In spring security how to implement both SAML and custom authentication handler

Viewed 447

I am implementing three types of authentication mechanisms they are SAML and two custom authentication. So, how can I implement a filter based on a header it'll detect the authentication type and it'll route to the appropriate authentication mechanism.

  1. SAML: In case of SAML if the cookie is having a key as saml then SAML authentication has to happen. In SAML authentication also whenever the user login happens I am inserting a cookie with the name saml in the browser and for further requests I need to invoke a REST API by passing saml cookie value and check whether the authentication is valid or not.

  2. Custom authentication: If the cookie key is having token1 or token2 then do the custom authentication which involves calling a Rest API by passing the token and check the user is valid or not.

I know about SAML with spring security but as I explained in SAML how we can do the rest API call and implement a filter that invoke an appropriate authentication mechanism how we can achieve this. Is there any reference which could help fr the above scenario .

2 Answers

You can do it using Spring Security AuthenticationManagerBuilder. Create a security configuration with three autowired autentication provider defined elsewhere

@Autowired
private CustomAuthenticationProvider1 customProvider1;

@Autowired
private CustomAuthenticationProvider2 customProvider2;

@Autowired
private SAMLAuthenticationProvider samlProvider;

and then using the AuthenticationManagerBuilder just add them

authenticationManagerBuilder.authenticationProvider(customProvider1);
authenticationManagerBuilder.authenticationProvider(customProvider2);
authenticationManagerBuilder.authenticationProvider(samlProvider);

For a complete example you can see this article

I am assuming you are using Azure for SAML authentication. Follow this way to implement custom and saml authentication.

  1. First, implement Simple JWT token authentication using spring security. I hope using this user can do authentication with username and password.
  2. Implement SAML authentication, I am assuming you are using Azure. this azure will return one token.
  3. Pass azure token from frontend to rest API. Validate this token using azure API with help of RestTemplate. if the token is valid, then create normal spring jwt token.

Now actually you are maintaining single token for all authentication.

Related