I was reading an article about OAuth 2.0 with jwt tokens. Interesting part is when author describes client_secret, he says:
In a non-trivial implementation client ids and passwords will be securely stored in a database and retrievable through a separate API that clients applications access during deployment.
Now let's say I have a frontend app in angular and a backend app in spring with MySQL db.
My question is what author meant by the aforementioned quote. Is it, that
client (frontend app in this case) makes a call using client_id
and secret (nothing changes here), but backend is checking
provided "credentials" not by comparing with values stored in plain-text (in
application.properties in that case), but making a hash from received values and
comparing with hashed version in db ?
- User
john doeopenslog inpage. Provides credentials:username:john.doeandpassword:john1. Clickssign in. - Angular-frontend intercepts request, and executes a method (f.e.
obtainTokenForUser()) in order to get a short-period-valid jwt token for the user. For that reason angular-app sends anOAuth2.0-compliant request to theauthorization server. Before sending contantAWS KMSto get itsclient_idandsecretin order to attach to the request. In the end, the request from angular to auth server looks like:curl front-app-sp3:frnt4pP@<auth_server_ip_addr>:<auth_server_port>/oauth/token -d grant_type=password -d username=john.doe -d password=john1 Authorization servercontactsAWS KMSfor receivedclient_id:front-app-sp3andclient_secret:frnt4pP. It finds the entry, passwords matches, validation correct.Auth servergenerates a JWT token valid f.e.5 minutes. The token is signed by the server usingAS_pr1v4t3private key.Authorization serverreturns a token to angular app.- User is logged in. User requests a resource in the main app (in spring), thus angular adds an obtained token and sends the request to the "Main-web application".
Resource serverin the "Main-web application" validates token. Token is correct and valid. Resource is returned.
