I have a Spring Boot project that uses a custom OpenID Connect server for authentication. I use org.springframework.boot:spring-boot-starter-oauth2-client to handle the authentication for me.
In application.properties I added the following keys:
spring.security.oauth2.client.registration.reg-id.client-id=app-client-id
spring.security.oauth2.client.registration.reg-id.client-secret=app-secret
spring.security.oauth2.client.registration.reg-id.scope=openid
spring.security.oauth2.client.provider.reg-id.issuer-uri=http://idp-url
In my WebSecurityConfigurerAdapter the configuration is quite simple as well:
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
class SecurityConfig: WebSecurityConfigurerAdapter() {
override fun configure(http: HttpSecurity) {
// @formatter:off
http
.authorizeRequests()
.antMatchers("/error").permitAll()
.anyRequest().authenticated()
.and()
.oauth2Login()
// @formatter:on
}
}
Authentication works fine, but we also have a lot of @SpringBootTest integration tests that are isolated from any running service on the outside. I would like to keep it this way, so that a ./mvnw integration-test is doable without any services needed to run.
The problem is that the oauth2 starter requests the openid configuration at context startup, which is obviously not there when testing. It tries to query http://idp-url/.well-known/openid-configuration, fails and then the context breaks down because my SecurityConfig couldn't be created.
I tried disabling the security auto configuration using the usual
@EnableAutoConfiguration(exclude = { SecurityAutoConfiguration.class, ManagementSecurityAutoConfiguration.class })
annotation. This doesn't stop the starter from accessing the uri though.
Is there any other way around this? Like putting the openid-configuration inside my own application and pointing the uri to myself or something like that? Or disabling this access altogether?