├── .gitignore
├── LICENSE
├── README.md
├── pom.xml
└── src
├── main
├── java
│ └── com
│ │ └── example
│ │ ├── MultitenancyMySqlApplication.java
│ │ ├── model
│ │ ├── CustomUserDetails.java
│ │ ├── Employee.java
│ │ ├── Role.java
│ │ └── User.java
│ │ ├── multitenancy
│ │ ├── CurrentTenantIdentifierResolverImpl.java
│ │ ├── DataSourceBasedMultiTenantConnectionProviderImpl.java
│ │ ├── MultiTenancyJpaConfiguration.java
│ │ └── MultitenancyProperties.java
│ │ ├── repository
│ │ ├── RoleRepository.java
│ │ └── UserRepository.java
│ │ ├── security
│ │ ├── CustomAuthenticationFilter.java
│ │ ├── CustomAuthenticationToken.java
│ │ ├── CustomSecurityConfig.java
│ │ ├── CustomUserDetailsAuthenticationProvider.java
│ │ ├── CustomUserDetailsService.java
│ │ └── CustomUserDetailsServiceImpl.java
│ │ ├── service
│ │ ├── RoleService.java
│ │ ├── RoleServiceImpl.java
│ │ ├── UserService.java
│ │ └── UserServiceImpl.java
│ │ ├── util
│ │ └── TenantContextHolder.java
│ │ └── web
│ │ └── LoginController.java
└── resources
│ ├── application.yml
│ ├── static
│ └── css
│ │ └── main.css
│ └── templates
│ ├── index.html
│ ├── login.html
│ └── user
│ └── index.html
└── test
└── java
└── com
└── example
└── MultitenancyMySqlApplicationTests.java
/.gitignore:
--------------------------------------------------------------------------------
1 | target/
2 | !.mvn/wrapper/maven-wrapper.jar
3 |
4 | ### STS ###
5 | .apt_generated
6 | .classpath
7 | .factorypath
8 | .project
9 | .settings
10 | .springBeans
11 | .sts4-cache
12 |
13 | ### IntelliJ IDEA ###
14 | .idea
15 | *.iws
16 | *.iml
17 | *.ipr
18 |
19 | ### NetBeans ###
20 | nbproject/private/
21 | build/
22 | nbbuild/
23 | dist/
24 | nbdist/
25 | .nb-gradle/
--------------------------------------------------------------------------------
/LICENSE:
--------------------------------------------------------------------------------
1 | Apache License
2 | Version 2.0, January 2004
3 | http://www.apache.org/licenses/
4 |
5 | TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
6 |
7 | 1. Definitions.
8 |
9 | "License" shall mean the terms and conditions for use, reproduction,
10 | and distribution as defined by Sections 1 through 9 of this document.
11 |
12 | "Licensor" shall mean the copyright owner or entity authorized by
13 | the copyright owner that is granting the License.
14 |
15 | "Legal Entity" shall mean the union of the acting entity and all
16 | other entities that control, are controlled by, or are under common
17 | control with that entity. For the purposes of this definition,
18 | "control" means (i) the power, direct or indirect, to cause the
19 | direction or management of such entity, whether by contract or
20 | otherwise, or (ii) ownership of fifty percent (50%) or more of the
21 | outstanding shares, or (iii) beneficial ownership of such entity.
22 |
23 | "You" (or "Your") shall mean an individual or Legal Entity
24 | exercising permissions granted by this License.
25 |
26 | "Source" form shall mean the preferred form for making modifications,
27 | including but not limited to software source code, documentation
28 | source, and configuration files.
29 |
30 | "Object" form shall mean any form resulting from mechanical
31 | transformation or translation of a Source form, including but
32 | not limited to compiled object code, generated documentation,
33 | and conversions to other media types.
34 |
35 | "Work" shall mean the work of authorship, whether in Source or
36 | Object form, made available under the License, as indicated by a
37 | copyright notice that is included in or attached to the work
38 | (an example is provided in the Appendix below).
39 |
40 | "Derivative Works" shall mean any work, whether in Source or Object
41 | form, that is based on (or derived from) the Work and for which the
42 | editorial revisions, annotations, elaborations, or other modifications
43 | represent, as a whole, an original work of authorship. For the purposes
44 | of this License, Derivative Works shall not include works that remain
45 | separable from, or merely link (or bind by name) to the interfaces of,
46 | the Work and Derivative Works thereof.
