Use X509 Certificate auth with JWT token based auth

Viewed 401

I have a Spring Boot application currently using X509 certificate authentication. Can I use JWT alongside to secure the API's via tokens and application via X509 protocol?

Use case:

The exposed/deployed application URL should be authenticated with a certificate and once verified the user should present valid JWT token to access any API inside the application. I currently have below Websecurity configured for my X509 certificate.

public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Value("${security.enable-csrf}")
    private boolean csrfEnabled;

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests().anyRequest().authenticated().and().x509().subjectPrincipalRegex("CN=(.*?)(?:,|$)")
                .userDetailsService(userDetailsService());
        
        if (!csrfEnabled) {
            http.csrf().disable();
        }
    }

    @Bean
    public UserDetailsService userDetailsService() {
        return (UserDetailsService) username -> {
            if (username.equals("XXXX")) {
                return new User(username, "", AuthorityUtils.commaSeparatedStringToAuthorityList("ROLE_USER"));
            } else {
                throw new UsernameNotFoundException(String.format("User %s not found", username));
            }
        };
0 Answers
Related