Class CommonInternalServiceConnectionAutoConfiguration

java.lang.Object
com.broadleafcommerce.common.extension.webclient.autoconfigure.CommonInternalServiceConnectionAutoConfiguration

@AutoConfiguration @ConditionalOnWebApplication(type=SERVLET) @ConditionalOnClass({org.springframework.web.reactive.function.client.WebClient.class,org.springframework.http.client.reactive.ClientHttpConnector.class,org.springframework.security.oauth2.client.registration.ClientRegistrationRepository.class,org.springframework.security.oauth2.client.web.reactive.function.client.ServletOAuth2AuthorizedClientExchangeFilterFunction.class,org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider.class}) @EnableConfigurationProperties({CommonInternalServiceSSLVerificationProperties.class,CommonInternalServiceConnectionPoolProperties.class}) @AutoConfigureOrder(-2147473648) public class CommonInternalServiceConnectionAutoConfiguration extends Object

Prior to this configuration, a variety of Broadleaf microservices and common libraries defined their own separate oAuth2FilterFunctionSupplier bean for 'internal' service-to-service communication (ex: services within the same deployment cluster). This resulted in duplicated classes for the functionality within CommonInternalServiceSynchronizedOAuth2AuthorizedClientManager, CommonInternalServiceSSLVerificationProperties, and CommonOAuth2ClientCredentialsAccessTokenResponseClient.

As of MicroExtensionCommon 2.0.8, this new configuration class aims to centralize this logic by superseding the classes/beans defined in the individual services with one that is easily overridden when needed.

Since:
MicroExtensionCommon 2.0.8
  • Constructor Details

    • CommonInternalServiceConnectionAutoConfiguration

      public CommonInternalServiceConnectionAutoConfiguration()
  • Method Details

    • oAuth2FilterFunctionSupplier

      @Bean(name="oAuth2FilterFunctionSupplier") @ConditionalOnMissingBean(name="oAuth2FilterFunctionSupplier") @ConditionalOnOAuth2ClientRegistrationProperties public Supplier<org.springframework.security.oauth2.client.web.reactive.function.client.ServletOAuth2AuthorizedClientExchangeFilterFunction> oAuth2FilterFunctionSupplier(@Qualifier("commonInternalServiceAuthorizedClientManager") org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager manager)
    • commonInternalServiceAuthorizedClientManager

      @Bean(name="commonInternalServiceAuthorizedClientManager") @ConditionalOnMissingBean(name="commonInternalServiceAuthorizedClientManager") @ConditionalOnOAuth2ClientRegistrationProperties public org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager commonInternalServiceAuthorizedClientManager(org.springframework.security.oauth2.client.registration.ClientRegistrationRepository clientRegistrations, @Qualifier("commonIntlSvcClientCredsAuthClientProvider") org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider clientCredentialsAuthorizedClientProvider)
      The shared authorized-client manager for internal service-to-service calls. Exposed as a bean (rather than instantiated privately inside the filter supplier) so that both the stock ServletOAuth2AuthorizedClientExchangeFilterFunction and the context-free CommonInternalServiceClientCredentialsExchangeFilterFunction share a single instance, and therefore a single access-token cache.
    • commonInternalServiceClientCredentialsExchangeFilterFunction

      @Bean(name="commonInternalServiceClientCredentialsExchangeFilterFunction") @ConditionalOnMissingBean(name="commonInternalServiceClientCredentialsExchangeFilterFunction") @ConditionalOnOAuth2ClientRegistrationProperties public CommonInternalServiceClientCredentialsExchangeFilterFunction commonInternalServiceClientCredentialsExchangeFilterFunction(@Qualifier("commonInternalServiceAuthorizedClientManager") org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager manager)
      A context-free ExchangeFilterFunction that resolves and attaches the client_credentials token without requiring an ambient request/security context. WebClient builders should register this filter ahead of oAuth2FilterFunctionSupplier.get().oauth2Configuration() so that service-to-service calls made off the request thread (background workers, @Async, scheduled tasks, messaging listeners) are authorized correctly. Call sites are unaffected — they keep using .attributes(clientRegistrationId(...)).
    • commonIntlSvcClientCredsAuthClientProvider