47 |
48 | "Contribution" shall mean any work of authorship, including
49 | the original version of the Work and any modifications or additions
50 | to that Work or Derivative Works thereof, that is intentionally
51 | submitted to Licensor for inclusion in the Work by the copyright owner
52 | or by an individual or Legal Entity authorized to submit on behalf of
53 | the copyright owner. For the purposes of this definition, "submitted"
54 | means any form of electronic, verbal, or written communication sent
55 | to the Licensor or its representatives, including but not limited to
56 | communication on electronic mailing lists, source code control systems,
57 | and issue tracking systems that are managed by, or on behalf of, the
58 | Licensor for the purpose of discussing and improving the Work, but
59 | excluding communication that is conspicuously marked or otherwise
60 | designated in writing by the copyright owner as "Not a Contribution."
61 |
62 | "Contributor" shall mean Licensor and any individual or Legal Entity
63 | on behalf of whom a Contribution has been received by Licensor and
64 | subsequently incorporated within the Work.
65 |
66 | 2. Grant of Copyright License. Subject to the terms and conditions of
67 | this License, each Contributor hereby grants to You a perpetual,
68 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
69 | copyright license to reproduce, prepare Derivative Works of,
70 | publicly display, publicly perform, sublicense, and distribute the
71 | Work and such Derivative Works in Source or Object form.
72 |
73 | 3. Grant of Patent License. Subject to the terms and conditions of
74 | this License, each Contributor hereby grants to You a perpetual,
75 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
76 | (except as stated in this section) patent license to make, have made,
77 | use, offer to sell, sell, import, and otherwise transfer the Work,
78 | where such license applies only to those patent claims licensable
79 | by such Contributor that are necessarily infringed by their
80 | Contribution(s) alone or by combination of their Contribution(s)
81 | with the Work to which such Contribution(s) was submitted. If You
82 | institute patent litigation against any entity (including a
83 | cross-claim or counterclaim in a lawsuit) alleging that the Work
84 | or a Contribution incorporated within the Work constitutes direct
85 | or contributory patent infringement, then any patent licenses
86 | granted to You under this License for that Work shall terminate
87 | as of the date such litigation is filed.
88 |
89 | 4. Redistribution. You may reproduce and distribute copies of the
90 | Work or Derivative Works thereof in any medium, with or without
91 | modifications, and in Source or Object form, provided that You
92 | meet the following conditions:
93 |
94 | (a) You must give any other recipients of the Work or
95 | Derivative Works a copy of this License; and
96 |
97 | (b) You must cause any modified files to carry prominent notices
98 | stating that You changed the files; and
99 |
100 | (c) You must retain, in the Source form of any Derivative Works
101 | that You distribute, all copyright, patent, trademark, and
102 | attribution notices from the Source form of the Work,
103 | excluding those notices that do not pertain to any part of
104 | the Derivative Works; and
105 |
106 | (d) If the Work includes a "NOTICE" text file as part of its
107 | distribution, then any Derivative Works that You distribute must
108 | include a readable copy of the attribution notices contained
109 | within such NOTICE file, excluding those notices that do not
110 | pertain to any part of the Derivative Works, in at least one
111 | of the following places: within a NOTICE text file distributed
112 | as part of the Derivative Works; within the Source form or
113 | documentation, if provided along with the Derivative Works; or,
114 | within a display generated by the Derivative Works, if and
115 | wherever such third-party notices normally appear. The contents
116 | of the NOTICE file are for informational purposes only and
117 | do not modify the License. You may add Your own attribution
118 | notices within Derivative Works that You distribute, alongside
119 | or as an addendum to the NOTICE text from the Work, provided
120 | that such additional attribution notices cannot be construed
121 | as modifying the License.
122 |
123 | You may add Your own copyright statement to Your modifications and
124 | may provide additional or different license terms and conditions
125 | for use, reproduction, or distribution of Your modifications, or
126 | for any such Derivative Works as a whole, provided Your use,
127 | reproduction, and distribution of the Work otherwise complies with
128 | the conditions stated in this License.
129 |
130 | 5. Submission of Contributions. Unless You explicitly state otherwise,
131 | any Contribution intentionally submitted for inclusion in the Work
132 | by You to the Licensor shall be under the terms and conditions of
133 | this License, without any additional terms or conditions.
134 | Notwithstanding the above, nothing herein shall supersede or modify
135 | the terms of any separate license agreement you may have executed
136 | with Licensor regarding such Contributions.
