Class CommonInternalServiceConnectionAutoConfiguration
Prior to this configuration, a variety of Broadleaf microservices and common libraries defined
their own separate oAuth2FilterFunctionSupplier bean for 'internal' service-to-service
communication (ex: services within the same deployment cluster). This resulted in duplicated
classes for the functionality within
CommonInternalServiceSynchronizedOAuth2AuthorizedClientManager,
CommonInternalServiceSSLVerificationProperties, and
CommonOAuth2ClientCredentialsAccessTokenResponseClient.
As of MicroExtensionCommon 2.0.8, this new configuration class aims to centralize this logic by superseding the classes/beans defined in the individual services with one that is easily overridden when needed.
- Since:
- MicroExtensionCommon 2.0.8
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionorg.springframework.security.oauth2.client.OAuth2AuthorizedClientManagercommonInternalServiceAuthorizedClientManager(org.springframework.security.oauth2.client.registration.ClientRegistrationRepository clientRegistrations, org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider clientCredentialsAuthorizedClientProvider) The shared authorized-client manager for internal service-to-service calls.commonInternalServiceClientCredentialsExchangeFilterFunction(org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager manager) A context-freeExchangeFilterFunctionthat resolves and attaches theclient_credentialstoken without requiring an ambient request/security context.org.springframework.http.client.reactive.ClientHttpConnectorcommonIntlSvcClientConnector(CommonInternalServiceClientConnectorFactory connectorFactory) TheClientHttpConnectorused by internal service-to-serviceWebClients.commonIntlSvcClientConnectorFactory(CommonInternalServiceSSLVerificationProperties sslVerificationProperties, org.springframework.beans.factory.ObjectProvider<reactor.netty.resources.ConnectionProvider> connectionProviderProvider) The factory services should use to build their ownClientHttpConnectorbeans on top of the shared connection pool.org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvidercommonIntlSvcClientCredsAuthClientProvider(org.springframework.beans.factory.ObjectProvider<org.springframework.http.client.reactive.ClientHttpConnector> clientConnectorProvider) reactor.netty.resources.ConnectionProviderThe dedicated, named Reactor Netty connection pool backing internal service-to-service communication.Supplier<org.springframework.security.oauth2.client.web.reactive.function.client.ServletOAuth2AuthorizedClientExchangeFilterFunction>oAuth2FilterFunctionSupplier(org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager manager)
-
Constructor Details
-
CommonInternalServiceConnectionAutoConfiguration
public CommonInternalServiceConnectionAutoConfiguration()
-
-
Method Details
-
oAuth2FilterFunctionSupplier
@Bean(name="oAuth2FilterFunctionSupplier") @ConditionalOnMissingBean(name="oAuth2FilterFunctionSupplier") @ConditionalOnOAuth2ClientRegistrationProperties public Supplier<org.springframework.security.oauth2.client.web.reactive.function.client.ServletOAuth2AuthorizedClientExchangeFilterFunction> oAuth2FilterFunctionSupplier(@Qualifier("commonInternalServiceAuthorizedClientManager") org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager manager) -
commonInternalServiceAuthorizedClientManager
@Bean(name="commonInternalServiceAuthorizedClientManager") @ConditionalOnMissingBean(name="commonInternalServiceAuthorizedClientManager") @ConditionalOnOAuth2ClientRegistrationProperties public org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager commonInternalServiceAuthorizedClientManager(org.springframework.security.oauth2.client.registration.ClientRegistrationRepository clientRegistrations, @Qualifier("commonIntlSvcClientCredsAuthClientProvider") org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider clientCredentialsAuthorizedClientProvider) The shared authorized-client manager for internal service-to-service calls. Exposed as a bean (rather than instantiated privately inside the filter supplier) so that both the stockServletOAuth2AuthorizedClientExchangeFilterFunctionand the context-freeCommonInternalServiceClientCredentialsExchangeFilterFunctionshare a single instance, and therefore a single access-token cache. -
commonInternalServiceClientCredentialsExchangeFilterFunction
