Posts

Showing posts with the label Spring Security

Spring Security: Configuring HttpSecurity

Spring Security 5.4 introduced the ability to configure HttpSecurity by creating a SecurityFilterChain bean. Below is an example configuration using the WebSecurityConfigurerAdapter that secures all endpoints with HTTP Basic: @Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter {     @Override     protected void configure(HttpSecurity http) throws Exception {         http             .authorizeHttpRequests((authz) -> authz                 .anyRequest().authenticated()             )             .httpBasic(withDefaults());     } } Going forward, the recommended way of doing this is registering a SecurityFilterChain bean: @Configuration public class SecurityConfiguration {     @Bean     public SecurityFilterChain filterChain(HttpSecurity http) throws Except...

Spring Security: Configuring WebSecurity

Spring Security 5.4 also introduced the WebSecurityCustomizer. The WebSecurityCustomizer is a callback interface that can be used to customize WebSecurity. Below is an example configuration using the WebSecurityConfigurerAdapter that ignores requests that match /ignore1 or /ignore2: @Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter {     @Override     public void configure(WebSecurity web) {         web.ignoring().antMatchers("/ignore1", "/ignore2");     } } Going forward, the recommended way of doing this is registering a WebSecurityCustomizer bean: @Configuration public class SecurityConfiguration {     @Bean     public WebSecurityCustomizer webSecurityCustomizer() {         return (web) -> web.ignoring().antMatchers("/ignore1", "/ignore2");     } } WARNING: If you are configuring WebSecurity to ignore requests, consider using permitAll via HttpSe...

Spring Security: LDAP Authentication exampe

Spring Security 5.7 introduced the EmbeddedLdapServerContextSourceFactoryBean, LdapBindAuthenticationManagerFactory and LdapPasswordComparisonAuthenticationManagerFactory which can be used to create an embedded LDAP Server and an AuthenticationManager that performs LDAP authentication. Below is an example configuration using WebSecurityConfigurerAdapter the that creates an embedded LDAP server and an AuthenticationManager that performs LDAP authentication using bind authentication: @Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter {     @Override     protected void configure(AuthenticationManagerBuilder auth) throws Exception {         auth             .ldapAuthentication()             .userDetailsContextMapper(new PersonContextMapper())             .userDnPatterns("uid={0},ou=people")           ...

Spring Security: JDBC Authentication example

Below is an example configuration using the WebSecurityConfigurerAdapter with an embedded DataSource that is initialized with the default schema and has a single user: @Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter {     @Bean     public DataSource dataSource() {         return new EmbeddedDatabaseBuilder()             .setType(EmbeddedDatabaseType.H2)             .build();     }     @Override     protected void configure(AuthenticationManagerBuilder auth) throws Exception {         UserDetails user = User.withDefaultPasswordEncoder()             .username("user")             .password("password")             .roles("USER")             .build();         auth.jdbc...

Spring Security : Global and Local AuthenticationManager example

Global AuthenticationManager To create an AuthenticationManager that is available to the entire application you can simply register the AuthenticationManager as a @Bean. @Configuration public class SecurityConfiguration {     @Bean     public EmbeddedLdapServerContextSourceFactoryBean contextSourceFactoryBean() {         EmbeddedLdapServerContextSourceFactoryBean contextSourceFactoryBean =             EmbeddedLdapServerContextSourceFactoryBean.fromEmbeddedLdapServer();         contextSourceFactoryBean.setPort(0);         return contextSourceFactoryBean;     }     @Bean     AuthenticationManager ldapAuthenticationManager(             BaseLdapPathContextSource contextSource) {         LdapBindAuthenticationManagerFactory factory =              new LdapBindAuthenticati...

Spring Security without the WebSecurityConfigurerAdapter

Spring Security moving towards a component-based security configuration. In Spring Security 5.7.0-M2, WebSecurityConfigurerAdapter is deprecated. To assist with the transition to this new style of configuration, we have compiled a list of common use-cases and the suggested alternatives going forward. In the examples below we follow best practice by using the Spring Security lambda DSL and the method HttpSecurity#authorizeHttpRequests to define our authorization rules. If you are new to the lambda DSL you can read about it in this blog post. If you would like to learn more about why we choose to use HttpSecurity#authorizeHttpRequests you can check out the reference documentation. Configuring HttpSecurity In Spring Security 5.4 we introduced the ability to configure HttpSecurity by creating a SecurityFilterChain bean. Below is an example configuration using the WebSecurityConfigurerAdapter that secures all endpoints with HTTP Basic: @Configuration public class SecurityConfiguration exten...

Spring Security - Spring SAML Tutorial

Spring Security SAML Extension Table of Contents I. Getting Started 1. Introduction 1.1. What this manual covers 1.2. When to use Spring Security SAML Extension 1.3. Features and supported profiles 1.4. Requirements 1.5. Source code 1.6. Builds 1.7. License 1.8. Issue tracking 1.9. Contributions 1.10. Commercial support 1.11. Community support 1.12. Dependencies 2. What's new 2.1. New features, improvements and fixes in 1.0.1.FINAL 2.2. New features, improvements and fixes in 1.0.0.FINAL 2.3. Important code changes in 1.0.0.FINAL 3. Glossary 4. Quick start guide 4.1. Pre-requisites 4.2. Installation steps 4.2.1. Downloading sample application 4.2.2. Configuration of IDP metadata 4.2.3. Generation of SP metadata 4.2.4. Compilation 4.2.5. Deployment 4.2.6. Uploading of SP metadata to the IDP 4.3. Testing single sign-on and single logout II. Configuring SAML Extension 5. Overview 6. Integration to applications 6.1. Maven dependency 6.2. Bean definitions 6.3. Java-based configuration 6...