Spring Boot integration test: Initialize security context

Viewed 28

I have a microservice exposing a REST-API which is secured with OAuth2 using the default Spring Boot configuration in application.yml:

security:
  oauth2:
    client:
      client-id: ...
      client-secret: ...
      grant-type: ...
    resource:
      user-info-uri: ...
      token-info-uri: ...
      prefer-token-info: false

The API methods have the usual annotations. The user is authorized in a frontend, which sends authorized requests to the API by sending the token in the header (Authorization: Bearer ...).

The user details can then be read in the backend by injecting the Principal as an argument in the mapped controller methods, e.g.:

@CrossOrigin
@RestController
@RequestMapping("/foo")
@ContextConfiguration
public class MyController {

    @GetMapping("/all")
    public ResponseEntity<List<String>> sampleMethod(Principal user) { // <<- Principal SHOULD NOT BE NULL FOR INTEGRATION TEST
        // some code here
    }
}

This works well when running the real microservice. However when running integration tests with MockMVC the principal is always null:

@ExtendWith(SpringExtension.class)
@SpringBootTest
@AutoConfigureMockMvc
@DirtiesContext
class MyControllerIT {

    @Autowired
    private MockMvc mockMvc;

    @Test
    void shouldReturnOk() throws Exception {
        mockMvc.perform(MockMvcRequestBuilders.get("/all"))
                .andExpect(status().isOk();
    }

}

What is an easy way to set up the @SpringBootTest integration test so the security context is pre-populated with some Principal under my control?

2 Answers
Related