137 |
138 | 6. Trademarks. This License does not grant permission to use the trade
139 | names, trademarks, service marks, or product names of the Licensor,
140 | except as required for reasonable and customary use in describing the
141 | origin of the Work and reproducing the content of the NOTICE file.
142 |
143 | 7. Disclaimer of Warranty. Unless required by applicable law or
144 | agreed to in writing, Licensor provides the Work (and each
145 | Contributor provides its Contributions) on an "AS IS" BASIS,
146 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
147 | implied, including, without limitation, any warranties or conditions
148 | of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
149 | PARTICULAR PURPOSE. You are solely responsible for determining the
150 | appropriateness of using or redistributing the Work and assume any
151 | risks associated with Your exercise of permissions under this License.
152 |
153 | 8. Limitation of Liability. In no event and under no legal theory,
154 | whether in tort (including negligence), contract, or otherwise,
155 | unless required by applicable law (such as deliberate and grossly
156 | negligent acts) or agreed to in writing, shall any Contributor be
157 | liable to You for damages, including any direct, indirect, special,
158 | incidental, or consequential damages of any character arising as a
159 | result of this License or out of the use or inability to use the
160 | Work (including but not limited to damages for loss of goodwill,
161 | work stoppage, computer failure or malfunction, or any and all
162 | other commercial damages or losses), even if such Contributor
163 | has been advised of the possibility of such damages.
164 |
165 | 9. Accepting Warranty or Additional Liability. While redistributing
166 | the Work or Derivative Works thereof, You may choose to offer,
167 | and charge a fee for, acceptance of support, warranty, indemnity,
168 | or other liability obligations and/or rights consistent with this
169 | License. However, in accepting such obligations, You may act only
170 | on Your own behalf and on Your sole responsibility, not on behalf
171 | of any other Contributor, and only if You agree to indemnify,
172 | defend, and hold each Contributor harmless for any liability
173 | incurred by, or claims asserted against, such Contributor by reason
174 | of your accepting any such warranty or additional liability.
175 |
176 | END OF TERMS AND CONDITIONS
177 |
178 | APPENDIX: How to apply the Apache License to your work.
179 |
180 | To apply the Apache License to your work, attach the following
181 | boilerplate notice, with the fields enclosed by brackets "[]"
182 | replaced with your own identifying information. (Don't include
183 | the brackets!) The text should be enclosed in the appropriate
184 | comment syntax for the file format. We also recommend that a
185 | file or class name and description of purpose be included on the
186 | same "printed page" as the copyright notice for easier
187 | identification within third-party archives.
188 |
189 | Copyright [yyyy] [name of copyright owner]
190 |
191 | Licensed under the Apache License, Version 2.0 (the "License");
192 | you may not use this file except in compliance with the License.
193 | You may obtain a copy of the License at
194 |
195 | http://www.apache.org/licenses/LICENSE-2.0
196 |
197 | Unless required by applicable law or agreed to in writing, software
198 | distributed under the License is distributed on an "AS IS" BASIS,
199 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
200 | See the License for the specific language governing permissions and
201 | limitations under the License.
202 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # Saas style database per tenant multitenancy with Spring Boot 2 and Spring Security 5
2 | SaaS application style multi-tenancy with database per tenant using Spring Boot 2 + JPA + Hibernate + Spring Security 5. This app
3 | is built with MySQL as the database. It can be adapted to use any other database like Microsoft SQL Server.
4 |
5 | This repository contains code which accompanies the blog post [Building SaaS style multi-tenant web app with Spring Boot 2 and Spring Security 5](https://sunitkatkar.blogspot.com/2018/04/building-saas-style-multi-tenant-web2.html)
6 |
7 | ## Getting Started
8 |
9 | This is a typical maven project. Download the source as a zip file or checkout the code
10 | and import as an Existing Maven project in your IDE.
11 |
12 | ### Prerequisites
13 |
14 | * Java 8
15 | * Spring Boot 2
16 | * MySQL
17 | * Not mandatory, but you can use any suitable IDE like Spring STS
18 |
19 |
20 | ## Authors
21 |
22 | * **Sunit Katkar** - *Initial work* - [Sunit Katkar](https://sunitkatkar.blogspot.com/)
23 |
24 |
25 |
26 | ## License
27 |
28 | This project is licensed under the Apache License - see the [LICENSE.md](LICENSE.md) file for details
29 |
30 | ## Request
31 | You are free to fork this repository, but please drop me a note at sunitkatkar@gmail.com
32 |
--------------------------------------------------------------------------------
/pom.xml:
--------------------------------------------------------------------------------
1 |
2 | tenant
to store the tenant name submitted by the end
47 | * user.
