Get role type after OAuth2 authentication

Viewed 259

I implemented OAuth2 authentication with Spring security legacy stack. After successful authentication I receive this payload:

{
    "access_token": "ed090e76-444b-4dd2-8c2a-15d3e52be31d",
    "token_type": "bearer",
    "refresh_token": "4ad590f1-2139-47b8-89f1-29ed4b461b53",
    "expires_in": 30,
    "scope": "read"
}

I have a several types of roles into the application. Usually in server-side rendering web application I just will show UI components based on the user role and I will restrict the unauthorized content.

In Angular there is also a way to show data based on the user role. But the problem is how Angular can get the type of the user role from the BE Spring Server?

After successful authentication I need to get the user role from the BE. How this is usually implemented when there is a SPA FE?

1 Answers

By default, Oauth2 Spring integration uses its own "type of tokens" (you can see them in your provided "example response"), if you want to work with JWT ones (easier to manage internally) you have to specify how to deal with them developing the suitable behaviour of JwtAccessTokenConverter.

In the following link you will be able to see a tutorial with a complete integration with: JWT + Oauth2

On the other hand, in the next one you will find a fully functional microservice used as Oauth 2.0 security server integrated with Spring, that includes several other customizations:

Oauth 2 security server

With an example of JwtAccessTokenConverter implementation here

Related