Spring Security Apple Sign in

Viewed 705

So I am trying to use Apple Sign in with REST API within my Spring Boot backend application, everything is working fine! Until I try to access the user name, even though I ask for name in scope, apple seems not to send back the name, and the documentation says clearly that they don't provide a user info uri, however AppleJS seems to return a user object in the response payload

And yes, I have implemented a custom OIDC UserDetails Service.

    public class CompactOAuth2UserService implements OAuth2UserService<OidcUserRequest, OidcUser>

.

  security:
oauth2:
  client:
    registration:
      apple:
        clientId: id
        clientSecret: secret
        authorizationGrantType: authorization_code
        redirectUri: "{baseUrl}/oauth2/callback/{registrationId}"
        scope:
          - openid
          - name
          - email
        clientName: Apple
        clientAuthenticationMethod: post
    provider:
      apple:
        authorizationUri: https://appleid.apple.com/auth/authorize?response_mode=form_post&response_type=code+id_token
        tokenUri: https://appleid.apple.com/auth/token
        jwkSetUri: https://appleid.apple.com/auth/keys
        userNameAttribute: sub

How can I get the user name? If it is not possible what is the best practice for this?

1 Answers

It looks like the name scope needs to be included in a query param to the /auth/authorize endpoint. Then it will be included in the response as a user object like you mentioned. NOTE: seems, though, it will be split first and last name.

From: https://developer.apple.com/forums/thread/118209

To request user information in the id_token (assuming you are requesting via the /auth/authorize REST API), you'll need to include the scope query parameter, which supports the values—name and email. You can request one, both, or none.

Note: Use space separation and percent-encoding for multiple scopes; for example, "scope=name%20email".

Then, https://developer.apple.com/documentation/sign_in_with_apple/sign_in_with_apple_js/incorporating_sign_in_with_apple_into_other_platforms

Handle the Response

When the Sign in with Apple UI appears in the opened browser tab, the user can sign in and accept any terms and conditions for your app. After Apple processes the authorization request, the handling of the response depends on the value in response_mode:

...

A successful response contains the following parameters:

... user

  • A JSON string containing the data requested in the scope property. The returned data is in the following format: { "name": { "firstName": string, "lastName": string }, "email": string }
Related