48 | *
49 | * @param username
50 | * @param password
51 | * @param authorities
52 | * @param tenant
53 | */
54 | public CustomUserDetails(String username, String password, Collection extends GrantedAuthority> authorities,
55 | String tenant) {
56 | super(username, password, authorities);
57 | this.tenant = tenant;
58 | }
59 |
60 | // Getters and Setters
61 | public String getTenant() {
62 | return tenant;
63 | }
64 |
65 | public void setTenant(String tenant) {
66 | this.tenant = tenant;
67 | }
68 |
69 | }
70 |
--------------------------------------------------------------------------------
/src/main/java/com/example/model/Employee.java:
--------------------------------------------------------------------------------
1 | /**
2 | * Copyright 2018 onwards - Sunit Katkar (sunitkatkar@gmail.com)
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package com.example.model;
18 |
19 | import javax.persistence.Column;
20 | import javax.persistence.Entity;
21 | import javax.persistence.GeneratedValue;
22 | import javax.persistence.GenerationType;
23 | import javax.persistence.Id;
24 | import javax.persistence.Table;
25 |
26 | /**
27 | * Just a regular entity which will be stored in all tenant databases.
28 | *
29 | * @author Sunit Katkar
30 | * @version 1.0
31 | * @since 1.0 (April 2018)
32 | */
33 | @Entity
34 | @Table(name = "employee")
35 | public class Employee {
36 |
37 | @Id
38 | @GeneratedValue(strategy = GenerationType.AUTO)
39 | @Column(name = "id", nullable = false, unique = true)
40 | private Long id;
41 |
42 | @Column(name = "first_name")
43 | private String firstName;
44 |
45 | @Column(name = "last_name")
46 | private String lastName;
47 |
48 | @Column(name = "department")
49 | private String department;
50 |
51 | private String office;
52 |
53 | public Long getId() {
54 | return id;
55 | }
56 |
57 | public void setId(Long id) {
58 | this.id = id;
59 | }
60 |
61 | public String getFirstName() {
62 | return firstName;
63 | }
64 |
65 | public void setFirstName(String firstName) {
66 | this.firstName = firstName;
67 | }
68 |
69 | public String getLastName() {
70 | return lastName;
71 | }
72 |
73 | public void setLastName(String lastName) {
74 | this.lastName = lastName;
75 | }
76 |
77 | public String getDepartment() {
78 | return department;
79 | }
80 |
81 | public void setDepartment(String department) {
82 | this.department = department;
83 | }
84 |
85 | public String getOffice() {
86 | return office;
87 | }
88 |
89 | public void setOffice(String office) {
90 | this.office = office;
91 | }
92 |
93 | @Override
94 | public int hashCode() {
95 | final int prime = 31;
96 | int result = 1;
97 | result = prime * result + ((department == null) ? 0 : department.hashCode());
98 | result = prime * result + ((firstName == null) ? 0 : firstName.hashCode());
99 | result = prime * result + ((id == null) ? 0 : id.hashCode());
100 | result = prime * result + ((lastName == null) ? 0 : lastName.hashCode());
101 | result = prime * result + ((office == null) ? 0 : office.hashCode());
102 | return result;
103 | }
104 |
105 | @Override
106 | public boolean equals(Object obj) {
107 | if (this == obj)
108 | return true;
109 | if (obj == null)
110 | return false;
111 | if (getClass() != obj.getClass())
112 | return false;
113 | Employee other = (Employee) obj;
114 | if (department == null) {
115 | if (other.department != null)
116 | return false;
117 | } else if (!department.equals(other.department))
118 | return false;
119 | if (firstName == null) {
120 | if (other.firstName != null)
121 | return false;
122 | } else if (!firstName.equals(other.firstName))
123 | return false;
124 | if (id == null) {
125 | if (other.id != null)
126 | return false;
127 | } else if (!id.equals(other.id))
128 | return false;
129 | if (lastName == null) {
130 | if (other.lastName != null)
131 | return false;
132 | } else if (!lastName.equals(other.lastName))
133 | return false;
134 | if (office == null) {
135 | if (other.office != null)
136 | return false;
137 | } else if (!office.equals(other.office))
138 | return false;
139 | return true;
140 | }
141 |
142 | /*
143 | * (non-Javadoc)
144 | *
145 | * @see java.lang.Object#toString()
146 | */
147 | @Override
148 | public String toString() {
149 | StringBuilder builder = new StringBuilder();
150 | builder.append("Employee [id=").append(id).append(", firstName=").append(firstName).append(", lastName=")
