spring oauth2: resource server without authorization server

Viewed 136

I need some lights about convenience of using an autheorizarion server in my project scope.

We're realising and deploying our services into customer environment.

  1. Customer infrastructure already provides an authentication mechanism in order to authenticate users.
  2. This mechanism intercepts all comunications and redirects user to a "login" form.
  3. After that, user is redirected to our service and we've to handle and digest it and respond with an JWT token.

Here is where I'm feeling lost:

I'm thinking about:

  1. using spring-oauth2 in order to request a JWT token to an authorization server, or
  2. using spring-oauth2 in order to auto-generate an JWT token and validate it. I don't know if it's possible.

My question is, since user is already authenticated, have it sense to use an oauth2 authorization server, using client-credentials in order to authentication client against our resource services?

Short question would be, could I use spring-oauth2 librearies in order to generate a JWT without an authorization server?

1 Answers

You technically can do it, but I would discourage you from doing that. Access tokens in a system should be issued centrally, by a dedicated service. Otherwise, it will be hard to maintain the infrastructure. If your services will start to issue JWTs, then they will also have to provide the public keys for others to validate these JWTs. Keys management, access token contents management, and any rules of mapping user information into claims - will now become part of your service and it will unnecessarily complicate its implementation.

If the customer's authentication mechanism issues a JWT, why not use that one for request authorization? If that one is insufficient, I would recommend having an Authorization Server (or a dedicated service), that can perform Token Exchange and exchange the original JWT for a new one.

Related