Skip to content

Commit

Permalink
switches web authentication principal resolver to use reactive context
Browse files Browse the repository at this point in the history
gh #6598

Signed-off-by: David Herberth <[email protected]>
  • Loading branch information
Dav1dde authored and eleftherias committed Dec 12, 2019
1 parent 8e53c3f commit 64e063d
Show file tree
Hide file tree
Showing 2 changed files with 24 additions and 34 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,9 @@
import org.springframework.expression.ExpressionParser;
import org.springframework.expression.spel.standard.SpelExpressionParser;
import org.springframework.expression.spel.support.StandardEvaluationContext;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.annotation.AuthenticationPrincipal;
import org.springframework.security.core.context.ReactiveSecurityContextHolder;
import org.springframework.security.core.context.SecurityContext;
import org.springframework.util.StringUtils;
import org.springframework.web.reactive.BindingContext;
import org.springframework.web.reactive.result.method.HandlerMethodArgumentResolverSupport;
Expand Down Expand Up @@ -69,9 +70,9 @@ public boolean supportsParameter(MethodParameter parameter) {
public Mono<Object> resolveArgument(MethodParameter parameter, BindingContext bindingContext,
ServerWebExchange exchange) {
ReactiveAdapter adapter = getAdapterRegistry().getAdapter(parameter.getParameterType());
return exchange.getPrincipal()
.ofType(Authentication.class)
.flatMap( a -> {
return ReactiveSecurityContextHolder.getContext()
.map(SecurityContext::getAuthentication)
.flatMap(a -> {
Object p = resolvePrincipal(parameter, a.getPrincipal());
Mono<Object> principal = Mono.justOrEmpty(p);
return adapter == null ? principal : Mono.just(adapter.fromPublisher(principal));
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@
import org.springframework.expression.BeanResolver;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.annotation.AuthenticationPrincipal;
import org.springframework.security.core.context.ReactiveSecurityContextHolder;
import org.springframework.security.web.method.ResolvableMethod;
import org.springframework.web.reactive.BindingContext;
import org.springframework.web.server.ServerWebExchange;
Expand Down Expand Up @@ -82,28 +83,16 @@ public void supportsParameterCurrentUser() {
public void resolveArgumentWhenIsAuthenticationThenObtainsPrincipal() {
MethodParameter parameter = this.authenticationPrincipal.arg(String.class);
when(authentication.getPrincipal()).thenReturn("user");
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.block()).isEqualTo(authentication.getPrincipal());
}

@Test
public void resolveArgumentWhenIsNotAuthenticationThenMonoEmpty() {
MethodParameter parameter = this.authenticationPrincipal.arg(String.class);
when(exchange.getPrincipal()).thenReturn(Mono.just(() -> ""));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);

assertThat(argument).isNotNull();
assertThat(argument.block()).isNull();
}

@Test
public void resolveArgumentWhenIsEmptyThenMonoEmpty() {
MethodParameter parameter = this.authenticationPrincipal.arg(String.class);
when(exchange.getPrincipal()).thenReturn(Mono.empty());

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);

Expand All @@ -115,9 +104,9 @@ public void resolveArgumentWhenIsEmptyThenMonoEmpty() {
public void resolveArgumentWhenMonoIsAuthenticationThenObtainsPrincipal() {
MethodParameter parameter = this.authenticationPrincipal.arg(Mono.class, String.class);
when(authentication.getPrincipal()).thenReturn("user");
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.cast(Mono.class).block().block()).isEqualTo(authentication.getPrincipal());
}
Expand All @@ -126,9 +115,9 @@ public void resolveArgumentWhenMonoIsAuthenticationThenObtainsPrincipal() {
public void resolveArgumentWhenMonoIsAuthenticationAndNoGenericThenObtainsPrincipal() {
MethodParameter parameter = ResolvableMethod.on(getClass()).named("authenticationPrincipalNoGeneric").build().arg(Mono.class);
when(authentication.getPrincipal()).thenReturn("user");
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.cast(Mono.class).block().block()).isEqualTo(authentication.getPrincipal());
}
Expand All @@ -138,9 +127,9 @@ public void resolveArgumentWhenSpelThenObtainsPrincipal() {
MyUser user = new MyUser(3L);
MethodParameter parameter = this.spel.arg(Long.class);
when(authentication.getPrincipal()).thenReturn(user);
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.block()).isEqualTo(user.getId());
}
Expand All @@ -150,10 +139,10 @@ public void resolveArgumentWhenBeanThenObtainsPrincipal() throws Exception {
MyUser user = new MyUser(3L);
MethodParameter parameter = this.bean.arg(Long.class);
when(authentication.getPrincipal()).thenReturn(user);
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));
when(this.beanResolver.resolve(any(), eq("beanName"))).thenReturn(new Bean());

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.block()).isEqualTo(user.getId());
}
Expand All @@ -162,9 +151,9 @@ public void resolveArgumentWhenBeanThenObtainsPrincipal() throws Exception {
public void resolveArgumentWhenMetaThenObtainsPrincipal() {
MethodParameter parameter = this.meta.arg(String.class);
when(authentication.getPrincipal()).thenReturn("user");
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.block()).isEqualTo("user");
}
Expand All @@ -173,9 +162,9 @@ public void resolveArgumentWhenMetaThenObtainsPrincipal() {
public void resolveArgumentWhenErrorOnInvalidTypeImplicit() {
MethodParameter parameter = ResolvableMethod.on(getClass()).named("errorOnInvalidTypeWhenImplicit").build().arg(Integer.class);
when(authentication.getPrincipal()).thenReturn("user");
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.block()).isNull();
}
Expand All @@ -184,9 +173,9 @@ public void resolveArgumentWhenErrorOnInvalidTypeImplicit() {
public void resolveArgumentWhenErrorOnInvalidTypeExplicitFalse() {
MethodParameter parameter = ResolvableMethod.on(getClass()).named("errorOnInvalidTypeWhenExplicitFalse").build().arg(Integer.class);
when(authentication.getPrincipal()).thenReturn("user");
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThat(argument.block()).isNull();
}
Expand All @@ -195,9 +184,9 @@ public void resolveArgumentWhenErrorOnInvalidTypeExplicitFalse() {
public void resolveArgumentWhenErrorOnInvalidTypeExplicitTrue() {
MethodParameter parameter = ResolvableMethod.on(getClass()).named("errorOnInvalidTypeWhenExplicitTrue").build().arg(Integer.class);
when(authentication.getPrincipal()).thenReturn("user");
when(exchange.getPrincipal()).thenReturn(Mono.just(authentication));

Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange);
Mono<Object> argument = resolver.resolveArgument(parameter, bindingContext, exchange)
.subscriberContext(ReactiveSecurityContextHolder.withAuthentication(authentication));

assertThatThrownBy(() -> argument.block()).isInstanceOf(ClassCastException.class);
}
Expand Down

0 comments on commit 64e063d

Please sign in to comment.