I am using OAuth2 with Spring Security to secure my APIs. Below is my code:
Authorization Server
@Configuration
@EnableAuthorizationServer
public class AuthorizationServerConfig extends AuthorizationServerConfigurerAdapter {
@Autowired
private AuthenticationManager authenticationManager;
@Override
public void configure(AuthorizationServerSecurityConfigurer security) throws Exception {
security.tokenKeyAccess("permitAll()")
.checkTokenAccess("isAuthenticated()");
}
@Override
public void configure(ClientDetailsServiceConfigurer clients) throws Exception {
clients
.inMemory()
.withClient("ClientId")
.secret("secret")
.authorizedGrantTypes("client_credentials", "password")
.scopes("user_info")
.autoApprove(true);
}
@Override
public void configure(AuthorizationServerEndpointsConfigurer endpoints) throws Exception {
endpoints.authenticationManager(authenticationManager);
}
}
Resource Server
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true, proxyTargetClass = true)
@EnableResourceServer
@Configuration
public class ResourceServerConfig extends WebSecurityConfigurerAdapter {
@Autowired
private AuthenticationManager authenticationManager;
@Autowired
private UserDetailsService customUserDetailsService;
@Override
protected void configure(HttpSecurity http) throws Exception {
http.csrf().disable();
http
.authorizeRequests()
.antMatchers("/static","/rest/register").permitAll()
.antMatchers("/rest/hello").hasRole("ADMIN");
}
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
auth.parentAuthenticationManager(authenticationManager)
.userDetailsService(customUserDetailsService);
}
}
When I run this I get the below error:
APPLICATION FAILED TO START
Description:
The dependencies of some of the beans in the application context form a cycle:
authorizationServerConfig (field private org.springframework.security.authentication.AuthenticationManager com.volunteermanagement.springsecurityauthorizationserver.config.AuthorizationSer
verConfig.authenticationManager)
┌─────┐ | authenticationManager defined in class path resource [org/springframework/boot/autoconfigure/security/AuthenticationManagerConfiguration.class] ↑ ↓ | resourceServerConfig (field private org.springframework.security.authentication.AuthenticationManager com.volunteermanagement.springsecurityauthorizationserver.config.ResourceServerConfig.authenticationManager) └─────┘
I need to use both the OAuth 2.0 annotation (@EnableResourceServer) and Spring Security annotation (@EnableWebSecurity and @EnableGlobalMethodSecurity). But when I am using both these annotations together I get the above error. How do I resolve this error? I am stuck. Kindly help in resolving the issue.
I resolved the cyclic dependency by adding the below code to my ResourceServerConfig class
@Bean
@Override
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
But now it seems that role based authorization is not working as I am getting Forbidden error for the REST endpoint.
My REST endpoint:
@PreAuthorize("hasRole('ADMIN')")
@GetMapping("/rest/hello")
public String hello() {
return "Hello World";
}
My Resource Config code snippet:
http.csrf().disable();
http
.authorizeRequests()
.antMatchers("**/rest/hello").hasRole("ADMIN")
.antMatchers("/static","/rest/register").permitAll();
why role based authorization not working???