Skip to content

Commit aa026f8

Browse files
committed
Nimbus JWK Set Builders Take SignatureAlgorithm
Fixes gh-7270
1 parent 10a9207 commit aa026f8

File tree

4 files changed

+30
-31
lines changed

4 files changed

+30
-31
lines changed

oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/oidc/authentication/OidcIdTokenDecoderFactory.java

+11-11
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,16 @@
1515
*/
1616
package org.springframework.security.oauth2.client.oidc.authentication;
1717

18+
import java.net.URL;
19+
import java.nio.charset.StandardCharsets;
20+
import java.time.Instant;
21+
import java.util.Collection;
22+
import java.util.HashMap;
23+
import java.util.Map;
24+
import java.util.concurrent.ConcurrentHashMap;
25+
import java.util.function.Function;
26+
import javax.crypto.spec.SecretKeySpec;
27+
1828
import org.springframework.core.convert.TypeDescriptor;
1929
import org.springframework.core.convert.converter.Converter;
2030
import org.springframework.security.oauth2.client.registration.ClientRegistration;
@@ -37,16 +47,6 @@
3747
import org.springframework.util.Assert;
3848
import org.springframework.util.StringUtils;
3949

40-
import javax.crypto.spec.SecretKeySpec;
41-
import java.net.URL;
42-
import java.nio.charset.StandardCharsets;
43-
import java.time.Instant;
44-
import java.util.Collection;
45-
import java.util.HashMap;
46-
import java.util.Map;
47-
import java.util.concurrent.ConcurrentHashMap;
48-
import java.util.function.Function;
49-
5050
import static org.springframework.security.oauth2.jwt.NimbusJwtDecoder.withJwkSetUri;
5151
import static org.springframework.security.oauth2.jwt.NimbusJwtDecoder.withSecretKey;
5252

@@ -150,7 +150,7 @@ private NimbusJwtDecoder buildDecoder(ClientRegistration clientRegistration) {
150150
);
151151
throw new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());
152152
}
153-
return withJwkSetUri(jwkSetUri).jwsAlgorithm(jwsAlgorithm).build();
153+
return withJwkSetUri(jwkSetUri).jwsAlgorithm((SignatureAlgorithm) jwsAlgorithm).build();
154154
} else if (jwsAlgorithm != null && MacAlgorithm.class.isAssignableFrom(jwsAlgorithm.getClass())) {
155155
// https://openid.net/specs/openid-connect-core-1_0.html#IDTokenValidation
156156
//

oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/oidc/authentication/ReactiveOidcIdTokenDecoderFactory.java

+11-11
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,16 @@
1515
*/
1616
package org.springframework.security.oauth2.client.oidc.authentication;
1717

18+
import java.net.URL;
19+
import java.nio.charset.StandardCharsets;
20+
import java.time.Instant;
21+
import java.util.Collection;
22+
import java.util.HashMap;
23+
import java.util.Map;
24+
import java.util.concurrent.ConcurrentHashMap;
25+
import java.util.function.Function;
26+
import javax.crypto.spec.SecretKeySpec;
27+
1828
import org.springframework.core.convert.TypeDescriptor;
1929
import org.springframework.core.convert.converter.Converter;
2030
import org.springframework.security.oauth2.client.registration.ClientRegistration;
@@ -37,16 +47,6 @@
3747
import org.springframework.util.Assert;
3848
import org.springframework.util.StringUtils;
3949

40-
import javax.crypto.spec.SecretKeySpec;
41-
import java.net.URL;
42-
import java.nio.charset.StandardCharsets;
43-
import java.time.Instant;
44-
import java.util.Collection;
45-
import java.util.HashMap;
46-
import java.util.Map;
47-
import java.util.concurrent.ConcurrentHashMap;
48-
import java.util.function.Function;
49-
5050
import static org.springframework.security.oauth2.jwt.NimbusReactiveJwtDecoder.withJwkSetUri;
5151
import static org.springframework.security.oauth2.jwt.NimbusReactiveJwtDecoder.withSecretKey;
5252

