Spring Security 6 & JWT Authentication · Lezione

Integrazione di AuthenticationManager e Provider

Colleghi il filtro JWT a `AuthenticationManager` di Spring Security e ai provider di autenticazione personalizzati.

Lezione 3 di 411 passaggi

Integrazione di AuthenticationManager e Provider è una lezione Spring Security 6 & JWT Authentication gratuita su CoddyKit. Questa è la lezione 3 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Spring Security 6 & JWT Authentication, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Spring Security 6 & JWT Authentication include 4 lezioni in totale.

Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.

Orchestrating Authentication

Welcome to the core of Spring Security's authentication process! Today, we'll connect our JWT filter with two vital components: the AuthenticationManager and AuthenticationProvider.

These components work together to verify a user's identity and establish their security context.

The Manager's Core Responsibility

The AuthenticationManager is the central interface in Spring Security for handling authentication requests. Think of it as the conductor of an orchestra.

  • It receives an Authentication object (representing a user's credentials).
  • It delegates the actual authentication task to one or more AuthenticationProviders.
  • If successful, it returns a fully authenticated Authentication object.

The Role of AuthenticationProvider

While the AuthenticationManager orchestrates, AuthenticationProviders are the specialized workers.

Each provider knows how to authenticate a specific type of user or credential (e.g., username/password, LDAP, or in our case, a JWT). It contains the logic to validate the credentials.

Crafting a JWT Token Object

For our JWT flow, we need a way to represent an unauthenticated JWT within Spring Security. We'll create a custom Authentication implementation, often called JwtAuthenticationToken.

  • It will hold the raw JWT string when unauthenticated.
  • After authentication, it will hold the authenticated user's details (UserDetails) and authorities.

Building Our JWT Provider

Now, let's create our own JwtAuthenticationProvider. This class will implement the AuthenticationProvider interface.

Its main job is to take our JwtAuthenticationToken, validate the JWT, extract user details, and return a fully authenticated token.

JwtAuthenticationProvider Logic

Here's a simplified look at what our JwtAuthenticationProvider's authenticate method might do. It checks if the token is valid and then builds an authenticated object.

import org.springframework.security.authentication.AuthenticationProvider;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.AuthenticationException;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.GrantedAuthority;
import java.util.Collections;

public class CustomJwtAuthProvider implements AuthenticationProvider {

  @Override
  public Authentication authenticate(Authentication authentication)
      throws AuthenticationException {
    // In a real app, you'd validate the JWT here.
    // For this example, we'll assume it's valid if it's our custom type.
    if (authentication instanceof JwtAuthenticationToken) {
      // Simulate successful JWT validation
      // Extract username and roles from the JWT payload
      String username = "coddykitUser"; // From JWT subject
      // Roles would also come from JWT claims
      // For simplicity, we grant a basic role
      GrantedAuthority role = () -> "ROLE_USER";
      User userDetails = new User(username, "", Collections.singletonList(role));

      // Return a fully authenticated token
      // The credentials (JWT string) are usually cleared
      return new JwtAuthenticationToken(userDetails, Collections.singletonList(role));
    }
    return null; // Not our type of authentication
  }

  @Override
  public boolean supports(Class<?> authentication) {
    // This provider supports our custom JwtAuthenticationToken
    return JwtAuthenticationToken.class.isAssignableFrom(authentication);
  }

  // Simple placeholder for our custom token
  static class JwtAuthenticationToken implements Authentication {
    private final User userDetails;
    private final String jwtToken;
    private boolean authenticated;
    private java.util.Collection<? extends GrantedAuthority> authorities;

    public JwtAuthenticationToken(String jwtToken) {
      this.jwtToken = jwtToken;
      this.userDetails = null;
      this.authenticated = false;
      this.authorities = Collections.emptyList();
    }

    public JwtAuthenticationToken(User userDetails,
                                  java.util.Collection<? extends GrantedAuthority> authorities) {
      this.userDetails = userDetails;
      this.jwtToken = null; // Token already validated
      this.authenticated = true;
      this.authorities = authorities;
    }

    @Override
    public java.util.Collection<? extends GrantedAuthority> getAuthorities() {
      return authorities;
    }

