0Pricing
Spring Security 6 & JWT Authentication · บทเรียน

ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง

พัฒนาตัวจัดการความสำเร็จแบบกำหนดเองเพื่อประมวลผลข้อมูลผู้ใช้หลังการยืนยันตัวตน OAuth2 สำเร็จ

ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง เป็นบทเรียน Spring Security 6 & JWT Authentication ฟรีบน CoddyKit นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Spring Security 6 & JWT Authentication และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

Intro to OAuth2 Success Handlers

Welcome to our lesson on custom OAuth2 success handlers! After a user successfully logs in via an OAuth2 provider (like Google or GitHub), Spring Security needs to know what to do next.

By default, it handles basic redirection. But what if you need to perform custom actions, like saving user details or updating their profile? That's where custom success handlers come in!

Default OAuth2 Success Flow

When a user successfully authenticates with an OAuth2 provider, Spring Security's default behavior is quite straightforward:

  • It extracts user details (like name, email) from the provider's response.
  • It creates an OAuth2AuthenticationToken.
  • It redirects the user to the application's root URL (or a previously requested URL).

This is often enough for simple integrations, but real-world apps usually need more.

Why Customize Success Handling?

Customizing the success handler allows you to:

  • Store User Data: Save new users or update existing ones in your application's database.
  • Generate Tokens: Create custom session tokens or JWTs after OAuth2 login.
  • Redirect Dynamically: Send users to different pages based on their role or status.
  • Logging & Auditing: Log successful logins for security monitoring.

It gives you fine-grained control over the post-authentication process.

The AuthenticationSuccessHandler

Spring Security provides the AuthenticationSuccessHandler interface. You implement this interface to define custom logic for successful authentication events.

Its core method is onAuthenticationSuccess, which gets called after authentication passes.

public interface AuthenticationSuccessHandler {
void onAuthenticationSuccess(
HttpServletRequest request,
HttpServletResponse response,
Authentication authentication
) throws IOException, ServletException;
}

Building a Simple Custom Handler

Let's create a basic custom handler that just logs the successful authentication and then redirects. We'll implement the AuthenticationSuccessHandler interface.

import org.springframework.security.web.authentication.AuthenticationSuccessHandler;
import org.springframework.security.core.Authentication;
import jakarta.servlet.ServletException;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import java.io.IOException;
import org.springframework.stereotype.Component;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

@Component
public class CustomOAuth2SuccessHandler implements AuthenticationSuccessHandler {

    private static final Logger logger = LoggerFactory.getLogger(CustomOAuth2SuccessHandler.class);

    @Override
    public void onAuthenticationSuccess(
        HttpServletRequest request,
        HttpServletResponse response,
        Authentication authentication) throws IOException, ServletException {

        logger.info("OAuth2 login successful for user: " + authentication.getName());
        // Default redirect to home page
        response.sendRedirect("/");
    }
}

Configuring the Custom Handler

To make Spring Security use our custom handler, we need to configure it in our SecurityFilterChain bean. We'll use the oauth2Login() method.

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.authentication.AuthenticationSuccessHandler;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    private final AuthenticationSuccessHandler customOAuth2SuccessHandler;

    public SecurityConfig(AuthenticationSuccessHandler customOAuth2SuccessHandler) {
        this.customOAuth2SuccessHandler = customOAuth2SuccessHandler;
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .oauth2Login(oauth2 -> oauth2
                .successHandler(customOAuth2SuccessHandler) // <--- Register our handler
            );
        return http.build();
    }
}

Accessing User Details

Inside onAuthenticationSuccess, the Authentication object holds the authenticated principal. For OAuth2, this principal will be an OAuth2User.

You can cast it to OAuth2User to access provider-specific attributes like email, name, or unique IDs (e.g., Google ID).

import org.springframework.security.oauth2.core.user.OAuth2User;
import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
import org.springframework.security.oauth2.client.authentication.OAuth2AuthenticationToken;

// Inside onAuthenticationSuccess method:

public void onAuthenticationSuccess(
    HttpServletRequest request,
    HttpServletResponse response,
    Authentication authentication) throws IOException, ServletException {

    if (authentication instanceof OAuth2AuthenticationToken) {
        OAuth2AuthenticationToken oauthToken = (OAuth2AuthenticationToken) authentication;
        OAuth2User oauth2User = oauthToken.getPrincipal();

