634 |
635 | This program is free software: you can redistribute it and/or modify
636 | it under the terms of the GNU Affero General Public License as published by
637 | the Free Software Foundation, either version 3 of the License, or
638 | (at your option) any later version.
639 |
640 | This program is distributed in the hope that it will be useful,
641 | but WITHOUT ANY WARRANTY; without even the implied warranty of
642 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
643 | GNU Affero General Public License for more details.
644 |
645 | You should have received a copy of the GNU Affero General Public License
646 | along with this program. If not, see .
647 |
648 | Also add information on how to contact you by electronic and paper mail.
649 |
650 | If your software can interact with users remotely through a computer
651 | network, you should also make sure that it provides a way for users to
652 | get its source. For example, if your program is a web application, its
653 | interface could display a "Source" link that leads users to an archive
654 | of the code. There are many ways you could offer source, and different
655 | solutions will be better for different programs; see section 13 for the
656 | specific requirements.
657 |
658 | You should also get your employer (if you work as a programmer) or school,
659 | if any, to sign a "copyright disclaimer" for the program, if necessary.
660 | For more information on this, and how to apply and follow the GNU AGPL, see
661 | .
662 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # Java Microservice Quickstart Template
2 | Spring-Boot application preconfigured for to use [EGO](https://github.com/overture-stack/ego/) generated JWTs for authorization.
3 |
4 | [](https://opensource.org/licenses/Apache-2.0)
5 |
6 |
7 | ## Features
8 | This template provides the following:
9 |
10 | * Spring-Boot Application with Spring Security
11 | * JWT Authorization
12 | * JWT Asymmetric Verification - fetches public-key from web on start-up
13 | * JWT Filter - User Role and Status requirements implemented by default
14 | * Docker and Docker-Compose configuration
15 |
16 |
17 | ## Template Guide
18 | Here is a convenient list of steps to create a new application based on this template:
19 |
20 | 1. Fork this!
21 | 2. Update __pom.xml__:
22 | - `groupId`
23 | - `artifactId`
24 | - `name`
25 | - `description`
26 | 3. Update __application.yml__:
27 | - `auth.jwt.publicKeyUrl` - URL to fetch the JWT verification key
28 | 4. Configure Codacy:
29 | - Go to [Codacy Project Wizard](https://www.codacy.com/wizard/projects) and add your new repository.
30 | 5. Configure CircleCI:
31 | - Go to [CircleCI Add Projects](https://circleci.com/add-projects/gh/overture-stack) and add your project.
32 | - Go to CircleCI project settings and modify environment variables
33 | - If not there, add new environment variable: `EGO_TEST_SERVER_KEY_URL` . This should store the URL used for `auth.jwt.publicKeyUrl` value in CircleCI tests.
34 | 6. Update __README.md__:
35 | - Replace current README with template - __README.template.md__
36 | - Remove template file
37 | - Update Project name and description in new README
38 | - Update Shields in Introduction section
39 | - Codacy - Badge Markdown code can be found on Codacy project's settings page
40 | - CircleCI - Build from example using github organization, project, and branch names
41 |
42 |
43 |
44 |
45 | ## Requirements
46 | The application can be run locally or in a docker container, the requirements for each setup are listed below.
47 |
48 |
49 | ### EGO
50 | A running instance of [EGO](https://github.com/overture-stack/ego/) is required to generate the Authorization tokens and to provide the verification key.
51 |
52 | [EGO](https://github.com/overture-stack/ego/) can be cloned and run locally if a public instance is not setup.
53 |
54 |
55 | ### Local
56 | * [Java 8 SDK](http://www.oracle.com/technetwork/java/javase/downloads/jdk8-downloads-2133151.html)
57 | * [Maven](https://maven.apache.org/download.cgi)
58 |
59 |
60 | ### Docker
61 | * [Docker](https://www.docker.com/get-docker)
62 |
63 |
64 | ## Quick Start
65 | Make sure the JWT Verification Key URL is configured, then you can run the server in a docker container or on your local machine.
66 |
67 |
68 | ### Configure JWT Verification Key
69 | Update __application.yml__. Set `auth.jwt.publicKeyUrl` to the URL to fetch the JWT verification key. The application will not start if it can't set the verification key for the JWTConverter.
70 |
71 | The default value in the __application.yml__ file is set to connect to EGO running locally on its default port `8081`.
72 |
73 | ### Run Local
74 | ```bash
75 | $ mvn spring-boot:run
76 | ```
77 |
78 | Application will run by default on port `1234`
79 |
80 | Configure the port by changing `server.port` in __application.yml__
81 |
82 |
83 | ### Run Docker
84 |
85 | First build the image:
86 | ```bash
87 | $ docker-compose build
88 | ```
89 |
90 | When ready, run it:
91 | ```bash
92 | $ docker-compose up
93 | ```
94 |
95 | Application will run by default on port `1234`
96 |
97 | Configure the port by changing `services.api.ports` in __docker-compose.yml__. Port 1234 was used by default so the value is easy to identify and change in the configuration file.
98 |
99 | ### Test Endpoint
100 | The application has a single endpoint `/test` that will accept GET and POST requests with a valid token.
101 |
102 | A JWT must be passed in a request header, following the Bearer token pattern. Below is a usable value to test with, it is valid vs. the example keystore given in the EGO repo.
