We are currently working on application having micro-service architecture with following components as shown in below image and everything is working fine.However need some clarification on following points.
- To secure communication between Gateway and Deep microservice we are passing IDToken and validating it at each microservice level however once IDtoken expires service returns 401 status code and then on Ui we trigger authorization flow which eventually results in full page refresh and if user in middle of submitting very large form then all the data will be lost moroever as per OIDC specificition we can't refresh ID token so not sure how to handle this scenario.
To overcome first problem we could pass access_token to microservice rather than idtoken however we need to call
/userinfoend point each time for getting user information from provider and considering high concurrency is it a good practice to proceed with ?Or we are missing something here and there are better alternatives to fix this problem ?
Any help would be much appreciated
Spring boot OIDC Properties in application.yml file
security:
oauth2:
client:
registration:
pingIdentity:
scope:
- openid
- profile
- email
- phone
- job_title
- scoped_entitlement
- authorization_group
- entitlement_group
- organizational_data
- basic_start_authorization
client-id: <Client ID>
client-secret: <Client Secret>
provider: pingIdentity
provider:
pingIdentity:
issuer-uri: <Issuer URI>
