Should the OAuth2 Token Endpoint require authentication?

Viewed 98

I'm using Spring Security OAuth2 to create my own authorization server. In my case I want to enable a Angular client (SPA) to use the Authorization Code Grant.

The client can use the oauth/authorize endpoint, the user can log in and the browser is redirect to the SPA. Now the client wants to get the token via oauth/token. But this endpoint is secured and needs client id and client secret. The security is enabled by default in Spring.

In the docs I could find the following:

The token endpoint is protected for you by default by Spring OAuth in the @Configuration support using HTTP Basic authentication of the client secret. This is not the case in XML (so it should be protected explicitly).

As far as I know there shouldn't be a client secret used in public clients. But that means, that the oauth/token endpoint should not be secure.

Question: Is it a good practice to disable auth for oauth/token? If not, how should I solve this?

This is my WebSecurityConfig:

@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
    @Bean
    @Override
    protected UserDetailsService userDetailsService() {
        // WARN: Do not use the default password encoder in production environments!
        return new InMemoryUserDetailsManager(
                User.withDefaultPasswordEncoder()
                .username("user-a")
                .password("password")
                .roles("USER_ROLE")
                .build()
        );
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http = http
            .requiresChannel()
                .anyRequest()
                .requiresSecure()
                .and()
            .cors()
                .and()
            .authorizeRequests()
                .antMatchers("/.well-known/**")
                .permitAll()
                .and();
        super.configure(http);
    }

    @Bean
    public CorsConfigurationSource corsConfigurationSource() {
        CorsConfiguration configuration = new CorsConfiguration();
        configuration.setAllowedOrigins(singletonList("*"));
        configuration.setAllowedMethods(asList("GET","POST"));
        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        source.registerCorsConfiguration("/**", configuration);
        return source;
    }
}
0 Answers
Related