103 |
104 | ```
105 | Authorization=Bearer eyJhbGciOiJSUzI1NiJ9.eyJpYXQiOjE1MTI3NjIxODIsImV4cCI6MjE0NzQ4MzY0Nywic3ViIjoiNjA2IiwiaXNzIjoiZWdvIiwiYXVkIjpbXSwiY29udGV4dCI6eyJ1c2VyIjp7Im5hbWUiOiJEZW1vLlVzZXJAZXhhbXBsZS5jb20iLCJlbWFpbCI6IkRlbW8uVXNlckBleGFtcGxlLmNvbSIsInN0YXR1cyI6IkFwcHJvdmVkIiwiZmlyc3ROYW1lIjoiRGVtbyIsImxhc3ROYW1lIjoiVXNlciIsImNyZWF0ZWRBdCI6IjIwMTctMTEtMjIgMDM6MTA6NTUiLCJsYXN0TG9naW4iOiIyMDE3LTEyLTA4IDA3OjQzOjAyIiwicHJlZmVycmVkTGFuZ3VhZ2UiOm51bGwsInJvbGVzIjpbIlVTRVIiXX19LCJqdGkiOiI0OGE5NGIzNy1mMTJlLTQxNWQtYjM1Zi1kZDhmOThiMDQ4ZDcifQ.Cmgbd_xnUp8dPnIJvmUXmh5LYnHgHSk_n_0VzCn0k9r4WVNdsupb-MQqJvgOMg3K8si5mzhIjzLi9rZL5N_JwFXtpjKXKRVT7KF4mYfqF7bVNm6tkQg6CeAGhiuaMujhLhASS79LVBPKOv1tk79WuVu-VKHzyLS1h3yFQAsjLVQxA6_0MD7zKa1W3Nbhte6lHwgiNo1AlxuIJzP37-2saNb-aUy9DigmH3_C2oPqxpBu-YNnaekO5jNmbfucMinlpxCpEw-UvpvxI9Xk_9E73TNQE9acNQyyg_BxdnVbwDsR-kG5QXNrlEAxGm-1yY6w8Nvqxcp-3uoff6K0uKLUdQ
106 | ```
107 |
108 | Test cURL requests:
109 | ```bash
110 | curl -X GET \
111 | http://localhost:1234/test \
112 | -H 'authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJpYXQiOjE1MTI3NjIxODIsImV4cCI6MjE0NzQ4MzY0Nywic3ViIjoiNjA2IiwiaXNzIjoiZWdvIiwiYXVkIjpbXSwiY29udGV4dCI6eyJ1c2VyIjp7Im5hbWUiOiJEZW1vLlVzZXJAZXhhbXBsZS5jb20iLCJlbWFpbCI6IkRlbW8uVXNlckBleGFtcGxlLmNvbSIsInN0YXR1cyI6IkFwcHJvdmVkIiwiZmlyc3ROYW1lIjoiRGVtbyIsImxhc3ROYW1lIjoiVXNlciIsImNyZWF0ZWRBdCI6IjIwMTctMTEtMjIgMDM6MTA6NTUiLCJsYXN0TG9naW4iOiIyMDE3LTEyLTA4IDA3OjQzOjAyIiwicHJlZmVycmVkTGFuZ3VhZ2UiOm51bGwsInJvbGVzIjpbIlVTRVIiXX19LCJqdGkiOiI0OGE5NGIzNy1mMTJlLTQxNWQtYjM1Zi1kZDhmOThiMDQ4ZDcifQ.Cmgbd_xnUp8dPnIJvmUXmh5LYnHgHSk_n_0VzCn0k9r4WVNdsupb-MQqJvgOMg3K8si5mzhIjzLi9rZL5N_JwFXtpjKXKRVT7KF4mYfqF7bVNm6tkQg6CeAGhiuaMujhLhASS79LVBPKOv1tk79WuVu-VKHzyLS1h3yFQAsjLVQxA6_0MD7zKa1W3Nbhte6lHwgiNo1AlxuIJzP37-2saNb-aUy9DigmH3_C2oPqxpBu-YNnaekO5jNmbfucMinlpxCpEw-UvpvxI9Xk_9E73TNQE9acNQyyg_BxdnVbwDsR-kG5QXNrlEAxGm-1yY6w8Nvqxcp-3uoff6K0uKLUdQ'
113 | ```
114 |
115 | ```bash
116 | curl -X POST \
117 | http://localhost:1234/test \
118 | -H 'authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJpYXQiOjE1MTI3NjIxODIsImV4cCI6MjE0NzQ4MzY0Nywic3ViIjoiNjA2IiwiaXNzIjoiZWdvIiwiYXVkIjpbXSwiY29udGV4dCI6eyJ1c2VyIjp7Im5hbWUiOiJEZW1vLlVzZXJAZXhhbXBsZS5jb20iLCJlbWFpbCI6IkRlbW8uVXNlckBleGFtcGxlLmNvbSIsInN0YXR1cyI6IkFwcHJvdmVkIiwiZmlyc3ROYW1lIjoiRGVtbyIsImxhc3ROYW1lIjoiVXNlciIsImNyZWF0ZWRBdCI6IjIwMTctMTEtMjIgMDM6MTA6NTUiLCJsYXN0TG9naW4iOiIyMDE3LTEyLTA4IDA3OjQzOjAyIiwicHJlZmVycmVkTGFuZ3VhZ2UiOm51bGwsInJvbGVzIjpbIlVTRVIiXX19LCJqdGkiOiI0OGE5NGIzNy1mMTJlLTQxNWQtYjM1Zi1kZDhmOThiMDQ4ZDcifQ.Cmgbd_xnUp8dPnIJvmUXmh5LYnHgHSk_n_0VzCn0k9r4WVNdsupb-MQqJvgOMg3K8si5mzhIjzLi9rZL5N_JwFXtpjKXKRVT7KF4mYfqF7bVNm6tkQg6CeAGhiuaMujhLhASS79LVBPKOv1tk79WuVu-VKHzyLS1h3yFQAsjLVQxA6_0MD7zKa1W3Nbhte6lHwgiNo1AlxuIJzP37-2saNb-aUy9DigmH3_C2oPqxpBu-YNnaekO5jNmbfucMinlpxCpEw-UvpvxI9Xk_9E73TNQE9acNQyyg_BxdnVbwDsR-kG5QXNrlEAxGm-1yY6w8Nvqxcp-3uoff6K0uKLUdQ'
119 | ```
120 |
121 | If everything is working as expected, the request should return a pleasant greeting. ;)
122 |
--------------------------------------------------------------------------------
/README.template.md:
--------------------------------------------------------------------------------
1 | Project Title
2 |
3 |
4 | Sample microservice description.
