Add a minimal authorization server configuration

Closes gh-18144

Signed-off-by: Andrey Litvitski <andrey1010102008@gmail.com>
This commit is contained in:
Andrey Litvitski 2025-11-09 15:26:26 +03:00 committed by Joe Grandja
parent b7fb2892ed
commit e6db56ab4f

View File

@ -95,6 +95,24 @@ public JwtDecoder jwtDecoder(JWKSource<SecurityContext> jwkSource) {
The main intent of `OAuth2AuthorizationServerConfiguration` is to provide a convenient method to apply the minimal default configuration for an OAuth2 authorization server. However, in most cases, customizing the configuration will be required.
The following example shows how you can wire an authorization server with nothing more than an `HttpSecurity` builder while still re-using Spring Boots defaults for users and static resources:
[source,java]
----
@Bean
SecurityFilterChain springSecurity(HttpSecurity http) {
http
.authorizeHttpRequests(requests -> requests
.anyRequest().authenticated()
)
.authorizationServer(auth -> auth
.oidc(Customizer.withDefaults())
)
.formLogin(Customizer.withDefaults());
return http.build();
}
----
[[oauth2AuthorizationServer-customizing-the-configuration]]
== Customizing the configuration