การผสานรวม AuthenticationManager และตัวให้บริการ
เชื่อมต่อตัวกรอง JWT ของคุณเข้ากับ `AuthenticationManager` ของ Spring Security และตัวให้บริการการยืนยันตัวตนแบบกำหนดเอง
การผสานรวม AuthenticationManager และตัวให้บริการ เป็นบทเรียน Spring Security 6 & JWT Authentication ฟรีบน CoddyKit นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Spring Security 6 & JWT Authentication และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
Orchestrating Authentication
Welcome to the core of Spring Security's authentication process! Today, we'll connect our JWT filter with two vital components: the AuthenticationManager and AuthenticationProvider.
These components work together to verify a user's identity and establish their security context.
The Manager's Core Responsibility
The AuthenticationManager is the central interface in Spring Security for handling authentication requests. Think of it as the conductor of an orchestra.
- It receives an
Authenticationobject (representing a user's credentials). - It delegates the actual authentication task to one or more
AuthenticationProviders. - If successful, it returns a fully authenticated
Authenticationobject.
The Role of AuthenticationProvider
While the AuthenticationManager orchestrates, AuthenticationProviders are the specialized workers.
Each provider knows how to authenticate a specific type of user or credential (e.g., username/password, LDAP, or in our case, a JWT). It contains the logic to validate the credentials.
Crafting a JWT Token Object
For our JWT flow, we need a way to represent an unauthenticated JWT within Spring Security. We'll create a custom Authentication implementation, often called JwtAuthenticationToken.
- It will hold the raw JWT string when unauthenticated.
- After authentication, it will hold the authenticated user's details (
UserDetails) and authorities.
Building Our JWT Provider
Now, let's create our own JwtAuthenticationProvider. This class will implement the AuthenticationProvider interface.
Its main job is to take our JwtAuthenticationToken, validate the JWT, extract user details, and return a fully authenticated token.
JwtAuthenticationProvider Logic
Here's a simplified look at what our JwtAuthenticationProvider's authenticate method might do. It checks if the token is valid and then builds an authenticated object.
import org.springframework.security.authentication.AuthenticationProvider;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.AuthenticationException;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.GrantedAuthority;
import java.util.Collections;
public class CustomJwtAuthProvider implements AuthenticationProvider {
@Override
public Authentication authenticate(Authentication authentication)
throws AuthenticationException {
// In a real app, you'd validate the JWT here.
// For this example, we'll assume it's valid if it's our custom type.
if (authentication instanceof JwtAuthenticationToken) {
// Simulate successful JWT validation
// Extract username and roles from the JWT payload
String username = "coddykitUser"; // From JWT subject
// Roles would also come from JWT claims
// For simplicity, we grant a basic role
GrantedAuthority role = () -> "ROLE_USER";
User userDetails = new User(username, "", Collections.singletonList(role));
// Return a fully authenticated token
// The credentials (JWT string) are usually cleared
return new JwtAuthenticationToken(userDetails, Collections.singletonList(role));
}
return null; // Not our type of authentication
}
@Override
public boolean supports(Class<?> authentication) {
// This provider supports our custom JwtAuthenticationToken
return JwtAuthenticationToken.class.isAssignableFrom(authentication);
}
// Simple placeholder for our custom token
static class JwtAuthenticationToken implements Authentication {
private final User userDetails;
private final String jwtToken;
private boolean authenticated;
private java.util.Collection<? extends GrantedAuthority> authorities;
public JwtAuthenticationToken(String jwtToken) {
this.jwtToken = jwtToken;
this.userDetails = null;
this.authenticated = false;
this.authorities = Collections.emptyList();
}
public JwtAuthenticationToken(User userDetails,
java.util.Collection<? extends GrantedAuthority> authorities) {
this.userDetails = userDetails;
this.jwtToken = null; // Token already validated
this.authenticated = true;
this.authorities = authorities;
}
@Override
public java.util.Collection<? extends GrantedAuthority> getAuthorities() {
return authorities;
}
@Override
public Object getCredentials() {
return jwtToken; // The raw JWT string (if unauthenticated)
}
@Override
public Object getDetails() {
return userDetails;
}
@Override
public Object getPrincipal() {
return userDetails; // The authenticated user object
}
@Override
public boolean isAuthenticated() {
return authenticated;
}
@Override
public void setAuthenticated(boolean isAuthenticated)
throws IllegalArgumentException {
this.authenticated = isAuthenticated;
}
@Override
public String getName() {
return userDetails != null ? userDetails.getUsername() : "N/A";
}
}
public static void main(String[] args) {
System.out.println("CustomJwtAuthProvider initialized.");
// In a real app, Spring Security would call authenticate()
// We're just demonstrating the class structure here.
