I've a simple question regarding the object. I made a @Controller to manage some REST APIs which read and write to a db which looks like this:
@RestController
@RequestMapping("/api")
public class PersonController {
@Autowired
PersonService personService;
@RequestMapping(value="/write/persons", method=RequestMethod.POST)
public Person createPerson(@RequestBody Person person) {
return personService.createPerson(person);
}
@RequestMapping(value="/read/persons", method=RequestMethod.GET)
public List<Person> getPersons() {
return personService.getPersons();
}
@RequestMapping(value="/write/persons/{id}", method=RequestMethod.PUT)
public Person updatePerson(@PathVariable(value = "id") Long id, @RequestBody Person personDetails) {
return personService.updatePerson(id, personDetails);
}
@RequestMapping(value="/write/persons/{id}", method=RequestMethod.DELETE)
public void deletePerson(@PathVariable(value = "id") Long id) {
personService.deletePerson(id);
}
@RequestMapping(value="/read/personsbyname", method=RequestMethod.GET)
public List<Person> findByFirstName(@RequestParam(value = "fstname", defaultValue = "Test") String firstName) {
return personService.findAllByFirstName(firstName);
}
}
Then I also made a web security configurer which looks like this:
@Configuration
public class JWTSecurityConfig extends WebSecurityConfigurerAdapter {
//@Override
protected void configure(HttpSecurity http) throws Exception {
http
.authorizeRequests()
.antMatchers("/api/write/**").hasAuthority("SCOPE_write")
.antMatchers("/api/read/**").hasAuthority("SCOPE_read")
.anyRequest().permitAll()
.and().oauth2ResourceServer().jwt();
}
}
Also in keycloack which is running on localhost:8080 I defined a user and 2 clients with, obviously, a read scope and a write scope. I'm using Postman to test this out and everything seem to work fine: if I try to call a "write API" without retrieving the access token with the write scope before calling it, Postman returns 403 Forbidden and I'm ok with it. The question is then: how keycloack (or another auth server) and spring work together? Using Postman to retrieve the access token I've to insert Client-ID, Auth URL and Token URL which I can retrieve only if I access to OIDC specs (after logging into keycloak as admin). After that it asks me to log as a keycloak user but why it happens? Keycloak just wants to know that the client Postman is emulating has a "connected" Resource Owner? I don't know if I specifed the question properly, let me know if something is not clear.