Add Spring Authorization Server project: OAuth2/OIDC provider, client and resource server
Three modules on Spring Boot 4.1.1 with Spring Authorization Server 7.1.1: the provider
itself, a relying party, and an API that trusts its tokens. Client registration, PKCE,
a custom consent page and token customisation, with profiles that make each failure
reproducible.
Every claim is backed by captured output in docs/output/as-*.txt, regenerated by
authorization-server/scripts/run-all.sh. Notable findings, verified against the jars:
- OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(HttpSecurity) was deleted
in 7.0, and both configuration classes moved into spring-security-config
- ClientSettings.requireProofKey flipped from false to true, on the authorization server
(1.5.8 -> 7.1.1) and on the OAuth2 client (6.5.1 -> 7.1.1)
- requireProofKey(false) does not make PKCE optional for a public client; the code
verifier is that client's only authentication at the token endpoint
- MediaTypeRequestMatcher(TEXT_HTML) matches Accept: */*, so the token endpoint answers
API callers with 302 -> /login unless setIgnoredMediaTypes(ALL) is called
Also renames the repository to spring-auth-demo and cross-links the new chapter set from
the existing documentation.
This commit is contained in:
81
docs/authorization-server/01-versions.md
Normal file
81
docs/authorization-server/01-versions.md
Normal file
@@ -0,0 +1,81 @@
|
||||
[← index](README.md) · next: [02 — The minimum working provider](02-minimum-provider.md)
|
||||
|
||||
# Versions, artifacts and the 7.0 move
|
||||
|
||||
## There is no Spring Authorization Server version to pin
|
||||
|
||||
The brief for this project was “pin the SAS version from the Boot 4.1 BOM”. There
|
||||
is nothing to pin. `spring-boot-dependencies:4.1.1` has no
|
||||
`<spring-authorization-server.version>` property, because Spring Authorization Server is no
|
||||
longer a separate project.
|
||||
|
||||
```
|
||||
$ grep -oP '<spring-security\.version>[^<]+' spring-boot-dependencies-4.1.1.pom
|
||||
<spring-security.version>7.1.1
|
||||
|
||||
$ curl -s .../spring-security-bom/7.1.1/spring-security-bom-7.1.1.pom | grep -A1 authorization-server
|
||||
<artifactId>spring-security-oauth2-authorization-server</artifactId>
|
||||
<version>7.1.1</version>
|
||||
```
|
||||
|
||||
The Maven coordinates are unchanged —
|
||||
`org.springframework.security:spring-security-oauth2-authorization-server` — and the
|
||||
version now tracks Spring Security. Spring Boot 4.1.1 therefore gives you **7.1.1**.
|
||||
|
||||
## The version numbers skipped
|
||||
|
||||
The published version list on Maven Central tells the story on its own:
|
||||
|
||||
```
|
||||
… 1.5.6 1.5.7 1.5.8 2.0.0-M1 2.0.0-M2 7.0.0-M3 7.0.0-RC1 … 7.0.0 7.0.1 … 7.1.1 7.2.0-M1
|
||||
```
|
||||
|
||||
`2.0.0` was started and abandoned. There is **no 2.x GA**, and anything that tells you to
|
||||
upgrade to Spring Authorization Server 2 is describing a milestone that was renumbered.
|
||||
The line jumps from 1.5.8 to 7.0.0 to align with Spring Security 7.0.
|
||||
|
||||
[Joe Grandja's announcement](https://spring.io/blog/2025/09/11/spring-authorization-server-moving-to-spring-security-7-0/)
|
||||
(11 September 2025) says the migration impact is “quite minimal” with “a
|
||||
couple of minor package relocation changes”. That is true in the sense that the
|
||||
relocations are mechanical. It is optimistic in the sense that one of them is the class
|
||||
every tutorial calls — see [02](02-minimum-provider.md).
|
||||
|
||||
## Which starter
|
||||
|
||||
Boot 4.1 publishes both of these, and they resolve the same four dependencies:
|
||||
|
||||
| artifact | status |
|
||||
|---|---|
|
||||
| `spring-boot-starter-oauth2-authorization-server` | deprecated |
|
||||
| `spring-boot-starter-security-oauth2-authorization-server` | current |
|
||||
|
||||
That is not inference. It is in the deprecated starter's own published POM:
|
||||
|
||||
```xml
|
||||
<description>Starter for using Spring Authorization Server features (deprecated in favor
|
||||
of spring-boot-starter-security-oauth2-authorization-server)</description>
|
||||
```
|
||||
|
||||
The same rename happened to the client and resource-server starters
|
||||
(`spring-boot-starter-security-oauth2-client`,
|
||||
`spring-boot-starter-security-oauth2-resource-server`), and there is a new
|
||||
`spring-boot-starter-security-oauth2-authorization-server-test`. Boot 4 also renamed
|
||||
`spring-boot-starter-web` to `spring-boot-starter-webmvc`; the authorization server starter
|
||||
pulls the latter in transitively, so you do not need to declare a web starter at all.
|
||||
|
||||
## Exact versions this project was built and run against
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| JDK | Temurin 25.0.4.1+1 (current LTS) |
|
||||
| Spring Boot | 4.1.1 |
|
||||
| Spring Framework | 7.0.9 |
|
||||
| Spring Security / Authorization Server | 7.1.1 |
|
||||
| Maven | 3.9.11 |
|
||||
|
||||
## Related
|
||||
|
||||
- [Spring Security 7.1 JWT Authentication: The Complete Guide](https://ankurm.com/spring-security-7-1-jwt-authentication-guide/) and [`docs/11-spring-security-7-changes.md`](../11-spring-security-7-changes.md) — the rest of what moved in Spring Security 7
|
||||
- [`docs/output/as-settings-defaults.txt`](../output/as-settings-defaults.txt) — defaults read out of the 1.5.8 and 7.1.1 jars side by side
|
||||
|
||||
Next: [02 — The minimum working provider](02-minimum-provider.md)
|
||||
Reference in New Issue
Block a user