5 |
6 |
7 |
8 | ## Table of Contents
9 |
10 | - [Introduction](#introduction)
11 | - [Features](#features)
12 | - [Requirements](#requirements)
13 | - [Quick Start](#quick-start)
14 | - [Testing](#testing)
15 | - [API](#requirements)
16 | - [Acknowledgements](#acknowledgements)
17 |
18 |
19 |
20 |
21 | ## Introduction
22 |
23 | [](https://opensource.org/licenses/Apache-2.0)
24 | [](https://www.codacy.com/app/joneubank/microservice-template-java?utm_source=github.com&utm_medium=referral&utm_content=overture-stack/microservice-template-java&utm_campaign=Badge_Grade)
25 | [](https://circleci.com/gh/overture-stack/microservice-template-java/tree/master)
26 |
27 | TODO: Replace with introduction
28 |
29 | ## Features
30 | TODO: Description of features
31 |
32 | * Include a list of
33 | * all the many beautiful
34 | * web server features
35 |
36 |
37 | ## Requirements
38 | The application can be run locally or in a docker container, the requirements for each setup are listed below.
39 |
40 |
41 | ### EGO
42 | A running instance of [EGO](https://github.com/overture-stack/ego/) is required to generate the Authorization tokens and to provide the verification key.
43 |
44 | [EGO](https://github.com/overture-stack/ego/) can be cloned and run locally if no public server is available.
45 |
46 |
47 | ### Local
48 | * [Java 8 SDK](http://www.oracle.com/technetwork/java/javase/downloads/jdk8-downloads-2133151.html)
49 | * [Maven](https://maven.apache.org/download.cgi)
50 |
51 |
52 | ### Docker
53 | * [Docker](https://www.docker.com/get-docker)
54 |
55 |
56 | ## Quick Start
57 | Make sure the JWT Verification Key URL is configured, then you can run the server in a docker container or on your local machine.
58 |
59 | ### Configure JWT Verification Key
60 | Update __application.yml__. Set `auth.jwt.publicKeyUrl` to the URL to fetch the JWT verification key. The application will not start if it can't set the verification key for the JWTConverter.
61 |
62 | The default value in the __application.yml__ file is set to connect to EGO running locally on its default port `8081`.
63 |
64 | ### Run Local
65 | ```bash
66 | $ mvn spring-boot:run
67 | ```
68 |
69 | Application will run by default on port `1234`
70 |
71 | Configure the port by changing `server.port` in __application.yml__
72 |
73 |
74 | ### Run Docker
75 |
76 | First build the image:
77 | ```bash
78 | $ docker-compose build
79 | ```
80 |
81 | When ready, run it:
82 | ```bash
83 | $ docker-compose up
84 | ```
85 |
86 | Application will run by default on port `1234`
87 |
88 | Configure the port by changing `services.api.ports` in __docker-compose.yml__. Port 1234 was used by default so the value is easy to identify and change in the configuration file.
89 |
90 |
91 | ## Testing
92 | TODO: Additional instructions for testing the application.
93 |
94 |
95 | ## API
96 | TODO: API Reference with examples, or a link to a wiki or other documentation source.
97 |
98 | ## Acknowledgements
99 | TODO: Show folks some love.
--------------------------------------------------------------------------------
/docker-compose.yml:
--------------------------------------------------------------------------------
1 | version: "3.2"
2 | services:
3 | api:
4 | build: .
5 | ports:
6 | - "1234:8081"
7 |
--------------------------------------------------------------------------------
/mvnw:
--------------------------------------------------------------------------------
1 | #!/bin/sh
2 | # ----------------------------------------------------------------------------
3 | # Licensed to the Apache Software Foundation (ASF) under one
4 | # or more contributor license agreements. See the NOTICE file
5 | # distributed with this work for additional information
6 | # regarding copyright ownership. The ASF licenses this file
7 | # to you under the Apache License, Version 2.0 (the
8 | # "License"); you may not use this file except in compliance
9 | # with the License. You may obtain a copy of the License at
10 | #
11 | # http://www.apache.org/licenses/LICENSE-2.0
12 | #
13 | # Unless required by applicable law or agreed to in writing,
14 | # software distributed under the License is distributed on an
15 | # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
16 | # KIND, either express or implied. See the License for the
17 | # specific language governing permissions and limitations
18 | # under the License.
19 | # ----------------------------------------------------------------------------
20 |
21 | # ----------------------------------------------------------------------------
22 | # Maven2 Start Up Batch script
23 | #
24 | # Required ENV vars:
25 | # ------------------
26 | # JAVA_HOME - location of a JDK home dir
27 | #
28 | # Optional ENV vars
29 | # -----------------
30 | # M2_HOME - location of maven2's installed home dir
31 | # MAVEN_OPTS - parameters passed to the Java VM when running Maven
32 | # e.g. to debug Maven itself, use
33 | # set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000
34 | # MAVEN_SKIP_RC - flag to disable loading of mavenrc files
35 | # ----------------------------------------------------------------------------
36 |
37 | if [ -z "$MAVEN_SKIP_RC" ] ; then
38 |
39 | if [ -f /etc/mavenrc ] ; then
40 | . /etc/mavenrc
41 | fi
42 |
43 | if [ -f "$HOME/.mavenrc" ] ; then
44 | . "$HOME/.mavenrc"
45 | fi
46 |
47 | fi
48 |
49 | # OS specific support. $var _must_ be set to either true or false.
