcher.matches(exchange).block())
.isInstanceOf(RuntimeException.class);
}
}