        String email = oauth2User.getAttribute("email");
        String name = oauth2User.getAttribute("name");
        String provider = oauthToken.getAuthorizedClientRegistrationId();

        logger.info("User logged in: " + name + " from " + provider + " with email: " + email);
        // ... further processing
    }
    response.sendRedirect("/");
}

Practical: Saving User to DB

A common use case is to save or update user information in your database after a successful OAuth2 login. Here's a simplified example:

import org.springframework.security.web.authentication.AuthenticationSuccessHandler;
import org.springframework.security.core.Authentication;
import org.springframework.security.oauth2.core.user.OAuth2User;
import org.springframework.security.oauth2.client.authentication.OAuth2AuthenticationToken;
import jakarta.servlet.ServletException;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import java.io.IOException;
import org.springframework.stereotype.Component;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

// Assume you have a UserService and User entity
// public interface UserService { User saveOrUpdateUser(OAuth2User oauth2User, String provider); }
// public class User { private String email; private String name; /*...*/ }

@Component
public class DatabaseOAuth2SuccessHandler implements AuthenticationSuccessHandler {

    private static final Logger logger = LoggerFactory.getLogger(DatabaseOAuth2SuccessHandler.class);
    // private final UserService userService; // Inject your user service

    // public DatabaseOAuth2SuccessHandler(UserService userService) {
    //     this.userService = userService;
    // }

    @Override
    public void onAuthenticationSuccess(
        HttpServletRequest request,
        HttpServletResponse response,
        Authentication authentication) throws IOException, ServletException {

        if (authentication instanceof OAuth2AuthenticationToken) {
            OAuth2AuthenticationToken oauthToken = (OAuth2AuthenticationToken) authentication;
            OAuth2User oauth2User = oauthToken.getPrincipal();
            String provider = oauthToken.getAuthorizedClientRegistrationId();

            logger.info("Processing OAuth2 user from " + provider);
            // User savedUser = userService.saveOrUpdateUser(oauth2User, provider);
            // logger.info("User saved/updated: " + savedUser.getEmail());
        }
        response.sendRedirect("/");
    }
}

Custom Redirection Logic

The onAuthenticationSuccess method also allows you to control the redirection after login. You can redirect users to a specific dashboard, a profile setup page, or back to the page they were trying to access.

You can use response.sendRedirect("/some-path") or integrate with Spring's RedirectStrategy.

  • request.getRequestURI(): Get the original request URI.
  • response.sendRedirect("/"): Redirect to the root.
  • new DefaultRedirectStrategy().sendRedirect(request, response, "/dashboard"): More robust redirection.

Quick Check: Success Handlers

Which of the following are valid reasons to implement a custom AuthenticationSuccessHandler for OAuth2 in Spring Security?

Recap: Custom Success Handlers

In this lesson, we explored how to customize the post-authentication process for OAuth2 logins using Spring Security's AuthenticationSuccessHandler.

  • We learned its purpose: extending default behavior for user management, redirection, and auditing.
  • We saw how to implement the onAuthenticationSuccess method.
  • We configured our custom handler in the SecurityFilterChain.
  • We understood how to access OAuth2User details and perform actions like saving users to a database.

Custom success handlers provide powerful control over your application's user experience and data integration after an OAuth2 login.

คำถามที่พบบ่อย

บทเรียน “ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Spring Security 6 & JWT Authentication ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง”

พัฒนาตัวจัดการความสำเร็จแบบกำหนดเองเพื่อประมวลผลข้อมูลผู้ใช้หลังการยืนยันตัวตน OAuth2 สำเร็จ คุณปฏิบัติ Spring Security 6 & JWT Authentication ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Spring Security 6 & JWT Authentication หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Spring Security 6 & JWT Authentication บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน

บทเรียน “ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Spring Security 6 & JWT Authentication นี้ได้ไหม

ได้ บทเรียน Spring Security 6 & JWT Authentication ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. การตั้งค่าไคลเอ็นต์ OAuth2
  2. การผสานรวมการเข้าสู่ระบบผ่านโซเชียล
  3. ตัวจัดการความสำเร็จ OAuth2 แบบกำหนดเอง
  4. การเข้าถึงผู้ใช้ OAuth2 ที่ผ่านการตรวจสอบสิทธิ์
← กลับไปที่ Spring Security 6 & JWT Authentication