Cycle Dependency Error in Spring Security

Viewed 108

I am using OAuth2 with Spring Security to secure my APIs. Below is my code:

Authorization Server

@Configuration
@EnableAuthorizationServer
public class AuthorizationServerConfig extends AuthorizationServerConfigurerAdapter {

    @Autowired
    private AuthenticationManager authenticationManager;

    @Override
    public void configure(AuthorizationServerSecurityConfigurer security) throws Exception {
        security.tokenKeyAccess("permitAll()")
                .checkTokenAccess("isAuthenticated()");
    }

    @Override
    public void configure(ClientDetailsServiceConfigurer clients) throws Exception {
        clients
                .inMemory()
                .withClient("ClientId")
                .secret("secret")
                .authorizedGrantTypes("client_credentials", "password")
                .scopes("user_info")
                .autoApprove(true);
    }

    @Override
    public void configure(AuthorizationServerEndpointsConfigurer endpoints) throws Exception {
        endpoints.authenticationManager(authenticationManager);
    }

}

Resource Server

@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true, proxyTargetClass = true)
@EnableResourceServer
@Configuration    
public class ResourceServerConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private AuthenticationManager authenticationManager;

    @Autowired
    private UserDetailsService customUserDetailsService;   

    @Override
    protected void configure(HttpSecurity http) throws Exception {

        http.csrf().disable();
        http
        .authorizeRequests()
           .antMatchers("/static","/rest/register").permitAll()
           .antMatchers("/rest/hello").hasRole("ADMIN");

    }

    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
             auth.parentAuthenticationManager(authenticationManager)
                .userDetailsService(customUserDetailsService);
    }

}

When I run this I get the below error:


APPLICATION FAILED TO START


Description:

The dependencies of some of the beans in the application context form a cycle:

authorizationServerConfig (field private org.springframework.security.authentication.AuthenticationManager com.volunteermanagement.springsecurityauthorizationserver.config.AuthorizationSer

verConfig.authenticationManager)

┌─────┐ | authenticationManager defined in class path resource [org/springframework/boot/autoconfigure/security/AuthenticationManagerConfiguration.class] ↑ ↓ | resourceServerConfig (field private org.springframework.security.authentication.AuthenticationManager com.volunteermanagement.springsecurityauthorizationserver.config.ResourceServerConfig.authenticationManager) └─────┘

I need to use both the OAuth 2.0 annotation (@EnableResourceServer) and Spring Security annotation (@EnableWebSecurity and @EnableGlobalMethodSecurity). But when I am using both these annotations together I get the above error. How do I resolve this error? I am stuck. Kindly help in resolving the issue.

I resolved the cyclic dependency by adding the below code to my ResourceServerConfig class

 @Bean
    @Override
    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();
    }

But now it seems that role based authorization is not working as I am getting Forbidden error for the REST endpoint.

My REST endpoint:

@PreAuthorize("hasRole('ADMIN')")
    @GetMapping("/rest/hello")
    public String hello() {
        return "Hello World";
    }

My Resource Config code snippet:

http.csrf().disable();
        http
        .authorizeRequests()
           .antMatchers("**/rest/hello").hasRole("ADMIN")
           .antMatchers("/static","/rest/register").permitAll();

why role based authorization not working???

0 Answers
Related