Spring boot securing api with both basic authorization and jwt role based authorization

Viewed 37

I am trying to secure my api requests with both basic authorization and jwt role based authorization.

I have two classes for basic auth and web security config. Both jwt role based auth and basic auth classed are imported in WebSecurityConfigurerAdapter.

When running the application, api is working only with basic auth and does not know jwt token included or not.

WebSecurityConfigurerAdapter class

@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {

    final private static String REALM = "UWAPP_SECURITY_REALM";

    @Autowired
    UserDetailsServiceImpl userDetailsService;
    @Autowired
    private AuthEntryPointJwt unauthorizedHandler;

    @Autowired
    public WebSecurityConfig(UserDetailsServiceImpl userDetailsService) {
        super();
        this.userDetailsService = userDetailsService;
    }

    @Bean
    public AuthTokenFilter authenticationJwtTokenFilter() {
        return new AuthTokenFilter();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

    @Bean
    @Override
    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();
    }

    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userDetailsService).passwordEncoder(passwordEncoder());
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
                .exceptionHandling().authenticationEntryPoint(unauthorizedHandler).and()
                .authorizeRequests()
                .antMatchers("/actuator/health", "/api/auth/signup", "/api/auth/login", "/api/auth/logout").permitAll()
                .antMatchers("/api/test/public").permitAll()
                .antMatchers("/api/test/user").hasAnyAuthority(UserLoginRole.USER.value())
                .anyRequest().authenticated()
                .and()
                .formLogin().disable()
                .csrf().disable()
                .httpBasic().realmName(REALM)
                .authenticationEntryPoint(getBasicAuthEntryPoint());
        http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class);
        http.cors();
    }

    @Bean
    public BasicAuthentication getBasicAuthEntryPoint() {
        return new BasicAuthentication();
    }

}

BasicAuthentication class

public class BasicAuthentication extends BasicAuthenticationEntryPoint {

    final private static String REALM = "UWAPP_SECURITY_REALM";

    @Override
    public void commence(final HttpServletRequest request, final HttpServletResponse response,
                         final AuthenticationException authException) throws IOException {

        response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
        response.addHeader("WWW-Authenticate", "Basic realm=" + getRealmName() + "");

        PrintWriter writer = response.getWriter();
        writer.println("HTTP Status 401 : " + authException.getMessage());
    }

    @Override
    public void afterPropertiesSet() {
        setRealmName(REALM);
        super.afterPropertiesSet();
    }
}

Requests did not pass through authorization jwt token included or not.

What am I missing here?

0 Answers
Related