151 | .append(lastName).append(", department=").append(department).append(", office=").append(office)
152 | .append("]");
153 | return builder.toString();
154 | }
155 |
156 | }
157 |
--------------------------------------------------------------------------------
/src/main/java/com/example/model/Role.java:
--------------------------------------------------------------------------------
1 | /**
2 | * Copyright 2018 onwards - Sunit Katkar (sunitkatkar@gmail.com)
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package com.example.model;
18 |
19 | import java.io.Serializable;
20 | import java.util.Set;
21 |
22 | import javax.persistence.Column;
23 | import javax.persistence.Entity;
24 | import javax.persistence.FetchType;
25 | import javax.persistence.GeneratedValue;
26 | import javax.persistence.GenerationType;
27 | import javax.persistence.Id;
28 | import javax.persistence.ManyToMany;
29 | import javax.persistence.Table;
30 |
31 | /**
32 | * Role entity to represent a ROLE of the {@link User} in the system.
33 | *
34 | * The JPA definitions of {@link User} and {@link Role} will cause the following
35 | * 3 tables to be created:
36 | *
multitenancy.mtapp
node from
26 | * application.yml
file and populates a list of
27 | * {@link org.springframework.boot.autoconfigure.jdbc.DataSourceProperties}
28 | * objects, with each instance containing the data source details about the
29 | * database like url, username, password etc
30 | *
31 | * @author Sunit Katkar
32 | * @version 1.0
33 | * @since 1.0 (April 2018)
34 | */
35 | @Configuration
36 | @ConfigurationProperties("multitenancy.mtapp")
37 | public class MultitenancyProperties {
38 |
39 | private Listtenant
field
28 | * extracted by the {@link CustomAuthenticationFilter} from the user submitted
29 | * login form.
30 | *
31 | * @author Sunit Katkar
32 | * @version 1.0
33 | * @since 1.0 (April 2018)
34 | */
35 | public class CustomAuthenticationToken extends UsernamePasswordAuthenticationToken {
36 |
37 | private static final long serialVersionUID = 1L;
38 |
39 | /**
40 | * The tenant i.e. database identifier
41 | */
42 | private String tenant;
43 |
44 | /**
45 | * @param principal
46 | * @param credentials
47 | * @param tenant
48 | */
49 | public CustomAuthenticationToken(Object principal, Object credentials, String tenant) {
50 | super(principal, credentials);
51 | this.tenant = tenant;
52 | super.setAuthenticated(false);
53 | }
54 |
55 | /**
56 | * @param principal
57 | * @param credentials
58 | * @param tenant
59 | * @param authorities
60 | */
61 | public CustomAuthenticationToken(Object principal, Object credentials, String tenant,
62 | Collection extends GrantedAuthority> authorities) {
63 | super(principal, credentials, authorities);
64 | this.tenant = tenant;
65 | super.setAuthenticated(true); // must use super, as we override
66 | }
67 |
68 | public String getTenant() {
69 | return this.tenant;
70 | }
71 | }
--------------------------------------------------------------------------------
/src/main/java/com/example/security/CustomSecurityConfig.java:
--------------------------------------------------------------------------------
1 | /**
2 | * Copyright 2018 onwards - Sunit Katkar (sunitkatkar@gmail.com)
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package com.example.security;
18 |
19 | import org.springframework.beans.factory.annotation.Autowired;
20 | import org.springframework.context.annotation.Bean;
21 | import org.springframework.context.annotation.Configuration;
22 | import org.springframework.security.authentication.AuthenticationProvider;
23 | import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
24 | import org.springframework.security.config.annotation.web.builders.HttpSecurity;
25 | import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
26 | import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
27 | import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
28 | import org.springframework.security.crypto.password.PasswordEncoder;
29 | import org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler;
30 | import org.springframework.security.web.authentication.SimpleUrlAuthenticationSuccessHandler;
31 | import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;
32 |
33 | /**
34 | * Configuration of security related beans and methods. The access to different
35 | * urls within the application is defined here.