      @Bean(name="commonIntlSvcClientCredsAuthClientProvider") @ConditionalOnMissingBean(name="commonIntlSvcClientCredsAuthClientProvider") public org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider commonIntlSvcClientCredsAuthClientProvider(@Qualifier("commonIntlSvcClientConnector") org.springframework.beans.factory.ObjectProvider<org.springframework.http.client.reactive.ClientHttpConnector> clientConnectorProvider)
    • commonIntlSvcConnectionProvider

      @Bean(name="commonIntlSvcConnectionProvider", destroyMethod="dispose") @ConditionalOnMissingBean(name="commonIntlSvcConnectionProvider") @ConditionalOnProperty(name="broadleaf.common.webclient.connection-pool.enabled", havingValue="true", matchIfMissing=true) public reactor.netty.resources.ConnectionProvider commonIntlSvcConnectionProvider(CommonInternalServiceConnectionPoolProperties properties)

      The dedicated, named Reactor Netty connection pool backing internal service-to-service communication.

      Reactor Netty only publishes connection pool metrics for pools that are explicitly built with metrics enabled, and it tags those meters with the pool's name. The global HttpResources pool used by a bare HttpClient.create() is neither, which is why outbound connection saturation has been invisible up to this point. Declaring the pool here - rather than in each service's own connector bean - means every consumer of commonIntlSvcClientConnector is measured through one pool, under one name.

      Parameters:
      properties - the connection pool configuration
      Returns:
      the shared connection pool for internal service-to-service communication
      Since:
      MicroExtensionCommon 3.0.0
    • commonIntlSvcClientConnectorFactory

      @Bean(name="commonIntlSvcClientConnectorFactory") @ConditionalOnMissingBean(name="commonIntlSvcClientConnectorFactory") public CommonInternalServiceClientConnectorFactory commonIntlSvcClientConnectorFactory(CommonInternalServiceSSLVerificationProperties sslVerificationProperties, @Qualifier("commonIntlSvcConnectionProvider") org.springframework.beans.factory.ObjectProvider<reactor.netty.resources.ConnectionProvider> connectionProviderProvider)

      The factory services should use to build their own ClientHttpConnector beans on top of the shared connection pool.

      Services deliberately keep individually-named connector beans so that each remains overridable, which means they cannot simply consume commonIntlSvcClientConnector. Exposing the construction logic as a factory lets those beans stay where they are while still sharing - and therefore reporting on - one pool.

      Parameters:
      sslVerificationProperties - the internal SSL verification configuration
      connectionProviderProvider - the dedicated connection pool, if one is enabled
      Returns:
      the factory for internal service-to-service connectors
      Since:
      MicroExtensionCommon 3.0.0
    • commonIntlSvcClientConnector

      @Bean(name="commonIntlSvcClientConnector") @ConditionalOnMissingBean(name="commonIntlSvcClientConnector") public org.springframework.http.client.reactive.ClientHttpConnector commonIntlSvcClientConnector(@Qualifier("commonIntlSvcClientConnectorFactory") CommonInternalServiceClientConnectorFactory connectorFactory)

      The ClientHttpConnector used by internal service-to-service WebClients.

      As of MicroExtensionCommon 3.0.0 this is built on top of commonIntlSvcConnectionProvider so that internal traffic is pooled - and therefore measurable - separately from any third-party integration traffic. When the dedicated pool is disabled, the previous behavior is preserved exactly: an SSL-disabled connector on Reactor Netty's global pool when SSL verification is off, and no connector at all otherwise.

      Parameters:
      connectorFactory - the factory for internal service-to-service connectors
      Returns:
      the connector for internal service-to-service communication, or null if there is nothing to contribute over the WebClient builder's own default