Authentication for SPA in Microservice architecture

Viewed 587

I am looking for an optimal way to create registration, authentication, and authorization for our project based on spring boot microservices. Microservices will provide rest API for SPA application, and later for mobile applications (android and ios). Actually, we have all users in Postgres database.

As I mentioned user registration and authentication will be consumed by SPA and mobile platforms so I prefer RESTful API for that.

My idea is to have one auth-service which will resolve auth* actions, and also provide a public key for other microservices to decode and verify JWT.

In fact that we don't need to provide authorization to external services does make sense to use OIDC provider like Keycloak? Or custom authentication is a better option?

1 Answers

You're not forced to use the authorization capabilities provided by Keycloak if you want to use it for OIDC support. You can benefit from its registration, authentication or forget password flows as well as easily configurable OAuth/OIDC features.

Another nice feature about Keycloak is the smooth integration in the client side which allows your code to work almost with no change. I've not evaluated their Spring adapter, but in projects that I was involved, as they were all JEE based and were using standard security APIs provided by all application servers, we really benefited from using Keycloak adapter for our application server. It handles all the logic you described in your question, before the request reaches our code, which means everything is already setup (i.e. token got validated/verified and principal and roles are already extracted from it and we can just access it via request.getPrincipal() or sessionContext.getCallerPrincipal(), request.isUserInRole(), etc.).

Related