Skip to content

Opaque token introspectors should not allow empty credentials #19201

Description

@wilkinsona

Describe the bug

In Spring Security 7.0 and earlier, both SpringOpaqueTokenIntrospector and SpringReactiveOpaqueTokenIntrospector could not be created without a client ID and secret. In 7.1, this has changed and the introspector is now created but it won't use basic auth:

if (this.clientId != null && this.clientSecret != null) {
restTemplate.getInterceptors()
.add(new BasicAuthenticationInterceptor(this.clientId, this.clientSecret));
}

if (this.clientId != null && this.clientSecret != null) {
String clientId = this.clientId;
String clientSecret = this.clientSecret;
builder.defaultHeaders((h) -> h.setBasicAuth(clientId, clientSecret));
}

To Reproduce

SpringReactiveOpaqueTokenIntrospector
    .withIntrospectionUri(opaquetoken.getIntrospectionUri())
    .build();

Expected behavior

Creation fails as client ID and secret are required.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

in: oauth2An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)type: bugA general bug

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions