spring-projects / spring-projects/spring-security

provide an interceptor in Spring Security (messaging?) that installs an `Authentication` object in a Message header given a JWT header

Open
#19,709 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status: waiting-for-triage type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Id love to just have this class provided out of the box since it makes using Spring Security with Spring's Messaging support (which in turn underpins projects like Spring Integration and Spring Cloud Stream and Spring Cloud Data Flow) much easier in a production-like OAuth environment

I've solved this problem by writing the same boilerplate every single time. It seems to me it belongs in the framework

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file or test is identified in the issue. Start by locating Spring Security's integration with Spring Messaging and reviewing how Spring Integration and Spring Cloud Stream represent message headers and JWT authentication. Done means a documented, reusable interceptor can install an Authentication object from a JWT header in the supported messaging flow.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
backend, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.