Spring Security OIDC and JWT instead of session

Viewed 222

We are considering going stateless, i.e. using JWTs instead of sessions. But it seems to be tricky with OIDC and Spring Security. Some blog posts, e.g. Spring Lemon[1], suggest subclassing several of Spring's OIDC classes and make use of filters for issuing signed JWTs after the user has been authenticated, but they are based on older versions before .oauth2ResourceServer() became available as a configurable class in security config.

Today our users are being authenticated by using OIDC, but we also provide an API, and thus we have API users as well. At the time of writing, we are rewriting the application to become more RESTful. More logic will be placed in frontend, and backend will only provide several APIs. To simplify the model even further, our idea is to use JWTs instead of session, for both API and OIDC users.

What is the best approach? Still use sessions for the end users (and only use JWTs for API users) or try to build a stateless application using JWTs for all users instead? Is Spring Lemon the right way to go? Should we also use oauth2ResourceServer in our config class for validating the JWTs?

[1] Spring Lemon: https://dzone.com/articles/spring-security-5-oauth-20-login-and-signup-in-stas

0 Answers
Related