50 | cygwin=false;
51 | darwin=false;
52 | mingw=false
53 | case "`uname`" in
54 | CYGWIN*) cygwin=true ;;
55 | MINGW*) mingw=true;;
56 | Darwin*) darwin=true
57 | # Use /usr/libexec/java_home if available, otherwise fall back to /Library/Java/Home
58 | # See https://developer.apple.com/library/mac/qa/qa1170/_index.html
59 | if [ -z "$JAVA_HOME" ]; then
60 | if [ -x "/usr/libexec/java_home" ]; then
61 | export JAVA_HOME="`/usr/libexec/java_home`"
62 | else
63 | export JAVA_HOME="/Library/Java/Home"
64 | fi
65 | fi
66 | ;;
67 | esac
68 |
69 | if [ -z "$JAVA_HOME" ] ; then
70 | if [ -r /etc/gentoo-release ] ; then
71 | JAVA_HOME=`java-config --jre-home`
72 | fi
73 | fi
74 |
75 | if [ -z "$M2_HOME" ] ; then
76 | ## resolve links - $0 may be a link to maven's home
77 | PRG="$0"
78 |
79 | # need this for relative symlinks
80 | while [ -h "$PRG" ] ; do
81 | ls=`ls -ld "$PRG"`
82 | link=`expr "$ls" : '.*-> \(.*\)$'`
83 | if expr "$link" : '/.*' > /dev/null; then
84 | PRG="$link"
85 | else
86 | PRG="`dirname "$PRG"`/$link"
87 | fi
88 | done
89 |
90 | saveddir=`pwd`
91 |
92 | M2_HOME=`dirname "$PRG"`/..
93 |
94 | # make it fully qualified
95 | M2_HOME=`cd "$M2_HOME" && pwd`
96 |
97 | cd "$saveddir"
98 | # echo Using m2 at $M2_HOME
99 | fi
100 |
101 | # For Cygwin, ensure paths are in UNIX format before anything is touched
102 | if $cygwin ; then
103 | [ -n "$M2_HOME" ] &&
104 | M2_HOME=`cygpath --unix "$M2_HOME"`
105 | [ -n "$JAVA_HOME" ] &&
106 | JAVA_HOME=`cygpath --unix "$JAVA_HOME"`
107 | [ -n "$CLASSPATH" ] &&
108 | CLASSPATH=`cygpath --path --unix "$CLASSPATH"`
109 | fi
110 |
111 | # For Migwn, ensure paths are in UNIX format before anything is touched
112 | if $mingw ; then
113 | [ -n "$M2_HOME" ] &&
114 | M2_HOME="`(cd "$M2_HOME"; pwd)`"
115 | [ -n "$JAVA_HOME" ] &&
116 | JAVA_HOME="`(cd "$JAVA_HOME"; pwd)`"
117 | # TODO classpath?
118 | fi
119 |
120 | if [ -z "$JAVA_HOME" ]; then
121 | javaExecutable="`which javac`"
122 | if [ -n "$javaExecutable" ] && ! [ "`expr \"$javaExecutable\" : '\([^ ]*\)'`" = "no" ]; then
123 | # readlink(1) is not available as standard on Solaris 10.
124 | readLink=`which readlink`
125 | if [ ! `expr "$readLink" : '\([^ ]*\)'` = "no" ]; then
126 | if $darwin ; then
127 | javaHome="`dirname \"$javaExecutable\"`"
128 | javaExecutable="`cd \"$javaHome\" && pwd -P`/javac"
129 | else
130 | javaExecutable="`readlink -f \"$javaExecutable\"`"
131 | fi
132 | javaHome="`dirname \"$javaExecutable\"`"
133 | javaHome=`expr "$javaHome" : '\(.*\)/bin'`
134 | JAVA_HOME="$javaHome"
135 | export JAVA_HOME
136 | fi
137 | fi
138 | fi
139 |
140 | if [ -z "$JAVACMD" ] ; then
141 | if [ -n "$JAVA_HOME" ] ; then
142 | if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
143 | # IBM's JDK on AIX uses strange locations for the executables
144 | JAVACMD="$JAVA_HOME/jre/sh/java"
145 | else
146 | JAVACMD="$JAVA_HOME/bin/java"
147 | fi
148 | else
149 | JAVACMD="`which java`"
150 | fi
151 | fi
152 |
153 | if [ ! -x "$JAVACMD" ] ; then
154 | echo "Error: JAVA_HOME is not defined correctly." >&2
155 | echo " We cannot execute $JAVACMD" >&2
156 | exit 1
157 | fi
158 |
159 | if [ -z "$JAVA_HOME" ] ; then
160 | echo "Warning: JAVA_HOME environment variable is not set."