36 | *
37 | * @author Sunit Katkar
38 | * @version 1.0
39 | * @since 1.0 (April 2018)
40 | *
41 | */
42 | @Configuration
43 | @EnableWebSecurity
44 | public class CustomSecurityConfig extends WebSecurityConfigurerAdapter {
45 |
46 | @Autowired
47 | private CustomUserDetailsService userDetailsService;
48 |
49 | /**
50 | * This is where access to various resources (urls) in the application is
51 | * defined
52 | */
53 | @Override
54 | protected void configure(HttpSecurity http) throws Exception {
55 | //@formatter:off
56 | http
57 | .addFilterBefore(authenticationFilter(), UsernamePasswordAuthenticationFilter.class)
58 | .authorizeRequests()
59 | .antMatchers("/css/**", "/index").permitAll()
60 | .antMatchers("/user/**").authenticated()
61 | .and()
62 | .formLogin().loginPage("/login")
63 | .and()
64 | .logout()
65 | .logoutUrl("/logout");
66 | //@formatter:on
67 | }
68 |
69 | /**
70 | * Create an instance of the custom authentication filter which intercepts and
71 | * processes the end user's login form submission for further authentication
72 | * processing. This filter is added before other filters so that it can
73 | * intercept the user login form submission and extract the the additional
74 | * 'tenant' field
75 | *
76 | * @return
77 | * @throws Exception
78 | */
79 | public CustomAuthenticationFilter authenticationFilter() throws Exception {
80 | CustomAuthenticationFilter filter = new CustomAuthenticationFilter();
81 | filter.setAuthenticationManager(authenticationManagerBean());
82 | filter.setAuthenticationFailureHandler(failureHandler());
83 | filter.setAuthenticationSuccessHandler(successHandler());
84 | return filter;
85 | }
86 |
87 | @Autowired
88 | public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
89 | auth.authenticationProvider(authProvider());
90 | }
91 |
92 | /**
93 | * Authentication provider which provides the logged in user's credentials for
94 | * verification and authentication if they are coeect
95 | *
96 | * @return
97 | */
98 | public AuthenticationProvider authProvider() {
99 | // The custom authentication provider defined for this app
100 | CustomUserDetailsAuthenticationProvider provider = new CustomUserDetailsAuthenticationProvider(
101 | passwordEncoder(), userDetailsService);
102 | return provider;
103 | }
104 |
105 | /**
106 | * The page to show if authentication fails
107 | *
108 | * @return
109 | */
110 | public SimpleUrlAuthenticationFailureHandler failureHandler() {
111 | return new SimpleUrlAuthenticationFailureHandler("/login?error=true");
112 | }
113 |
114 | public SimpleUrlAuthenticationSuccessHandler successHandler() {
115 | return new SimpleUrlAuthenticationSuccessHandler("/user/index");
116 | }
117 |
118 | @Bean(name = "passwordEncoder")
119 | public PasswordEncoder passwordEncoder() {
120 | return new BCryptPasswordEncoder();
121 | }
122 |
123 | }
124 |
--------------------------------------------------------------------------------
/src/main/java/com/example/security/CustomUserDetailsAuthenticationProvider.java:
--------------------------------------------------------------------------------
1 | /**
2 | * Copyright 2018 onwards - Sunit Katkar (sunitkatkar@gmail.com)
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package com.example.security;
18 |
19 | import org.springframework.security.authentication.BadCredentialsException;
20 | import org.springframework.security.authentication.InternalAuthenticationServiceException;
21 | import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
22 | import org.springframework.security.authentication.dao.AbstractUserDetailsAuthenticationProvider;
23 | import org.springframework.security.core.AuthenticationException;
24 | import org.springframework.security.core.userdetails.UserDetails;
25 | import org.springframework.security.core.userdetails.UsernameNotFoundException;
26 | import org.springframework.security.crypto.password.PasswordEncoder;
27 | import org.springframework.util.Assert;
28 |
29 | /**
30 | * {@link CustomUserDetailsAuthenticationProvider} extends
31 | * {@link AbstractUserDetailsAuthenticationProvider} and delegates to the
32 | * {@link CustomUserDetailService} to retrieve the User. The most important
33 | * feature of this class is the implementation of the retrieveUser
34 | * method.
