Can not redirect to my original URL after OAuth2 SSO authentication using Java Spring Boot and Spring Security

Viewed 226

In Java Spring Boot I can not redirect from SSO to the originally requested URL after login

My company has an SSO authentication server set up and I can successfully redirect URLs for authentication, however, I can't seem to route the request back to the original URL (or save the original URLs location prior to the .oauth2Login() call.

For example, if I have a URL like:

/api/s/v1/some-resource-name/some-path-variable?some-request-variable=some-value

Based on the map, this should (and is) directed to SSO (.oauth2Login()), but I need to somehow redirect back to the URL after the user has validly authenticated.

Below is how I have set up my environment.

  1. Registered/provisioned an SSO OIDC Connection Client (returns me a client id, secret, and endpoints)

  2. Setup a basic Configuration Using Spring Boot's application.properties file and the registered OIDC client information

spring.security.oauth2.client.registration.w3id.client-name=wfm-data-managment
spring.security.oauth2.client.registration.w3id.client-id=******************
spring.security.oauth2.client.registration.w3id.client-secret=****************
spring.security.oauth2.client.registration.w3id.redirect-uri={baseUrl}
spring.security.oauth2.client.registration.w3id.scope=openid
spring.security.oauth2.client.provider.w3id.issuer-uri=https://preprod.login.w3.ibm.com/oidc/endpoint/default
  1. Set up the OAuth2 configuration to map any /api/s/v1 path through authentication and set up a successHandler()in an attempt to redirect the client to the originally requested URL after successfully authenticating.
@Configuration
@EnableWebSecurity
public class OAuth2SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.antMatcher("/**").authorizeRequests()
            .antMatchers("/api/s/v1/**").authenticated()
                .anyRequest().permitAll()
                    .and()
                    .oauth2Login()
                    .successHandler(new RedirectAuthenticationSuccessHandler())
                    ;
    }
}
  1. Define the class that is passed the the successHandler(). Note that onAuthenticationSuccess() never gets called.
@Component
public class RedirectAuthenticationSuccessHandler extends SimpleUrlAuthenticationSuccessHandler implements AuthenticationSuccessHandler {
    
    private RedirectStrategy redirectStrategy = new DefaultRedirectStrategy();
    
    @Autowired
    public RedirectAuthenticationSuccessHandler() {
        setUseReferer(true); // use referer
    }
    
    @Override
    public void onAuthenticationSuccess(HttpServletRequest request, HttpServletResponse response, Authentication authentication)
        throws IOException, ServletException {
        handle(request, response, authentication);
        clearAuthenticationAttributes(request);
    }


    @Override
    protected String determineTargetUrl(HttpServletRequest request, HttpServletResponse response) {
        return (String) request.getParameter("redirect");
    }
}
0 Answers
Related