@@ -150,7 +150,7 @@ private NimbusReactiveJwtDecoder buildDecoder(ClientRegistration clientRegistrat
150150
);
151151
throw new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());
152152
}
153-
return withJwkSetUri(jwkSetUri).jwsAlgorithm(jwsAlgorithm).build();
153+
return withJwkSetUri(jwkSetUri).jwsAlgorithm((SignatureAlgorithm) jwsAlgorithm).build();
154154
} else if (jwsAlgorithm != null && MacAlgorithm.class.isAssignableFrom(jwsAlgorithm.getClass())) {
155155
// https://openid.net/specs/openid-connect-core-1_0.html#IDTokenValidation
156156
//

oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/NimbusJwtDecoder.java

+4-5
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,6 @@
5252
import org.springframework.http.ResponseEntity;
5353
import org.springframework.security.oauth2.core.OAuth2TokenValidator;
5454
import org.springframework.security.oauth2.core.OAuth2TokenValidatorResult;
55-
import org.springframework.security.oauth2.jose.jws.JwsAlgorithm;
5655
import org.springframework.security.oauth2.jose.jws.MacAlgorithm;
5756
import org.springframework.security.oauth2.jose.jws.SignatureAlgorithm;
5857
import org.springframework.util.Assert;
@@ -222,12 +221,12 @@ private JwkSetUriJwtDecoderBuilder(String jwkSetUri) {
222221
* Use the given signing
223222
* <a href="https://tools.ietf.org/html/rfc7515#section-4.1.1" target="_blank">algorithm</a>.
224223
*
225-
* @param jwsAlgorithm the algorithm to use
224+
* @param signatureAlgorithm the algorithm to use
226225
* @return a {@link JwkSetUriJwtDecoderBuilder} for further configurations
227226
*/
228-
public JwkSetUriJwtDecoderBuilder jwsAlgorithm(JwsAlgorithm jwsAlgorithm) {
229-
Assert.notNull(jwsAlgorithm, "jwsAlgorithm cannot be null");
230-
this.jwsAlgorithm = JWSAlgorithm.parse(jwsAlgorithm.getName());
227+
public JwkSetUriJwtDecoderBuilder jwsAlgorithm(SignatureAlgorithm signatureAlgorithm) {
228+
Assert.notNull(signatureAlgorithm, "signatureAlgorithm cannot be null");
229+
this.jwsAlgorithm = JWSAlgorithm.parse(signatureAlgorithm.getName());
231230
return this;
232231
}
233232

oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/NimbusReactiveJwtDecoder.java

+4-4
Original file line numberDiff line numberDiff line change
@@ -245,12 +245,12 @@ private JwkSetUriReactiveJwtDecoderBuilder(String jwkSetUri) {
245245
* Use the given signing
246246
* <a href="https://tools.ietf.org/html/rfc7515#section-4.1.1" target="_blank">algorithm</a>.
247247
*
248-
* @param jwsAlgorithm the algorithm to use
248+
* @param signatureAlgorithm the algorithm to use
249249
* @return a {@link JwkSetUriReactiveJwtDecoderBuilder} for further configurations
250250
*/
251-
public JwkSetUriReactiveJwtDecoderBuilder jwsAlgorithm(JwsAlgorithm jwsAlgorithm) {
252-
Assert.notNull(jwsAlgorithm, "jwsAlgorithm cannot be null");
253-
this.jwsAlgorithm = JWSAlgorithm.parse(jwsAlgorithm.getName());
251+
public JwkSetUriReactiveJwtDecoderBuilder jwsAlgorithm(SignatureAlgorithm signatureAlgorithm) {
252+
Assert.notNull(signatureAlgorithm, "sig cannot be null");
253+
this.jwsAlgorithm = JWSAlgorithm.parse(signatureAlgorithm.getName());
254254
return this;
255255
}
256256

0 commit comments

Comments
 (0)