-
Notifications
You must be signed in to change notification settings - Fork 5.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Change default authority for oauth2Login() #11887
Closed
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
sjohnr
added
status: duplicate
A duplicate of another issue
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
labels
Sep 21, 2022
sjohnr
force-pushed
the
gh-7856-oidc-user-authority
branch
2 times, most recently
from
September 21, 2022 16:27
21555d9
to
6df7a92
Compare
Previously, the default authority was ROLE_USER when using oauth2Login() for both OAuth2 and OIDC providers. * Default authority for OAuth2UserAuthority is now OAUTH2_USER * Default authority for OidcUserAuthority is now OIDC_USER Documentation has been updated to include this implementation detail. Closes spring-projectsgh-7856
sjohnr
force-pushed
the
gh-7856-oidc-user-authority
branch
from
September 21, 2022 20:11
6df7a92
to
bcc3e95
Compare
jgrandja
requested changes
Sep 23, 2022
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the PR @sjohnr.
There are 2 minor updates needed and then please go ahead and merge.
Thanks!
...core/src/main/java/org/springframework/security/oauth2/core/oidc/user/OidcUserAuthority.java
Show resolved
Hide resolved
...h2-core/src/main/java/org/springframework/security/oauth2/core/user/OAuth2UserAuthority.java
Show resolved
Hide resolved
Merged via 181ee74. |
sjohnr
added a commit
to sjohnr/spring-security
that referenced
this pull request
Nov 10, 2022
sjohnr
added a commit
that referenced
this pull request
Nov 14, 2022
sjohnr
added a commit
that referenced
this pull request
Nov 14, 2022
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: duplicate
A duplicate of another issue
type: breaks-passivity
A change that breaks passivity with the previous release
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Previously, the default authority was
ROLE_USER
when usingoauth2Login()
for both OAuth2 and OIDC providers.OAuth2UserAuthority
is nowOAUTH2_USER
OidcUserAuthority
is nowOIDC_USER
Documentation has been updated to include this implementation detail.
Closes gh-7856