161 | fi
162 |
163 | CLASSWORLDS_LAUNCHER=org.codehaus.plexus.classworlds.launcher.Launcher
164 |
165 | # traverses directory structure from process work directory to filesystem root
166 | # first directory with .mvn subdirectory is considered project base directory
167 | find_maven_basedir() {
168 |
169 | if [ -z "$1" ]
170 | then
171 | echo "Path not specified to find_maven_basedir"
172 | return 1
173 | fi
174 |
175 | basedir="$1"
176 | wdir="$1"
177 | while [ "$wdir" != '/' ] ; do
178 | if [ -d "$wdir"/.mvn ] ; then
179 | basedir=$wdir
180 | break
181 | fi
182 | # workaround for JBEAP-8937 (on Solaris 10/Sparc)
183 | if [ -d "${wdir}" ]; then
184 | wdir=`cd "$wdir/.."; pwd`
185 | fi
186 | # end of workaround
187 | done
188 | echo "${basedir}"
189 | }
190 |
191 | # concatenates all lines of a file
192 | concat_lines() {
193 | if [ -f "$1" ]; then
194 | echo "$(tr -s '\n' ' ' < "$1")"
195 | fi
196 | }
197 |
198 | BASE_DIR=`find_maven_basedir "$(pwd)"`
199 | if [ -z "$BASE_DIR" ]; then
200 | exit 1;
201 | fi
202 |
203 | export MAVEN_PROJECTBASEDIR=${MAVEN_BASEDIR:-"$BASE_DIR"}
204 | echo $MAVEN_PROJECTBASEDIR
205 | MAVEN_OPTS="$(concat_lines "$MAVEN_PROJECTBASEDIR/.mvn/jvm.config") $MAVEN_OPTS"
206 |
207 | # For Cygwin, switch paths to Windows format before running java
208 | if $cygwin; then
209 | [ -n "$M2_HOME" ] &&
210 | M2_HOME=`cygpath --path --windows "$M2_HOME"`
211 | [ -n "$JAVA_HOME" ] &&
212 | JAVA_HOME=`cygpath --path --windows "$JAVA_HOME"`
213 | [ -n "$CLASSPATH" ] &&
214 | CLASSPATH=`cygpath --path --windows "$CLASSPATH"`
215 | [ -n "$MAVEN_PROJECTBASEDIR" ] &&
216 | MAVEN_PROJECTBASEDIR=`cygpath --path --windows "$MAVEN_PROJECTBASEDIR"`
217 | fi
218 |
219 | WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain
220 |
221 | exec "$JAVACMD" \
222 | $MAVEN_OPTS \
223 | -classpath "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" \
224 | "-Dmaven.home=${M2_HOME}" "-Dmaven.multiModuleProjectDirectory=${MAVEN_PROJECTBASEDIR}" \
225 | ${WRAPPER_LAUNCHER} $MAVEN_CONFIG "$@"
226 |
--------------------------------------------------------------------------------
/mvnw.cmd:
--------------------------------------------------------------------------------
1 | @REM ----------------------------------------------------------------------------
2 | @REM Licensed to the Apache Software Foundation (ASF) under one
3 | @REM or more contributor license agreements. See the NOTICE file
4 | @REM distributed with this work for additional information
5 | @REM regarding copyright ownership. The ASF licenses this file
6 | @REM to you under the Apache License, Version 2.0 (the
7 | @REM "License"); you may not use this file except in compliance
8 | @REM with the License. You may obtain a copy of the License at
9 | @REM
10 | @REM http://www.apache.org/licenses/LICENSE-2.0
11 | @REM
12 | @REM Unless required by applicable law or agreed to in writing,
13 | @REM software distributed under the License is distributed on an
14 | @REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15 | @REM KIND, either express or implied. See the License for the
16 | @REM specific language governing permissions and limitations
17 | @REM under the License.
18 | @REM ----------------------------------------------------------------------------
19 |
20 | @REM ----------------------------------------------------------------------------
21 | @REM Maven2 Start Up Batch script
22 | @REM
23 | @REM Required ENV vars:
24 | @REM JAVA_HOME - location of a JDK home dir
25 | @REM
26 | @REM Optional ENV vars
27 | @REM M2_HOME - location of maven2's installed home dir
28 | @REM MAVEN_BATCH_ECHO - set to 'on' to enable the echoing of the batch commands
29 | @REM MAVEN_BATCH_PAUSE - set to 'on' to wait for a key stroke before ending
30 | @REM MAVEN_OPTS - parameters passed to the Java VM when running Maven
31 | @REM e.g. to debug Maven itself, use
32 | @REM set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000
33 | @REM MAVEN_SKIP_RC - flag to disable loading of mavenrc files
34 | @REM ----------------------------------------------------------------------------
35 |
36 | @REM Begin all REM lines with '@' in case MAVEN_BATCH_ECHO is 'on'
37 | @echo off
38 | @REM enable echoing my setting MAVEN_BATCH_ECHO to 'on'
39 | @if "%MAVEN_BATCH_ECHO%" == "on" echo %MAVEN_BATCH_ECHO%
40 |
41 | @REM set %HOME% to equivalent of $HOME
42 | if "%HOME%" == "" (set "HOME=%HOMEDRIVE%%HOMEPATH%")
43 |
44 | @REM Execute a user defined script before this one
45 | if not "%MAVEN_SKIP_RC%" == "" goto skipRcPre
46 | @REM check for pre script, once with legacy .bat ending and once with .cmd ending
47 | if exist "%HOME%\mavenrc_pre.bat" call "%HOME%\mavenrc_pre.bat"
48 | if exist "%HOME%\mavenrc_pre.cmd" call "%HOME%\mavenrc_pre.cmd"
49 | :skipRcPre
50 |
51 | @setlocal
52 |
53 | set ERROR_CODE=0
54 |
55 | @REM To isolate internal variables from possible post scripts, we use another setlocal
56 | @setlocal
57 |
58 | @REM ==== START VALIDATION ====
59 | if not "%JAVA_HOME%" == "" goto OkJHome
60 |
61 | echo.
62 | echo Error: JAVA_HOME not found in your environment. >&2
63 | echo Please set the JAVA_HOME variable in your environment to match the >&2
64 | echo location of your Java installation. >&2
65 | echo.
66 | goto error
67 |
68 | :OkJHome
69 | if exist "%JAVA_HOME%\bin\java.exe" goto init
70 |
71 | echo.
72 | echo Error: JAVA_HOME is set to an invalid directory. >&2
73 | echo JAVA_HOME = "%JAVA_HOME%" >&2
74 | echo Please set the JAVA_HOME variable in your environment to match the >&2
75 | echo location of your Java installation. >&2
76 | echo.
