I'm considering a microservice architecture and I'm struggle with authorization and authentication. I found a lot of resources about oauth2 and openid connect that claim they solve the issue but it is not clear enough for me.
Let's consider we have a following architecture:
In my system I want to add a feature only for a certain group of users defined by role. I want to also know the name of the user, their email and id.
After my research I find the following solution to be a good start:
- SPA application displays
login form. - User fills in the form and sends
POSTrequest toauthN&authZ server. - The server replies with
access token(being aJWT) that containsname,email,idandroleof the user. The response contains arefresh tokenas well. - SPA application stores the token and attaches it to every request it makes.
Microservice 1andMicroservice 2check if the token is valid. If so, they check if the role is correct. If so, they take user info and process the request.
How far away from the good solution I am? The login flow looks like Implicit flow with form post described here but with implicit consents and I'm not sure if it's fine.
Moving forward, I find passing user data in JWT (such as name, email) to be not a good solution as it exposes sensitive data. I found resources that say it is recommended to expose only a reference to a user in token (such as ID) and replace such token with a classic access_token in reverser-proxy/api gateway when sending a request to a microservice. Considering such solution I think that following scenario is a good start:
- SPA application displays
login form. - User fills in the form and sends
POSTrequest toauthN&authZ server. - The server replies with
access tokenandrefresh token. API gateway (in middle) replacesaccess tokenwithID tokenand stores claims from access token within its cache. - SPA application stores the token and attaches it to every request it makes.
- Handling a request,
API GatewaytakesID Tokenand based on the user ID generates a newaccess token. The access token is send to microservice 1 or microservice 2 that validate it as previous.
How do you find such solutions? Is this a secure approach? What should I improve proposed flow?
Thanks in advance!
