Class CommonInternalServiceSynchronizedOAuth2AuthorizedClientManager

java.lang.Object
com.broadleafcommerce.common.extension.webclient.oauth2.client.CommonInternalServiceSynchronizedOAuth2AuthorizedClientManager
All Implemented Interfaces:
org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager

public class CommonInternalServiceSynchronizedOAuth2AuthorizedClientManager extends Object implements org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager

This component implements OAuth2AuthorizedClientManager and internally instantiates and delegates to AuthorizedClientServiceOAuth2AuthorizedClientManager.

The only differences between this and AuthorizedClientServiceOAuth2AuthorizedClientManager are:

  • This attempts to serialize on the OAuth2AuthorizeRequest.getClientRegistrationId(). The reason is that these clients are normally shared clients, with shared access tokens. As a result, only one thread needs to call the auth server when the token is unavailable or otherwise expired. The token is then stored in InMemoryOAuth2AuthorizedClientService for re-use across threads.
  • This force-sets a static value for OAuth2AuthorizeRequest.getPrincipal(), for the reasons outlined in cloneWithModifiedPrincipal(OAuth2AuthorizeRequest)

This helps prevent a race condition where multiple threads are trying to fetch the same token at the same time via a network call.

Since:
MicroExtensionCommon 2.0.8
  • Constructor Details

    • CommonInternalServiceSynchronizedOAuth2AuthorizedClientManager

      public CommonInternalServiceSynchronizedOAuth2AuthorizedClientManager(org.springframework.security.oauth2.client.registration.ClientRegistrationRepository clientRegistrationRepository)
  • Method Details

    • authorize

      public org.springframework.security.oauth2.client.OAuth2AuthorizedClient authorize(org.springframework.security.oauth2.client.OAuth2AuthorizeRequest authorizeRequest)
      Specified by:
      authorize in interface org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager
    • cloneWithModifiedPrincipal

      protected org.springframework.security.oauth2.client.OAuth2AuthorizeRequest cloneWithModifiedPrincipal(org.springframework.security.oauth2.client.OAuth2AuthorizeRequest authorizeRequest)
      InMemoryOAuth2AuthorizedClientService loads/stores access tokens but includes the principal name as part of the storage key. Since this flow is invoked only for service-to-service backend calls and is not directly related to the end-user (ex: customer) that may have triggered this flow, we don't want to needlessly request separate access tokens for each unique end-user. This reduces the number of token requests and promotes token reuse.
      Parameters:
      authorizeRequest - the original authorize request
      Returns:
      a clone of the original, with a pre-determined fixed system principal
    • setAuthorizedClientProvider

      public void setAuthorizedClientProvider(org.springframework.security.oauth2.client.OAuth2AuthorizedClientProvider authorizedClientProvider)
      See Also:
      • AuthorizedClientServiceOAuth2AuthorizedClientManager.setAuthorizedClientProvider(OAuth2AuthorizedClientProvider)
    • setContextAttributesMapper

      public void setContextAttributesMapper(Function<org.springframework.security.oauth2.client.OAuth2AuthorizeRequest,Map<String,Object>> contextAttributesMapper)
      See Also:
      • AuthorizedClientServiceOAuth2AuthorizedClientManager.setContextAttributesMapper(Function)
    • setAuthorizationSuccessHandler

      public void setAuthorizationSuccessHandler(org.springframework.security.oauth2.client.OAuth2AuthorizationSuccessHandler authorizationSuccessHandler)
      See Also:
      • AuthorizedClientServiceOAuth2AuthorizedClientManager.setAuthorizationSuccessHandler(OAuth2AuthorizationSuccessHandler)
    • setAuthorizationFailureHandler

      public void setAuthorizationFailureHandler(org.springframework.security.oauth2.client.OAuth2AuthorizationFailureHandler authorizationFailureHandler)
      See Also:
      • AuthorizedClientServiceOAuth2AuthorizedClientManager.setAuthorizationFailureHandler(OAuth2AuthorizationFailureHandler)