    @Override
    public Object getCredentials() {
      return jwtToken; // The raw JWT string (if unauthenticated)
    }

    @Override
    public Object getDetails() {
      return userDetails;
    }

    @Override
    public Object getPrincipal() {
      return userDetails; // The authenticated user object
    }

    @Override
    public boolean isAuthenticated() {
      return authenticated;
    }

    @Override
    public void setAuthenticated(boolean isAuthenticated)
        throws IllegalArgumentException {
      this.authenticated = isAuthenticated;
    }

    @Override
    public String getName() {
      return userDetails != null ? userDetails.getUsername() : "N/A";
    }
  }

  public static void main(String[] args) {
    System.out.println("CustomJwtAuthProvider initialized.");
    // In a real app, Spring Security would call authenticate()
    // We're just demonstrating the class structure here.
  }
}

Wiring Up the Provider

For our JwtAuthenticationProvider to be used, we must register it with Spring Security's configuration. This is typically done in your security configuration class.

Spring Boot often auto-configures the AuthenticationManager, but we can add custom providers to it.

Filter-Manager Interaction

Remember our custom JwtAuthenticationFilter from the previous lesson? Now we connect it to the AuthenticationManager.

  • The filter will extract the JWT from the request.
  • It will create an unauthenticated JwtAuthenticationToken.
  • It will then pass this token to the AuthenticationManager for processing.

The manager, in turn, will find and use our JwtAuthenticationProvider.

JWT Authentication Journey

Let's trace the full authentication flow with our new components:

  1. Client sends request with JWT in the Authorization header.
  2. Our JwtAuthenticationFilter intercepts the request, extracts the JWT.
  3. Filter creates an unauthenticated JwtAuthenticationToken.
  4. Filter calls AuthenticationManager.authenticate() with this token.
  5. AuthenticationManager finds our JwtAuthenticationProvider (because supports() returns true).
  6. JwtAuthenticationProvider validates the JWT and builds a fully authenticated JwtAuthenticationToken (containing UserDetails and authorities).
  7. The filter receives the authenticated token and sets it in the SecurityContextHolder.
  8. The request proceeds, now knowing who the user is and what they can do!

Understanding the Flow

Which statements accurately describe the roles of AuthenticationManager and AuthenticationProvider in a Spring Security JWT setup?

Bringing It All Together

In this lesson, we've explored how AuthenticationManager acts as the central orchestrator and how a custom AuthenticationProvider handles the specific logic for validating JWTs.

By integrating these components with our JwtAuthenticationFilter, we've established a robust and modular JWT authentication flow within Spring Security. This separation of concerns makes your security configuration flexible and maintainable!

Gratis per iniziare

Impara Java con un tutor IA — gratis

Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.

Corsi
12
Lezioni
48

Domande Frequenti

La lezione «Integrazione di AuthenticationManager e Provider» è gratuita?

Sì — il testo completo di «Integrazione di AuthenticationManager e Provider» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Spring Security 6 & JWT Authentication, passa a CoddyKit PRO. Il corso Spring Security 6 & JWT Authentication include 4 lezioni in totale.

Cosa imparerò in «Integrazione di AuthenticationManager e Provider»?

Colleghi il filtro JWT a `AuthenticationManager` di Spring Security e ai provider di autenticazione personalizzati. Eserciti Spring Security 6 & JWT Authentication con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.

Ho bisogno di esperienza per iniziare Spring Security 6 & JWT Authentication?

Non è richiesta alcuna esperienza precedente. Spring Security 6 & JWT Authentication su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 3 di 4.

Quanto tempo richiede la lezione «Integrazione di AuthenticationManager e Provider»?

La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.

Posso scrivere ed eseguire codice in questa lezione Spring Security 6 & JWT Authentication?

Sì. Ogni lezione Spring Security 6 & JWT Authentication include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.

Tutte le lezioni di questo corso

  1. Progettazione del flusso di autenticazione JWT
  2. Implementazione di un filtro JWT personalizzato
  3. Integrazione di AuthenticationManager e Provider
  4. Gestire gli errori di autenticazione e gli entry point
← Torna a Spring Security 6 & JWT Authentication