35 | *
36 | * Note that the authentication token must be cast to CustomAuthenticationToken
37 | * to access the custom field - tenant
38 | *
39 | *
40 | * @author Sunit Katkar
41 | * @version 1.0
42 | * @since 1.0 (April 2018)
43 | */
44 | public class CustomUserDetailsAuthenticationProvider
45 | extends AbstractUserDetailsAuthenticationProvider {
46 |
47 | /**
48 | * The plaintext password used to perform PasswordEncoder#matches(CharSequence,
49 | * String)} on when the user is not found to avoid SEC-2056
50 | * (https://github.com/spring-projects/spring-security/issues/2280).
51 | */
52 | private static final String USER_NOT_FOUND_PASSWORD = "userNotFoundPassword";
53 |
54 | /**
55 | * For encoding and/or matching the encrypted password stored in the database
56 | * with the user submitted password
57 | */
58 | private PasswordEncoder passwordEncoder;
59 |
60 | private CustomUserDetailsService userDetailsService;
61 |
62 | /**
63 | * The password used to perform
64 | * {@link PasswordEncoder#matches(CharSequence, String)} on when the user is not
65 | * found to avoid SEC-2056. This is necessary, because some
66 | * {@link PasswordEncoder} implementations will short circuit if the password is
67 | * not in a valid format.
68 | */
69 | private String userNotFoundEncodedPassword;
70 |
71 | public CustomUserDetailsAuthenticationProvider(PasswordEncoder passwordEncoder,
72 | CustomUserDetailsService userDetailsService) {
73 | this.passwordEncoder = passwordEncoder;
74 | this.userDetailsService = userDetailsService;
75 | }
76 |
77 | /*
78 | * (non-Javadoc)
79 | *
80 | * @see org.springframework.security.authentication.dao.
81 | * AbstractUserDetailsAuthenticationProvider#additionalAuthenticationChecks(org.
82 | * springframework.security.core.userdetails.UserDetails,
83 | * org.springframework.security.authentication.
84 | * UsernamePasswordAuthenticationToken)
85 | */
86 | @Override
87 | protected void additionalAuthenticationChecks(UserDetails userDetails,
88 | UsernamePasswordAuthenticationToken authentication) throws AuthenticationException {
89 |
90 | if (authentication.getCredentials() == null) {
91 | logger.debug("Authentication failed: no credentials provided");
92 | throw new BadCredentialsException(
93 | messages.getMessage("AbstractUserDetailsAuthenticationProvider.badCredentials",
94 | "Bad credentials"));
95 | }
96 | // Get the password submitted by the end user
97 | String presentedPassword = authentication.getCredentials().toString();
98 |
99 | // If the password stored in the database and the user submitted password do not
100 | // match, then signal a login error
101 | if (!passwordEncoder.matches(presentedPassword, userDetails.getPassword())) {
102 | logger.debug("Authentication failed: password does not match stored value");
103 | throw new BadCredentialsException(
104 | messages.getMessage("AbstractUserDetailsAuthenticationProvider.badCredentials",
105 | "Bad credentials"));
106 | }
107 | }
108 |
109 | @Override
110 | protected void doAfterPropertiesSet() throws Exception {
111 | Assert.notNull(this.userDetailsService, "A UserDetailsService must be set");
112 | this.userNotFoundEncodedPassword = this.passwordEncoder.encode(USER_NOT_FOUND_PASSWORD);
113 | }
114 |
115 | /*
116 | * (non-Javadoc)
117 | *
118 | * @see org.springframework.security.authentication.dao.
119 | * AbstractUserDetailsAuthenticationProvider#retrieveUser(java.lang.String,
120 | * org.springframework.security.authentication.
