access ResourceInfo in Quarkus / Vertx HttpAuthenticationMechanism

Viewed 61

In Quarkus (resteasy reactive), is there a way to get hold of the "ResourceInfo" in an HTTP Authentication Mechanism? What I'm trying to do is read an annotation that is defined on the resource class or method, in order to choose an authentication mechanism based on it.

Injecting the ResourceInfo directly in the mechanism class does not work (and also, it is application scoped and not request scoped, so not sure it could work). I also couldn't find the info I need in the RoutingContext parameter. I have also tried adding a ContainerRequestFilter, in which injecting the ResourceInfo with @Context works well, but I think perhaps the filters are called after the httpAuthenticationMechanism.authenticate(), because it's not called in my test when the endpoint requires authentication.

Is there another way to do this?

----> To clarify with code what I would like to do:

have different JAX-RS resources with a custom @Authorization annotations with different "api names" like this:

@Path("/jwttest")
@ApplicationScoped
@Authorization("jwttest")
public class JWTTestController {
...
}

@Path("/oidctest")
@ApplicationScoped
@Authorization("myoidc")
public class OIDCTestController {
...
}

and then different configs like this:

myframework.auth.jwttest.type=jwt
myframework.auth.jwttest.issuer=123
myframework.auth.jwttest.audience=456

myframework.auth.myoidc.type=oidc
myframework.auth.myoidc.auth-server-url=myurl

And in the HttpAuthenticationMechanism, find the value of @Authorization, and based on it, call another provider like suggested in https://quarkus.io/guides/security-customization#dealing-with-more-than-one-httpauthenticationmechanism with the right api name so that it can load the config.

0 Answers
Related