|
27 | 27 | import org.springframework.context.ApplicationContext; |
28 | 28 | import org.springframework.core.ResolvableType; |
29 | 29 | import org.springframework.http.HttpStatus; |
| 30 | +import org.springframework.security.config.Customizer; |
30 | 31 | import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
31 | 32 | import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer; |
32 | 33 | import org.springframework.security.oauth2.core.OAuth2Token; |
33 | 34 | import org.springframework.security.oauth2.jwt.NimbusJwtEncoder; |
34 | 35 | import org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationServerMetadata; |
| 36 | +import org.springframework.security.oauth2.server.authorization.config.annotation.web.configurers.OAuth2AuthorizationServerConfigurer; |
35 | 37 | import org.springframework.security.oauth2.server.authorization.config.annotation.web.configurers.OAuth2ClientRegistrationEndpointConfigurer; |
36 | 38 | import org.springframework.security.oauth2.server.authorization.context.AuthorizationServerContext; |
37 | 39 | import org.springframework.security.oauth2.server.authorization.context.AuthorizationServerContextHolder; |
|
42 | 44 | import org.springframework.security.oauth2.server.authorization.token.ResourceIdentifierAudienceTokenCustomizer; |
43 | 45 | import org.springframework.security.web.authentication.HttpStatusEntryPoint; |
44 | 46 | import org.springframework.security.web.servlet.util.matcher.PathPatternRequestMatcher; |
| 47 | +import org.springframework.util.Assert; |
45 | 48 | import org.springframework.util.StringUtils; |
46 | 49 | import org.springframework.web.util.UriComponentsBuilder; |
47 | 50 | import static org.springframework.security.config.Customizer.withDefaults; |
48 | | -import static org.springframework.security.oauth2.server.authorization.config.annotation.web.configurers.OAuth2AuthorizationServerConfigurer.authorizationServer; |
49 | 51 |
|
50 | 52 | /** |
51 | 53 | * @author Daniel Garnier-Moiroux |
52 | 54 | */ |
53 | 55 | public class McpAuthorizationServerConfigurer |
54 | 56 | extends AbstractHttpConfigurer<McpAuthorizationServerConfigurer, HttpSecurity> { |
55 | 57 |
|
| 58 | + private Customizer<OAuth2AuthorizationServerConfigurer> authServerCustomizer = Customizer.withDefaults(); |
| 59 | + |
56 | 60 | public static McpAuthorizationServerConfigurer mcpAuthorizationServer() { |
57 | 61 | return new McpAuthorizationServerConfigurer(); |
58 | 62 | } |
59 | 63 |
|
| 64 | + /** |
| 65 | + * Customize the underlying Spring Security OAuth2 Authorization Server configuration, |
| 66 | + * through a {@link OAuth2AuthorizationServerConfigurer}. |
| 67 | + * @param oauth2AuthorizationServerConfigurerCustomizer a customizer of OAuth2 |
| 68 | + * Authorization Server. Defaults to a no-op {@link Customizer#withDefaults()}. |
| 69 | + * @return The {@link McpAuthorizationServerConfigurer} for further configuration. |
| 70 | + */ |
| 71 | + public McpAuthorizationServerConfigurer authorizationServer( |
| 72 | + Customizer<OAuth2AuthorizationServerConfigurer> oauth2AuthorizationServerConfigurerCustomizer) { |
| 73 | + Assert.notNull(oauth2AuthorizationServerConfigurerCustomizer, |
| 74 | + "oauth2AuthorizationServerConfigurerCustomizer cannot be null"); |
| 75 | + this.authServerCustomizer = oauth2AuthorizationServerConfigurerCustomizer; |
| 76 | + return this; |
| 77 | + } |
| 78 | + |
60 | 79 | @Override |
61 | 80 | public void init(HttpSecurity http) throws Exception { |
62 | | - http.with(authorizationServer(), authServer -> { |
| 81 | + http.with(OAuth2AuthorizationServerConfigurer.authorizationServer(), authServer -> { |
63 | 82 | authServer.authorizationServerMetadataEndpoint( |
64 | 83 | authorizationServerMetadataEndpoint -> authorizationServerMetadataEndpoint |
65 | 84 | .authorizationServerMetadataCustomizer(authorizationServerMetadataCustomizer())); |
66 | 85 | OAuth2TokenGenerator<?> tokenGenerator = getTokenGenerator(http); |
67 | 86 | authServer.tokenGenerator(tokenGenerator); |
| 87 | + this.authServerCustomizer.customize(authServer); |
68 | 88 | }); |
69 | 89 | http.with(new OAuth2ClientRegistrationEndpointConfigurer(), withDefaults()); |
70 | 90 | http.csrf(csrf -> csrf.ignoringRequestMatchers( |
|
0 commit comments