Three modules on Spring Boot 4.1.1 with Spring Authorization Server 7.1.1: the provider
itself, a relying party, and an API that trusts its tokens. Client registration, PKCE,
a custom consent page and token customisation, with profiles that make each failure
reproducible.
Every claim is backed by captured output in docs/output/as-*.txt, regenerated by
authorization-server/scripts/run-all.sh. Notable findings, verified against the jars:
- OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(HttpSecurity) was deleted
in 7.0, and both configuration classes moved into spring-security-config
- ClientSettings.requireProofKey flipped from false to true, on the authorization server
(1.5.8 -> 7.1.1) and on the OAuth2 client (6.5.1 -> 7.1.1)
- requireProofKey(false) does not make PKCE optional for a public client; the code
verifier is that client's only authentication at the token endpoint
- MediaTypeRequestMatcher(TEXT_HTML) matches Accept: */*, so the token endpoint answers
API callers with 302 -> /login unless setIgnoredMediaTypes(ALL) is called
Also renames the repository to spring-auth-demo and cross-links the new chapter set from
the existing documentation.
82 lines
3.6 KiB
Markdown
82 lines
3.6 KiB
Markdown
[← index](README.md) · next: [02 — The minimum working provider](02-minimum-provider.md)
|
|
|
|
# Versions, artifacts and the 7.0 move
|
|
|
|
## There is no Spring Authorization Server version to pin
|
|
|
|
The brief for this project was “pin the SAS version from the Boot 4.1 BOM”. There
|
|
is nothing to pin. `spring-boot-dependencies:4.1.1` has no
|
|
`<spring-authorization-server.version>` property, because Spring Authorization Server is no
|
|
longer a separate project.
|
|
|
|
```
|
|
$ grep -oP '<spring-security\.version>[^<]+' spring-boot-dependencies-4.1.1.pom
|
|
<spring-security.version>7.1.1
|
|
|
|
$ curl -s .../spring-security-bom/7.1.1/spring-security-bom-7.1.1.pom | grep -A1 authorization-server
|
|
<artifactId>spring-security-oauth2-authorization-server</artifactId>
|
|
<version>7.1.1</version>
|
|
```
|
|
|
|
The Maven coordinates are unchanged —
|
|
`org.springframework.security:spring-security-oauth2-authorization-server` — and the
|
|
version now tracks Spring Security. Spring Boot 4.1.1 therefore gives you **7.1.1**.
|
|
|
|
## The version numbers skipped
|
|
|
|
The published version list on Maven Central tells the story on its own:
|
|
|
|
```
|
|
… 1.5.6 1.5.7 1.5.8 2.0.0-M1 2.0.0-M2 7.0.0-M3 7.0.0-RC1 … 7.0.0 7.0.1 … 7.1.1 7.2.0-M1
|
|
```
|
|
|
|
`2.0.0` was started and abandoned. There is **no 2.x GA**, and anything that tells you to
|
|
upgrade to Spring Authorization Server 2 is describing a milestone that was renumbered.
|
|
The line jumps from 1.5.8 to 7.0.0 to align with Spring Security 7.0.
|
|
|
|
[Joe Grandja's announcement](https://spring.io/blog/2025/09/11/spring-authorization-server-moving-to-spring-security-7-0/)
|
|
(11 September 2025) says the migration impact is “quite minimal” with “a
|
|
couple of minor package relocation changes”. That is true in the sense that the
|
|
relocations are mechanical. It is optimistic in the sense that one of them is the class
|
|
every tutorial calls — see [02](02-minimum-provider.md).
|
|
|
|
## Which starter
|
|
|
|
Boot 4.1 publishes both of these, and they resolve the same four dependencies:
|
|
|
|
| artifact | status |
|
|
|---|---|
|
|
| `spring-boot-starter-oauth2-authorization-server` | deprecated |
|
|
| `spring-boot-starter-security-oauth2-authorization-server` | current |
|
|
|
|
That is not inference. It is in the deprecated starter's own published POM:
|
|
|
|
```xml
|
|
<description>Starter for using Spring Authorization Server features (deprecated in favor
|
|
of spring-boot-starter-security-oauth2-authorization-server)</description>
|
|
```
|
|
|
|
The same rename happened to the client and resource-server starters
|
|
(`spring-boot-starter-security-oauth2-client`,
|
|
`spring-boot-starter-security-oauth2-resource-server`), and there is a new
|
|
`spring-boot-starter-security-oauth2-authorization-server-test`. Boot 4 also renamed
|
|
`spring-boot-starter-web` to `spring-boot-starter-webmvc`; the authorization server starter
|
|
pulls the latter in transitively, so you do not need to declare a web starter at all.
|
|
|
|
## Exact versions this project was built and run against
|
|
|
|
| | |
|
|
|---|---|
|
|
| JDK | Temurin 25.0.4.1+1 (current LTS) |
|
|
| Spring Boot | 4.1.1 |
|
|
| Spring Framework | 7.0.9 |
|
|
| Spring Security / Authorization Server | 7.1.1 |
|
|
| Maven | 3.9.11 |
|
|
|
|
## Related
|
|
|
|
- [Spring Security 7.1 JWT Authentication: The Complete Guide](https://ankurm.com/spring-security-7-1-jwt-authentication-guide/) and [`docs/11-spring-security-7-changes.md`](../11-spring-security-7-changes.md) — the rest of what moved in Spring Security 7
|
|
- [`docs/output/as-settings-defaults.txt`](../output/as-settings-defaults.txt) — defaults read out of the 1.5.8 and 7.1.1 jars side by side
|
|
|
|
Next: [02 — The minimum working provider](02-minimum-provider.md)
|