Support multiple JWT issuers with different token resolvers in Spring Security

Viewed 712

I have built a spring security oauth2 resource server multi tenant solution following the documentation here:

https://docs.spring.io/spring-security/site/docs/current/reference/html5/#oauth2resourceserver-multitenancy

and here:

https://docs.spring.io/spring-security/site/docs/current/reference/html5/#oauth2resourceserver-bearertoken-resolver

This works fine, with the caveat that both issuers use the same bearer token resolver. In my case one issuer specifies the token on the Authorization header, and the other issuer sends the token in a custom header.

How do I configure spring security to specify a different BearerTokenResolver for each issuer?

My current code is below, which only works if both issuers provide the token in the X-JWT-ASSERTION header.

@Bean
BearerTokenResolver getTokenResolver()
{
    return new HeaderBearerTokenResolver("X-JWT-ASSERTION");
}
@Configuration
public class JWTSecurityConfig extends WebSecurityConfigurerAdapter {

    @Value("${oauth2.issuer-uris}")
    private String[] issuerUris;

    @Override
    protected void configure(HttpSecurity http) throws Exception {

        var authenticationManagerResolver = new JwtIssuerAuthenticationManagerResolver(issuerUris);

        http
        .authorizeRequests(authz -> authz
                .antMatchers("/api/**").authenticated()
                .anyRequest().permitAll())
        .oauth2ResourceServer(oauth2 -> oauth2.authenticationManagerResolver(authenticationManagerResolver));

    }

}
0 Answers
Related