77 | goto error
78 |
79 | @REM ==== END VALIDATION ====
80 |
81 | :init
82 |
83 | @REM Find the project base dir, i.e. the directory that contains the folder ".mvn".
84 | @REM Fallback to current working directory if not found.
85 |
86 | set MAVEN_PROJECTBASEDIR=%MAVEN_BASEDIR%
87 | IF NOT "%MAVEN_PROJECTBASEDIR%"=="" goto endDetectBaseDir
88 |
89 | set EXEC_DIR=%CD%
90 | set WDIR=%EXEC_DIR%
91 | :findBaseDir
92 | IF EXIST "%WDIR%"\.mvn goto baseDirFound
93 | cd ..
94 | IF "%WDIR%"=="%CD%" goto baseDirNotFound
95 | set WDIR=%CD%
96 | goto findBaseDir
97 |
98 | :baseDirFound
99 | set MAVEN_PROJECTBASEDIR=%WDIR%
100 | cd "%EXEC_DIR%"
101 | goto endDetectBaseDir
102 |
103 | :baseDirNotFound
104 | set MAVEN_PROJECTBASEDIR=%EXEC_DIR%
105 | cd "%EXEC_DIR%"
106 |
107 | :endDetectBaseDir
108 |
109 | IF NOT EXIST "%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config" goto endReadAdditionalConfig
110 |
111 | @setlocal EnableExtensions EnableDelayedExpansion
112 | for /F "usebackq delims=" %%a in ("%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config") do set JVM_CONFIG_MAVEN_PROPS=!JVM_CONFIG_MAVEN_PROPS! %%a
113 | @endlocal & set JVM_CONFIG_MAVEN_PROPS=%JVM_CONFIG_MAVEN_PROPS%
114 |
115 | :endReadAdditionalConfig
116 |
117 | SET MAVEN_JAVA_EXE="%JAVA_HOME%\bin\java.exe"
118 |
119 | set WRAPPER_JAR="%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.jar"
120 | set WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain
121 |
122 | %MAVEN_JAVA_EXE% %JVM_CONFIG_MAVEN_PROPS% %MAVEN_OPTS% %MAVEN_DEBUG_OPTS% -classpath %WRAPPER_JAR% "-Dmaven.multiModuleProjectDirectory=%MAVEN_PROJECTBASEDIR%" %WRAPPER_LAUNCHER% %MAVEN_CONFIG% %*
123 | if ERRORLEVEL 1 goto error
124 | goto end
125 |
126 | :error
127 | set ERROR_CODE=1
128 |
129 | :end
130 | @endlocal & set ERROR_CODE=%ERROR_CODE%
131 |
132 | if not "%MAVEN_SKIP_RC%" == "" goto skipRcPost
133 | @REM check for post script, once with legacy .bat ending and once with .cmd ending
134 | if exist "%HOME%\mavenrc_post.bat" call "%HOME%\mavenrc_post.bat"
135 | if exist "%HOME%\mavenrc_post.cmd" call "%HOME%\mavenrc_post.cmd"
136 | :skipRcPost
137 |
138 | @REM pause the script if MAVEN_BATCH_PAUSE is set to 'on'
139 | if "%MAVEN_BATCH_PAUSE%" == "on" pause
140 |
141 | if "%MAVEN_TERMINATE_CMD%" == "on" exit %ERROR_CODE%
142 |
143 | exit /B %ERROR_CODE%
144 |
--------------------------------------------------------------------------------
/pom.xml:
--------------------------------------------------------------------------------
1 |
2 |
17 |
18 |
20 | 4.0.0
21 |
22 | bio.overture
23 | microservice-template
24 | 0.0.1-SNAPSHOT
25 | jar
26 |
27 | microservice-template
28 | Template project for resource microservices
29 |
30 |
31 | org.springframework.boot
32 | spring-boot-starter-parent
33 | 2.1.6.RELEASE
34 |
35 |
36 |
37 |
38 | UTF-8
39 | UTF-8
40 | 1.8
41 |
42 |
43 |
44 |
45 |
46 |
47 | org.springframework.boot
48 | spring-boot-starter-security
49 |
50 |
51 | org.springframework.security.oauth
52 | spring-security-oauth2
53 | 2.3.6.RELEASE
54 |
55 |
56 | org.springframework.boot
57 | spring-boot-starter-web
58 |
59 |
60 |
61 |
62 | org.projectlombok
63 | lombok
64 | true
65 |
66 |
67 |
68 |
69 | org.springframework.security
70 | spring-security-jwt
71 | 1.0.10.RELEASE
72 |
73 |
74 |
75 | com.fasterxml.jackson.core
76 | jackson-databind
77 |
78 |
79 |
80 |
81 | org.springframework.boot
82 | spring-boot-starter-test
83 | test
84 |
85 |
86 | org.springframework.security
87 | spring-security-test
88 | test
89 |
90 |
91 |
92 |
93 |
94 |
95 | org.springframework.boot
96 | spring-boot-maven-plugin
97 |
98 |
99 |
100 |
101 |
102 |
103 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/MicroserviceTemplateApplication.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate;
18 |
19 | import org.springframework.boot.SpringApplication;
20 | import org.springframework.boot.autoconfigure.SpringBootApplication;
21 |
22 | @SpringBootApplication
23 | public class MicroserviceTemplateApplication {
24 |
25 | public static void main(String[] args) {
26 | SpringApplication.run(MicroserviceTemplateApplication.class, args);
27 | }
28 |
29 | }
30 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/config/WebSecurityConfig.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.config;
18 |
19 | import bio.overture.microservicetemplate.jwt.JWTAuthorizationFilter;
20 | import bio.overture.microservicetemplate.jwt.JWTTokenConverter;
21 | import lombok.SneakyThrows;
22 | import lombok.val;
23 |
24 | import lombok.extern.slf4j.Slf4j;
25 | import org.springframework.beans.factory.annotation.Autowired;
26 | import org.springframework.beans.factory.annotation.Value;
27 | import org.springframework.context.annotation.Bean;
28 | import org.springframework.context.annotation.Primary;
29 | import org.springframework.core.io.ResourceLoader;
30 | import org.springframework.http.HttpMethod;
31 | import org.springframework.security.config.annotation.web.builders.HttpSecurity;
32 | import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
33 | import org.springframework.security.oauth2.config.annotation.web.configuration.EnableResourceServer;
34 | import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter;
