In Java Spring Boot I can not redirect from SSO to the originally requested URL after login
My company has an SSO authentication server set up and I can successfully redirect URLs for authentication, however, I can't seem to route the request back to the original URL (or save the original URLs location prior to the .oauth2Login() call.
For example, if I have a URL like:
/api/s/v1/some-resource-name/some-path-variable?some-request-variable=some-value
Based on the map, this should (and is) directed to SSO (.oauth2Login()), but I need to somehow redirect back to the URL after the user has validly authenticated.
Below is how I have set up my environment.
Registered/provisioned an SSO OIDC Connection Client (returns me a client id, secret, and endpoints)
Setup a basic Configuration Using Spring Boot's
application.propertiesfile and the registered OIDC client information
spring.security.oauth2.client.registration.w3id.client-name=wfm-data-managment
spring.security.oauth2.client.registration.w3id.client-id=******************
spring.security.oauth2.client.registration.w3id.client-secret=****************
spring.security.oauth2.client.registration.w3id.redirect-uri={baseUrl}
spring.security.oauth2.client.registration.w3id.scope=openid
spring.security.oauth2.client.provider.w3id.issuer-uri=https://preprod.login.w3.ibm.com/oidc/endpoint/default
- Set up the OAuth2 configuration to map any
/api/s/v1path through authentication and set up asuccessHandler()in an attempt to redirect the client to the originally requested URL after successfully authenticating.
@Configuration
@EnableWebSecurity
public class OAuth2SecurityConfig extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.antMatcher("/**").authorizeRequests()
.antMatchers("/api/s/v1/**").authenticated()
.anyRequest().permitAll()
.and()
.oauth2Login()
.successHandler(new RedirectAuthenticationSuccessHandler())
;
}
}
- Define the class that is passed the the
successHandler(). Note thatonAuthenticationSuccess()never gets called.
@Component
public class RedirectAuthenticationSuccessHandler extends SimpleUrlAuthenticationSuccessHandler implements AuthenticationSuccessHandler {
private RedirectStrategy redirectStrategy = new DefaultRedirectStrategy();
@Autowired
public RedirectAuthenticationSuccessHandler() {
setUseReferer(true); // use referer
}
@Override
public void onAuthenticationSuccess(HttpServletRequest request, HttpServletResponse response, Authentication authentication)
throws IOException, ServletException {
handle(request, response, authentication);
clearAuthenticationAttributes(request);
}
@Override
protected String determineTargetUrl(HttpServletRequest request, HttpServletResponse response) {
return (String) request.getParameter("redirect");
}
}