}
}Wiring Up the Provider
For our JwtAuthenticationProvider to be used, we must register it with Spring Security's configuration. This is typically done in your security configuration class.
Spring Boot often auto-configures the AuthenticationManager, but we can add custom providers to it.
Filter-Manager Interaction
Remember our custom JwtAuthenticationFilter from the previous lesson? Now we connect it to the AuthenticationManager.
- The filter will extract the JWT from the request.
- It will create an unauthenticated
JwtAuthenticationToken. - It will then pass this token to the
AuthenticationManagerfor processing.
The manager, in turn, will find and use our JwtAuthenticationProvider.
JWT Authentication Journey
Let's trace the full authentication flow with our new components:
- Client sends request with JWT in the
Authorizationheader. - Our
JwtAuthenticationFilterintercepts the request, extracts the JWT. - Filter creates an unauthenticated
JwtAuthenticationToken. - Filter calls
AuthenticationManager.authenticate()with this token. AuthenticationManagerfinds ourJwtAuthenticationProvider(becausesupports()returns true).JwtAuthenticationProvidervalidates the JWT and builds a fully authenticatedJwtAuthenticationToken(containingUserDetailsand authorities).- The filter receives the authenticated token and sets it in the
SecurityContextHolder. - The request proceeds, now knowing who the user is and what they can do!
Understanding the Flow
Which statements accurately describe the roles of AuthenticationManager and AuthenticationProvider in a Spring Security JWT setup?
Bringing It All Together
In this lesson, we've explored how AuthenticationManager acts as the central orchestrator and how a custom AuthenticationProvider handles the specific logic for validating JWTs.
By integrating these components with our JwtAuthenticationFilter, we've established a robust and modular JWT authentication flow within Spring Security. This separation of concerns makes your security configuration flexible and maintainable!
คำถามที่พบบ่อย
บทเรียน “การผสานรวม AuthenticationManager และตัวให้บริการ” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “การผสานรวม AuthenticationManager และตัวให้บริการ” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Spring Security 6 & JWT Authentication ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “การผสานรวม AuthenticationManager และตัวให้บริการ”
เชื่อมต่อตัวกรอง JWT ของคุณเข้ากับ `AuthenticationManager` ของ Spring Security และตัวให้บริการการยืนยันตัวตนแบบกำหนดเอง คุณปฏิบัติ Spring Security 6 & JWT Authentication ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Spring Security 6 & JWT Authentication หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน Spring Security 6 & JWT Authentication บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน
บทเรียน “การผสานรวม AuthenticationManager และตัวให้บริการ” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน Spring Security 6 & JWT Authentication นี้ได้ไหม
ได้ บทเรียน Spring Security 6 & JWT Authentication ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- การออกแบบลำดับการยืนยันตัวตนด้วย JWT
- การสร้างตัวกรอง JWT แบบกำหนดเอง
- การผสานรวม AuthenticationManager และตัวให้บริการ
- การจัดการข้อผิดพลาดในการตรวจสอบสิทธิ์และจุดเริ่มต้น