35 | import org.springframework.security.oauth2.config.annotation.web.configurers.ResourceServerSecurityConfigurer;
36 | import org.springframework.security.oauth2.provider.token.DefaultTokenServices;
37 | import org.springframework.security.oauth2.provider.token.TokenStore;
38 | import org.springframework.security.oauth2.provider.token.store.JwtAccessTokenConverter;
39 | import org.springframework.security.oauth2.provider.token.store.JwtTokenStore;
40 | import org.springframework.security.web.authentication.www.BasicAuthenticationFilter;
41 |
42 | import java.io.BufferedReader;
43 | import java.io.InputStreamReader;
44 |
45 | @Slf4j
46 | @EnableWebSecurity
47 | @EnableResourceServer
48 | public class WebSecurityConfig extends ResourceServerConfigurerAdapter {
49 |
50 | @Autowired
51 | private ResourceLoader resourceLoader;
52 |
53 | @Value("${auth.jwt.publicKeyUrl}")
54 | private String publicKeyUrl;
55 |
56 | @Override
57 | @SneakyThrows
58 | public void configure(HttpSecurity http) {
59 | http
60 | .authorizeRequests()
61 | .antMatchers("/health").permitAll()
62 | .antMatchers("/isAlive").permitAll()
63 | .antMatchers("/upload/**").permitAll()
64 | .antMatchers("/download/**").permitAll()
65 | .antMatchers("/entities/**").permitAll()
66 | .antMatchers("/swagger**", "/swagger-resources/**", "/v2/api**", "/webjars/**").permitAll()
67 | .and()
68 | .authorizeRequests()
69 | .antMatchers(HttpMethod.POST).authenticated()
70 | .and()
71 | .authorizeRequests()
72 | .anyRequest().authenticated()
73 | .and()
74 | .addFilterAfter(new JWTAuthorizationFilter(), BasicAuthenticationFilter.class);
75 | }
76 |
77 | @Override
78 | public void configure(ResourceServerSecurityConfigurer config) {
79 | config.tokenServices(tokenServices());
80 | }
81 |
82 | @Bean
83 | public TokenStore tokenStore() {
84 | return new JwtTokenStore(accessTokenConverter());
85 | }
86 |
87 | @Bean
88 | @SneakyThrows
89 | public JwtAccessTokenConverter accessTokenConverter() {
90 | return new JWTTokenConverter(fetchJWTPublicKey());
91 | }
92 |
93 |
94 | @Bean
95 | @Primary
96 | public DefaultTokenServices tokenServices() {
97 | val defaultTokenServices = new DefaultTokenServices();
98 | defaultTokenServices.setTokenStore(tokenStore());
99 | return defaultTokenServices;
100 | }
101 |
102 | /**
103 | * Call EGO server for public key to use when verifying JWTs
104 | * Pass this value to the JWTTokenConverter
105 | */
106 | @SneakyThrows
107 | private String fetchJWTPublicKey() {
108 | val publicKeyResource = resourceLoader.getResource(publicKeyUrl);
109 |
110 | val stringBuilder = new StringBuilder();
111 | val reader = new BufferedReader(
112 | new InputStreamReader(publicKeyResource.getInputStream()));
113 |
114 | reader.lines().forEach(stringBuilder::append);
115 | return stringBuilder.toString();
116 | }
117 |
118 | }
119 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/controller/TestController.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.controller;
18 |
19 | import bio.overture.microservicetemplate.jwt.JWTFacadeInterface;
20 | import lombok.extern.slf4j.Slf4j;
21 | import lombok.val;
22 | import org.springframework.beans.factory.annotation.Autowired;
23 | import org.springframework.web.bind.annotation.GetMapping;
24 | import org.springframework.web.bind.annotation.PostMapping;
25 | import org.springframework.web.bind.annotation.RequestMapping;
26 | import org.springframework.web.bind.annotation.RestController;
27 |
28 |
29 | @Slf4j
30 | @RestController
31 | @RequestMapping("/test")
32 | public class TestController {
33 |
34 | @Autowired
35 | private JWTFacadeInterface jwtFacade;
36 |
37 | @GetMapping
38 | public String testGet() {
39 | val user = jwtFacade.getUser();
40 | val userName = user.isPresent() ? user.get().getFirstName() : "";
41 |
42 | return userName.isEmpty() ? "Hello there!" : "Good Morning " + userName + "!";
43 | }
44 |
45 | @PostMapping
46 | public String testPost() {
47 | val user = jwtFacade.getUser();
48 | val userName = user.isPresent() ? user.get().getFirstName() : "";
49 |
50 | return userName.isEmpty() ? "Greetings!" : "Good Afternoon " + userName + "!";
51 | }
52 |
53 | }
54 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/jwt/JWTAuthorizationFilter.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.jwt;
18 |
19 | import lombok.SneakyThrows;
20 | import lombok.extern.slf4j.Slf4j;
21 | import lombok.val;
22 | import org.springframework.security.core.context.SecurityContextHolder;
23 | import org.springframework.security.oauth2.provider.authentication.OAuth2AuthenticationDetails;
24 | import org.springframework.web.filter.GenericFilterBean;
25 |
26 | import javax.servlet.FilterChain;
27 | import javax.servlet.ServletRequest;
28 | import javax.servlet.ServletResponse;
29 |
30 | @Slf4j
31 | public class JWTAuthorizationFilter extends GenericFilterBean {
32 |
33 | private final String TYPE_ADMIN = "ADMIN";
34 | private final String TYPE_USER = "USER";
35 | private final String REQUIRED_TYPE = TYPE_ADMIN;
36 | private final String REQUIRED_STATUS = "Approved";
37 |
38 | @Override
39 | @SneakyThrows
40 | public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) {
41 | val authentication = SecurityContextHolder.getContext().getAuthentication();
