I'm setting up a spring-security saml 2.0 blueprint for my company.
I'm following the Howtos of Ulises Bocchio. Everything is fine so far - the sample authentication process works fine.
To follow the security guideline of our company, I have to make the SAMLConfig.java file configurable. My first thought was to autowire a component that loads the configuration from "somewhere"; like the following.
/**
* @author Ulises Bocchio
*/
@AutoConfigureBefore(WebSecurityConfig.class)
@Configuration
public class SAMLConfig {
protected Logger log = LoggerFactory.getLogger(this.getClass());
@Autowired
private SAMLUserDetailsServiceImpl samlUserDetailsServiceImpl;
@Autowired
private SAMLProperties samlProperties;
@Bean
public SAMLAuthenticationProvider samlAuthenticationProvider() {
final SAMLAuthenticationProvider provider = new SAMLAuthenticationProvider();
provider.setUserDetails(this.samlUserDetailsServiceImpl);
provider.setForcePrincipalAsString(false);
return provider;
}
This won't work, because the SAMLProperties object is null. I'm not sure but is it possible, that spring security is initiated before other (application) components?
How can I achieve a dynamic configuration of Ulises Bocchio's SAMLConfig.java file?