Skip to content
This repository was archived by the owner on May 31, 2022. It is now read-only.

Commit 0411bca

Browse files
committed
DefaultOAuth2RequestAuthenticator resolves Bearer syntax
Fixes gh-1346
1 parent 0c034e4 commit 0411bca

File tree

2 files changed

+57
-6
lines changed

2 files changed

+57
-6
lines changed

spring-security-oauth2/src/main/java/org/springframework/security/oauth2/client/DefaultOAuth2RequestAuthenticator.java

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
2-
* Copyright 2013-2014 the original author or authors.
2+
* Copyright 2013-2018 the original author or authors.
33
*
44
* Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
55
* the License. You may obtain a copy of the License at
@@ -35,6 +35,9 @@ public void authenticate(OAuth2ProtectedResourceDetails resource, OAuth2ClientCo
3535
String tokenType = accessToken.getTokenType();
3636
if (!StringUtils.hasText(tokenType)) {
3737
tokenType = OAuth2AccessToken.BEARER_TYPE; // we'll assume basic bearer token type if none is specified.
38+
} else if (tokenType.equalsIgnoreCase(OAuth2AccessToken.BEARER_TYPE)) {
39+
// gh-1346
40+
tokenType = OAuth2AccessToken.BEARER_TYPE; // Ensure we use the correct syntax for the "Bearer" authentication scheme
3841
}
3942
request.getHeaders().set("Authorization", String.format("%s %s", tokenType, accessToken.getValue()));
4043
}

spring-security-oauth2/src/test/java/org/springframework/security/oauth2/client/DefaultOAuth2RequestAuthenticatorTests.java

Lines changed: 53 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
2-
* Copyright 2013-2014 the original author or authors.
2+
* Copyright 2013-2018 the original author or authors.
33
*
44
* Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
55
* the License. You may obtain a copy of the License at
@@ -13,13 +13,14 @@
1313

1414
package org.springframework.security.oauth2.client;
1515

16-
import static org.junit.Assert.assertEquals;
17-
1816
import org.junit.Test;
1917
import org.springframework.mock.http.client.MockClientHttpRequest;
2018
import org.springframework.security.oauth2.client.http.AccessTokenRequiredException;
2119
import org.springframework.security.oauth2.client.resource.BaseOAuth2ProtectedResourceDetails;
2220
import org.springframework.security.oauth2.common.DefaultOAuth2AccessToken;
21+
import org.springframework.security.oauth2.common.OAuth2AccessToken;
22+
23+
import static org.junit.Assert.assertEquals;
2324

2425
/**
2526
* @author Dave Syer
@@ -45,7 +46,54 @@ public void addsAccessToken() {
4546
BaseOAuth2ProtectedResourceDetails resource = new BaseOAuth2ProtectedResourceDetails();
4647
authenticator.authenticate(resource, context, request);
4748
String header = request.getHeaders().getFirst("Authorization");
48-
assertEquals("bearer FOO", header);
49+
assertEquals("Bearer FOO", header);
50+
}
51+
52+
// gh-1346
53+
@Test
54+
public void authenticateWhenTokenTypeBearerUppercaseThenUseBearer() {
55+
DefaultOAuth2AccessToken accessToken = new DefaultOAuth2AccessToken("FOO");
56+
accessToken.setTokenType(OAuth2AccessToken.BEARER_TYPE.toUpperCase());
57+
context.setAccessToken(accessToken);
58+
BaseOAuth2ProtectedResourceDetails resource = new BaseOAuth2ProtectedResourceDetails();
59+
authenticator.authenticate(resource, context, request);
60+
String header = request.getHeaders().getFirst("Authorization");
61+
assertEquals("Bearer FOO", header);
4962
}
5063

51-
}
64+
// gh-1346
65+
@Test
66+
public void authenticateWhenTokenTypeBearerLowercaseThenUseBearer() {
67+
DefaultOAuth2AccessToken accessToken = new DefaultOAuth2AccessToken("FOO");
68+
accessToken.setTokenType(OAuth2AccessToken.BEARER_TYPE.toLowerCase());
69+
context.setAccessToken(accessToken);
70+
BaseOAuth2ProtectedResourceDetails resource = new BaseOAuth2ProtectedResourceDetails();
71+
authenticator.authenticate(resource, context, request);
72+
String header = request.getHeaders().getFirst("Authorization");
73+
assertEquals("Bearer FOO", header);
74+
}
75+
76+
// gh-1346
77+
@Test
78+
public void authenticateWhenTokenTypeBearerMixcaseThenUseBearer() {
79+
DefaultOAuth2AccessToken accessToken = new DefaultOAuth2AccessToken("FOO");
80+
accessToken.setTokenType("BeaRer");
81+
context.setAccessToken(accessToken);
82+
BaseOAuth2ProtectedResourceDetails resource = new BaseOAuth2ProtectedResourceDetails();
83+
authenticator.authenticate(resource, context, request);
84+
String header = request.getHeaders().getFirst("Authorization");
85+
assertEquals("Bearer FOO", header);
86+
}
87+
88+
// gh-1346
89+
@Test
90+
public void authenticateWhenTokenTypeMACThenUseMAC() {
91+
DefaultOAuth2AccessToken accessToken = new DefaultOAuth2AccessToken("FOO");
92+
accessToken.setTokenType("MAC");
93+
context.setAccessToken(accessToken);
94+
BaseOAuth2ProtectedResourceDetails resource = new BaseOAuth2ProtectedResourceDetails();
95+
authenticator.authenticate(resource, context, request);
96+
String header = request.getHeaders().getFirst("Authorization");
97+
assertEquals("MAC FOO", header);
98+
}
99+
}

0 commit comments

Comments
 (0)