spring-projects / spring-projects/spring-security
Add Bearer Token Test Support
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Related to https://github.com/spring-projects/spring-security/issues/6634
Testing authentication flows that include a JWT is straight-forward:
this.mvc.perform(get("/")
.with(jwt(jwt -> jwt.subject("subject"))));
It'd be nice to have Resource Server support that doesn't care about the format"
this.mvc.perform(get("/")
.with(bearer(b -> b.subject("subject"))));
While the first produces a JwtAuthenticationToken and Jwt principal, the second would produce a BearerTokenAuthentication and a OAuth2AuthenticatedPrincipal principal.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the existing jwt(jwt -> ...) MVC test-support entry point and the Resource Server behavior described in the issue. Trace how the JWT form produces JwtAuthenticationToken and Jwt, then define the corresponding bearer form for BearerTokenAuthentication and OAuth2AuthenticatedPrincipal. Done means authentication-flow tests can use bearer(...) without depending on JWT format.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security, testing
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100