Describe the bug
In Spring Security 7.0 and earlier, both SpringOpaqueTokenIntrospector and SpringReactiveOpaqueTokenIntrospector could not be created without a client ID and secret. In 7.1, this has changed and the introspector is now created but it won't use basic auth:
|
if (this.clientId != null && this.clientSecret != null) { |
|
restTemplate.getInterceptors() |
|
.add(new BasicAuthenticationInterceptor(this.clientId, this.clientSecret)); |
|
} |
|
if (this.clientId != null && this.clientSecret != null) { |
|
String clientId = this.clientId; |
|
String clientSecret = this.clientSecret; |
|
builder.defaultHeaders((h) -> h.setBasicAuth(clientId, clientSecret)); |
|
} |
To Reproduce
SpringReactiveOpaqueTokenIntrospector
.withIntrospectionUri(opaquetoken.getIntrospectionUri())
.build();
Expected behavior
Creation fails as client ID and secret are required.
Describe the bug
In Spring Security 7.0 and earlier, both
SpringOpaqueTokenIntrospectorandSpringReactiveOpaqueTokenIntrospectorcould not be created without a client ID and secret. In 7.1, this has changed and the introspector is now created but it won't use basic auth:spring-security/oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/introspection/SpringOpaqueTokenIntrospector.java
Lines 384 to 387 in aaaa9b9
spring-security/oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/introspection/SpringReactiveOpaqueTokenIntrospector.java
Lines 338 to 342 in aaaa9b9
To Reproduce
Expected behavior
Creation fails as client ID and secret are required.