@Bean(name="commonInternalServiceClientCredentialsExchangeFilterFunction") @ConditionalOnMissingBean(name="commonInternalServiceClientCredentialsExchangeFilterFunction") @ConditionalOnOAuth2ClientRegistrationProperties public CommonInternalServiceClientCredentialsExchangeFilterFunction commonInternalServiceClientCredentialsExchangeFilterFunction(@Qualifier("commonInternalServiceAuthorizedClientManager") org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager manager) A context-freeExchangeFilterFunctionthat resolves and attaches theclient_credentialstoken without requiring an ambient request/security context. WebClient builders should register this filter ahead ofoAuth2FilterFunctionSupplier.get().oauth2Configuration()so that service-to-service calls made off the request thread (background workers,@Async, scheduled tasks, messaging listeners) are authorized correctly. Call sites are unaffected — they keep using.attributes(clientRegistrationId(...)). -
commonIntlSvcClientCredsAuthClientProvider
@Bean(name="commonIntlSvcClientCredsAuthClientProvider") @ConditionalOnMissingBean(name="commonIntlSvcClientCredsAuthClientProvider") public org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider commonIntlSvcClientCredsAuthClientProvider(@Qualifier("commonIntlSvcClientConnector") org.springframework.beans.factory.ObjectProvider<org.springframework.http.client.reactive.ClientHttpConnector> clientConnectorProvider) -
commonIntlSvcConnectionProvider
@Bean(name="commonIntlSvcConnectionProvider", destroyMethod="dispose") @ConditionalOnMissingBean(name="commonIntlSvcConnectionProvider") @ConditionalOnProperty(name="broadleaf.common.webclient.connection-pool.enabled", havingValue="true", matchIfMissing=true) public reactor.netty.resources.ConnectionProvider commonIntlSvcConnectionProvider(CommonInternalServiceConnectionPoolProperties properties) The dedicated, named Reactor Netty connection pool backing internal service-to-service communication.
Reactor Netty only publishes connection pool metrics for pools that are explicitly built with metrics enabled, and it tags those meters with the pool's name. The global
HttpResourcespool used by a bareHttpClient.create()is neither, which is why outbound connection saturation has been invisible up to this point. Declaring the pool here - rather than in each service's own connector bean - means every consumer ofcommonIntlSvcClientConnectoris measured through one pool, under one name.- Parameters:
properties- the connection pool configuration- Returns:
- the shared connection pool for internal service-to-service communication
- Since:
- MicroExtensionCommon 3.0.0
-
commonIntlSvcClientConnectorFactory
@Bean(name="commonIntlSvcClientConnectorFactory") @ConditionalOnMissingBean(name="commonIntlSvcClientConnectorFactory") public CommonInternalServiceClientConnectorFactory commonIntlSvcClientConnectorFactory(CommonInternalServiceSSLVerificationProperties sslVerificationProperties, @Qualifier("commonIntlSvcConnectionProvider") org.springframework.beans.factory.ObjectProvider<reactor.netty.resources.ConnectionProvider> connectionProviderProvider) The factory services should use to build their own
ClientHttpConnectorbeans on top of the shared connection pool.Services deliberately keep individually-named connector beans so that each remains overridable, which means they cannot simply consume
commonIntlSvcClientConnector. Exposing the construction logic as a factory lets those beans stay where they are while still sharing - and therefore reporting on - one pool.- Parameters:
sslVerificationProperties- the internal SSL verification configurationconnectionProviderProvider- the dedicated connection pool, if one is enabled- Returns:
- the factory for internal service-to-service connectors
- Since:
- MicroExtensionCommon 3.0.0
-
commonIntlSvcClientConnector
@Bean(name="commonIntlSvcClientConnector") @ConditionalOnMissingBean(name="commonIntlSvcClientConnector") public org.springframework.http.client.reactive.ClientHttpConnector commonIntlSvcClientConnector(@Qualifier("commonIntlSvcClientConnectorFactory") CommonInternalServiceClientConnectorFactory connectorFactory) The
ClientHttpConnectorused by internal service-to-serviceWebClients.As of MicroExtensionCommon 3.0.0 this is built on top of
commonIntlSvcConnectionProviderso that internal traffic is pooled - and therefore measurable - separately from any third-party integration traffic. When the dedicated pool is disabled, the previous behavior is preserved exactly: an SSL-disabled connector on Reactor Netty's global pool when SSL verification is off, and no connector at all otherwise.- Parameters:
connectorFactory- the factory for internal service-to-service connectors- Returns:
- the connector for internal service-to-service communication, or
nullif there is nothing to contribute over theWebClientbuilder's own default
-