How do I enable multiple client ids in a Spring Boot OAuth2 Server?

Viewed 5104

I have Spring Boot OAuth2 server working, but now we need to distinguish between different clients from different departments and provide different functionality depending on the department. I figure I can separate it by the client id. This guide shows how to set up the OAuth2 server with a single client id, but how do I set it up with multiple client ids?

https://spring.io/guides/tutorials/spring-boot-oauth2/#_social_login_authserver

And then, when an API request is made, how do I find out which client id it is?

2 Answers

You can create multiple entries in table oauth_client_details with different combination of client_id and client_secret. The client_secret obviously will be encrypted.

Now to generate the refresh and access token, hit the url /oauth/token with Authorization : Basic base64-encoded,

Where base64-encoded will be Base64 encryption of client_id:client_secret. Remember, client_secret here should be original plain password (without encryption).

The same thing can be achieved using Spring xml configuration (in older way) as

<oauth:client client-id="mobile_ios"
        authorized-grant-types="password,refresh_token,implicit" secret="ios_s3cret"
        authorities="ROLE_CLIENT" 
        refresh-token-validity="7776000"
        access-token-validity="300" />

    <oauth:client client-id="mobile_android"
        authorized-grant-types="password,refresh_token,implicit" secret="android_s3cret"
        authorities="ROLE_CLIENT"
        refresh-token-validity="7776000"
        access-token-validity="300" />

    <oauth:client client-id="web_app"
        authorized-grant-types="password,refresh_token,implicit" secret="web_s3cret"
        authorities="ROLE_CLIENT" 
        refresh-token-validity="7776000"
        access-token-validity="30000" />
</oauth:client-details-service>
Related