42 | if(authentication != null) {
43 |
44 | val details = (OAuth2AuthenticationDetails) authentication.getDetails();
45 | val user = (JWTUser) details.getDecodedDetails();
46 |
47 | boolean hasCorrectRole = user.getType().equals(REQUIRED_TYPE);
48 | boolean hasCorrectStatus = user.getStatus().equalsIgnoreCase(REQUIRED_STATUS);
49 |
50 | if(!hasCorrectRole || !hasCorrectStatus) {
51 | SecurityContextHolder.clearContext();
52 | }
53 | }
54 |
55 | chain.doFilter(request, response);
56 | }
57 |
58 | }
59 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/jwt/JWTFacade.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.jwt;
18 |
19 | import lombok.val;
20 | import org.springframework.security.core.context.SecurityContextHolder;
21 | import org.springframework.security.oauth2.provider.authentication.OAuth2AuthenticationDetails;
22 | import org.springframework.stereotype.Component;
23 |
24 | import java.util.Optional;
25 |
26 | @Component
27 | public class JWTFacade implements JWTFacadeInterface {
28 |
29 | @Override
30 | public Optional getUser() {
31 | try {
32 | val details = (OAuth2AuthenticationDetails) SecurityContextHolder.getContext().getAuthentication().getDetails();
33 | val userDetails = (JWTUser) details.getDecodedDetails();
34 |
35 | return Optional.of(userDetails);
36 |
37 | } catch (Exception e) {
38 | return Optional.empty();
39 | }
40 |
41 | }
42 | }
43 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/jwt/JWTFacadeInterface.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.jwt;
18 |
19 | import java.util.Optional;
20 |
21 | public interface JWTFacadeInterface {
22 | Optional getUser();
23 | }
24 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/jwt/JWTTokenConverter.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.jwt;
18 |
19 | import bio.overture.microservicetemplate.utils.TypeUtils;
20 | import lombok.extern.slf4j.Slf4j;
21 | import lombok.val;
22 | import org.springframework.security.oauth2.provider.OAuth2Authentication;
23 | import org.springframework.security.oauth2.provider.token.store.JwtAccessTokenConverter;
24 |
25 | import java.util.Map;
26 |
27 | @Slf4j
28 | public class JWTTokenConverter extends JwtAccessTokenConverter {
29 |
30 | public JWTTokenConverter(String publicKey) {
31 | super();
32 | this.setVerifierKey(publicKey);
33 | }
34 |
35 | @Override
36 | public OAuth2Authentication extractAuthentication(Map map) {
37 | OAuth2Authentication authentication = super.extractAuthentication(map);
38 |
39 | val context = (Map)map.get("context");
40 | val user = (Map)context.get("user");
41 | val jwtUser = TypeUtils.convertType(user, JWTUser.class);
42 |
43 | authentication.setDetails(jwtUser);
44 |
45 | return authentication;
46 | }
47 |
48 | }
49 |
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/jwt/JWTUser.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.jwt;
18 |
19 | import lombok.Data;
20 |
21 | import java.util.List;
22 |
23 | @Data
24 | public class JWTUser {
25 |
26 | private String name;
27 | private String firstName;
28 | private String lastName;
29 | private String email;
30 | private String status;
31 | private String createdAt;
32 | private String lastLogin;
33 | private String preferredLanguage;
34 | private String type;
35 | private List permissions;
36 |
37 | }
--------------------------------------------------------------------------------
/src/main/java/bio/overture/microservicetemplate/utils/TypeUtils.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate.utils;
18 |
19 | import com.fasterxml.jackson.core.JsonGenerator;
20 | import com.fasterxml.jackson.databind.ObjectMapper;
21 | import lombok.val;
22 |
23 |
24 | public class TypeUtils {
25 | public static T convertType(Object fromObject, Class tClass){
26 | val mapper = new ObjectMapper();
27 | mapper.configure(JsonGenerator.Feature.IGNORE_UNKNOWN, true);
28 | return mapper.convertValue(fromObject, tClass);
29 | }
30 | }
31 |
--------------------------------------------------------------------------------
/src/main/resources/application.yml:
--------------------------------------------------------------------------------
1 | server:
2 | port: 1234
3 |
4 | auth:
5 | jwt:
6 | publicKeyUrl: "http://localhost:8081/oauth/token/public_key"
--------------------------------------------------------------------------------
/src/test/java/bio/overture/microservicetemplate/MicroserviceTemplateApplicationTests.java:
--------------------------------------------------------------------------------
1 | /*
2 | * Copyright (c) 2017. The Ontario Institute for Cancer Research. All rights reserved.
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package bio.overture.microservicetemplate;
18 |
19 | import org.junit.Test;
20 | import org.junit.runner.RunWith;
21 | import org.springframework.boot.test.context.SpringBootTest;
22 | import org.springframework.test.context.junit4.SpringRunner;
23 |
24 | @RunWith(SpringRunner.class)
25 | @SpringBootTest
26 | public class MicroserviceTemplateApplicationTests {
27 |
28 | @Test
29 | public void contextLoads() {
30 | // Passes if application starts
31 | assert(true);
32 | }
33 |
34 | }
35 |
--------------------------------------------------------------------------------