spring-projects / spring-projects/spring-security

Allow usage of reactive WebClient for NimbusJwtDecoder to retrieve JwkSet

Open
#11,052 8 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: oauth2 type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Expected Behavior

Should it be possible to use reactive WebClient to create non-reactive JwtDecoder?

NimbusJwtDecoder.withJwkSetUri(properties.getJwt().getJwkSetUri())
        .webClient(WebClient.builder().build())
        .cache(jwkSetCache)
        .build()

Current Behavior

It is only possible to use RestTemplate as http client option:

NimbusJwtDecoder.withJwkSetUri(properties.getJwt().getJwkSetUri())
        .restOperations(new RestTemplate())
        .cache(jwkSetCache)
        .build()

Context

A lot of non-reactive applications use reactive WebClient in a non-reactive manner, not having RestOperations bean created for the application, so I think it might have sense to allow usage of WebClient instead.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the NimbusJwtDecoder.withJwkSetUri builder and compare the existing restOperations path with the requested WebClient option. Check how the non-reactive JwtDecoder retrieves and caches the JWK set, then verify that WebClient can be used successfully without a RestOperations bean and that existing behavior remains intact.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.