-
Notifications
You must be signed in to change notification settings - Fork 4k
Token exchange support #957
Conversation
…security-oauth into token-exchange
|
@puug Please sign the Contributor License Agreement! Click here to manually synchronize the status of this Pull Request. See the FAQ for frequently asked questions. |
|
@puug Thank you for signing the Contributor License Agreement! |
This reverts commit f66a165.
There is one for ConsumerTokenServices and one for AuthorizationServerTokenServices. Fixes spring-atticgh-984
Add tests Add javadoc Fix bug to work with UAA 3.11.0 Issue spring-atticgh-977
|
Hi @puug. I apologize for the delay in getting to review this PR. As an FYI, we are limiting new features and only accepting bug fixes and minor enhancements as this project is in maintenance mode. Our efforts are focused on the new OAuth support we are building into Spring Security core project. We just released 5.0.0.M1 which provides support for the client-side and we hope to get to the server-side support soon. We appreciate your efforts here but I'm going to close this PR as it does contain new classes and interfaces ( Please keep an eye out on the new OAuth support we are building into Spring Security 5.0.0 and we hope you can contribute there. |
Basic implementation of token-exchange for the authorization server which address some of the points raised in #585
There's a couple of points worth discussing in this PR
AuthorizationProviderTokenExchangeServicewhich allows for all sorts of token support. I could supply a basic implementation which takes a username as thesubject_tokenand looks up against aUserDetailsService, but it would only be for test & evaluation purposes.