121 | * UsernamePasswordAuthenticationToken)
122 | */
123 | @Override
124 | protected UserDetails retrieveUser(String username, UsernamePasswordAuthenticationToken authentication)
125 | throws AuthenticationException {
126 | CustomAuthenticationToken auth = (CustomAuthenticationToken) authentication;
127 | UserDetails loadedUser;
128 |
129 | try {
130 | loadedUser = this.userDetailsService
131 | .loadUserByUsernameAndTenantname(auth.getPrincipal().toString(),
132 | auth.getTenant());
133 | } catch (UsernameNotFoundException notFound) {
134 | if (authentication.getCredentials() != null) {
135 | String presentedPassword = authentication.getCredentials().toString();
136 | passwordEncoder.matches(presentedPassword, userNotFoundEncodedPassword);
137 | }
138 | throw notFound;
139 | } catch (Exception repositoryProblem) {
140 | throw new InternalAuthenticationServiceException(repositoryProblem.getMessage(),
141 | repositoryProblem);
142 | }
143 |
144 | if (loadedUser == null) {
145 | throw new InternalAuthenticationServiceException(
146 | "UserDetailsService returned null, "
147 | + "which is an interface contract violation");
148 | }
149 | return loadedUser;
150 | }
151 | }
--------------------------------------------------------------------------------
/src/main/java/com/example/security/CustomUserDetailsService.java:
--------------------------------------------------------------------------------
1 | /**
2 | * Copyright 2018 onwards - Sunit Katkar (sunitkatkar@gmail.com)
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package com.example.security;
18 |
19 | import org.springframework.security.core.userdetails.UserDetails;
20 | import org.springframework.security.core.userdetails.UsernameNotFoundException;
21 |
22 | /**
23 | * @author Sunit Katkar
24 | * @version 1.0
25 | * @since 1.0 (April 2018)
26 | *
27 | */
28 | public interface CustomUserDetailsService {
29 |
30 | UserDetails loadUserByUsernameAndTenantname(String username, String tenantName) throws UsernameNotFoundException;
31 | }
32 |
--------------------------------------------------------------------------------
/src/main/java/com/example/security/CustomUserDetailsServiceImpl.java:
--------------------------------------------------------------------------------
1 | /**
2 | * Copyright 2018 onwards - Sunit Katkar (sunitkatkar@gmail.com)
3 | *
4 | * Licensed under the Apache License, Version 2.0 (the "License");
5 | * you may not use this file except in compliance with the License.
6 | * You may obtain a copy of the License at
7 | *
8 | * http://www.apache.org/licenses/LICENSE-2.0
9 | *
10 | * Unless required by applicable law or agreed to in writing, software
11 | * distributed under the License is distributed on an "AS IS" BASIS,
12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | * See the License for the specific language governing permissions and
14 | * limitations under the License.
15 | */
16 |
17 | package com.example.security;
18 |
19 | import java.util.HashSet;
20 | import java.util.Set;
21 |
22 | import org.apache.commons.lang3.StringUtils;
23 | import org.springframework.beans.factory.annotation.Autowired;
24 | import org.springframework.security.core.GrantedAuthority;
25 | import org.springframework.security.core.authority.SimpleGrantedAuthority;
26 | import org.springframework.security.core.userdetails.UserDetails;
27 | import org.springframework.security.core.userdetails.UsernameNotFoundException;
28 | import org.springframework.stereotype.Service;
29 |
30 | import com.example.model.CustomUserDetails;
31 | import com.example.model.Role;
32 | import com.example.model.User;
33 | import com.example.service.UserService;
34 |
35 | /**
36 | * {@link CustomUserDetailsService} contract defines a single method called
37 | * loadUserByUsernameAndTenantname.
38 | *
39 | * The {@link CustomUserDetailsServiceImpl} class simply implements the contract
40 | * and delegates to {@link UserService} to get the
41 | * {@link com.example.model.User} from the database so that it can be compared
42 | * with the {@link org.springframework.security.core.userdetails.User} for
43 | * authentication. Authentication occurs via the
44 | * {@link CustomUserDetailsAuthenticationProvider}.
45 | *
46 | * @author Sunit Katkar
47 | * @version 1.0
48 | * @since 1.0 (April 2018)
49 | *
50 | */
51 | @Service("userDetailsService")
52 | public class CustomUserDetailsServiceImpl implements CustomUserDetailsService {
53 |
54 | @Autowired
55 | private UserService userService;
56 |
57 | @Override
58 | public UserDetails loadUserByUsernameAndTenantname(String username, String tenant)
59 | throws UsernameNotFoundException {
60 | if (StringUtils.isAnyBlank(username, tenant)) {
61 | throw new UsernameNotFoundException("Username and domain must be provided");
62 | }
63 | // Look for the user based on the username and tenant by accessing the
64 | // UserRepository via the UserService
65 | User user = userService.findByUsernameAndTenantname(username, tenant);
66 |
67 | if (user == null) {
68 | throw new UsernameNotFoundException(
69 | String.format("Username not found for domain, "
70 | + "username=%s, tenant=%s", username, tenant));
71 | }
72 |
73 | SetLogged in: Username | | Some Domain 18 |
19 |This is an unsecured page, but you can access the secured pages after authenticating.
28 |