Spring : login without spring security and sending token to other applications

Viewed 767

I am using Spring Boot to build a simple microservices web app. I decided to create several services for my front-end and several REST services for the backend.

Let's say I have 2 front-end using Thymeleaf : login and products-list. I also have 2 REST services, users and product. login sends requests to users to manage connection, and products-list sends requests to products to manage CRUD operations on products. Some operations can only be performed if the user is connected and authentified.

Problem is : I don't know how to tell to my products-list service that my user is connected. And since login and products-list are two separate applications, I haven't found a way to send data from login to products-list without exposing them (like token, etc.).

I know that Spring Security exists but I'd to like to find another way, and I'm even sure it handles this case with redirection.

TLDR : how to pass token safely with redirection in Spring ?

Thanks

1 Answers

What you are looking for is JWT authentication.

This is the principal flow

JWT token based authentication flow:

  1. Get the JWT based token from the authentication endpoint, eg /login.

  2. Extract token from the authentication result.

  3. Set the HTTP header as Authorization and value as Bearer jwt_token.

  4. Then send a request to access the protected resources.

  5. If the requested resource is protected, Spring Security will use a custom Filter to validate the JWT token, and build an Authentication object and set it in Spring Security specific SecurityContextHolder to complete the authentication progress.

  6. If the JWT token is valid it will return the requested resource to client.

You can find a detailed description, which comes with a working GitHub example here. You can just reuse the necessary classes in your application.

Related