0Pricing
Spring Security 6 & JWT Authentication · 课时

AuthenticationManager 与身份验证提供程序集成

将您的 JWT 过滤器与 Spring Security 的 `AuthenticationManager` 和自定义身份验证提供程序连接起来。

AuthenticationManager 与身份验证提供程序集成 是 CoddyKit 上的免费 Spring Security 6 & JWT Authentication 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Security 6 & JWT Authentication 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Orchestrating Authentication

Welcome to the core of Spring Security's authentication process! Today, we'll connect our JWT filter with two vital components: the AuthenticationManager and AuthenticationProvider.

These components work together to verify a user's identity and establish their security context.

The Manager's Core Responsibility

The AuthenticationManager is the central interface in Spring Security for handling authentication requests. Think of it as the conductor of an orchestra.

  • It receives an Authentication object (representing a user's credentials).
  • It delegates the actual authentication task to one or more AuthenticationProviders.
  • If successful, it returns a fully authenticated Authentication object.

The Role of AuthenticationProvider

While the AuthenticationManager orchestrates, AuthenticationProviders are the specialized workers.

Each provider knows how to authenticate a specific type of user or credential (e.g., username/password, LDAP, or in our case, a JWT). It contains the logic to validate the credentials.

Crafting a JWT Token Object

For our JWT flow, we need a way to represent an unauthenticated JWT within Spring Security. We'll create a custom Authentication implementation, often called JwtAuthenticationToken.

  • It will hold the raw JWT string when unauthenticated.
  • After authentication, it will hold the authenticated user's details (UserDetails) and authorities.

Building Our JWT Provider

Now, let's create our own JwtAuthenticationProvider. This class will implement the AuthenticationProvider interface.

Its main job is to take our JwtAuthenticationToken, validate the JWT, extract user details, and return a fully authenticated token.

JwtAuthenticationProvider Logic

Here's a simplified look at what our JwtAuthenticationProvider's authenticate method might do. It checks if the token is valid and then builds an authenticated object.

import org.springframework.security.authentication.AuthenticationProvider;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.AuthenticationException;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.GrantedAuthority;
import java.util.Collections;

public class CustomJwtAuthProvider implements AuthenticationProvider {

  @Override
  public Authentication authenticate(Authentication authentication)
      throws AuthenticationException {
    // In a real app, you'd validate the JWT here.
    // For this example, we'll assume it's valid if it's our custom type.
    if (authentication instanceof JwtAuthenticationToken) {
      // Simulate successful JWT validation
      // Extract username and roles from the JWT payload
      String username = "coddykitUser"; // From JWT subject
      // Roles would also come from JWT claims
      // For simplicity, we grant a basic role
      GrantedAuthority role = () -> "ROLE_USER";
      User userDetails = new User(username, "", Collections.singletonList(role));

      // Return a fully authenticated token
      // The credentials (JWT string) are usually cleared
      return new JwtAuthenticationToken(userDetails, Collections.singletonList(role));
    }
    return null; // Not our type of authentication
  }

  @Override
  public boolean supports(Class<?> authentication) {
    // This provider supports our custom JwtAuthenticationToken
    return JwtAuthenticationToken.class.isAssignableFrom(authentication);
  }

  // Simple placeholder for our custom token
  static class JwtAuthenticationToken implements Authentication {
    private final User userDetails;
    private final String jwtToken;
    private boolean authenticated;
    private java.util.Collection<? extends GrantedAuthority> authorities;

    public JwtAuthenticationToken(String jwtToken) {
      this.jwtToken = jwtToken;
      this.userDetails = null;
      this.authenticated = false;
      this.authorities = Collections.emptyList();
    }

    public JwtAuthenticationToken(User userDetails,
                                  java.util.Collection<? extends GrantedAuthority> authorities) {
      this.userDetails = userDetails;
      this.jwtToken = null; // Token already validated
      this.authenticated = true;
      this.authorities = authorities;
    }

    @Override
    public java.util.Collection<? extends GrantedAuthority> getAuthorities() {
      return authorities;
    }

    @Override
    public Object getCredentials() {
      return jwtToken; // The raw JWT string (if unauthenticated)
    }

    @Override
    public Object getDetails() {
      return userDetails;
    }

    @Override
    public Object getPrincipal() {
      return userDetails; // The authenticated user object
    }

    @Override
    public boolean isAuthenticated() {
      return authenticated;
    }

    @Override
    public void setAuthenticated(boolean isAuthenticated)
        throws IllegalArgumentException {
      this.authenticated = isAuthenticated;
    }

    @Override
    public String getName() {
      return userDetails != null ? userDetails.getUsername() : "N/A";
    }
  }

  public static void main(String[] args) {
    System.out.println("CustomJwtAuthProvider initialized.");
    // In a real app, Spring Security would call authenticate()
    // We're just demonstrating the class structure here.
  }
}

Wiring Up the Provider

For our JwtAuthenticationProvider to be used, we must register it with Spring Security's configuration. This is typically done in your security configuration class.

Spring Boot often auto-configures the AuthenticationManager, but we can add custom providers to it.

Filter-Manager Interaction

Remember our custom JwtAuthenticationFilter from the previous lesson? Now we connect it to the AuthenticationManager.

  • The filter will extract the JWT from the request.
  • It will create an unauthenticated JwtAuthenticationToken.
  • It will then pass this token to the AuthenticationManager for processing.

The manager, in turn, will find and use our JwtAuthenticationProvider.

JWT Authentication Journey

Let's trace the full authentication flow with our new components:

  1. Client sends request with JWT in the Authorization header.
  2. Our JwtAuthenticationFilter intercepts the request, extracts the JWT.
  3. Filter creates an unauthenticated JwtAuthenticationToken.
  4. Filter calls AuthenticationManager.authenticate() with this token.
  5. AuthenticationManager finds our JwtAuthenticationProvider (because supports() returns true).
  6. JwtAuthenticationProvider validates the JWT and builds a fully authenticated JwtAuthenticationToken (containing UserDetails and authorities).
  7. The filter receives the authenticated token and sets it in the SecurityContextHolder.
  8. The request proceeds, now knowing who the user is and what they can do!

Understanding the Flow

Which statements accurately describe the roles of AuthenticationManager and AuthenticationProvider in a Spring Security JWT setup?

Bringing It All Together

In this lesson, we've explored how AuthenticationManager acts as the central orchestrator and how a custom AuthenticationProvider handles the specific logic for validating JWTs.

By integrating these components with our JwtAuthenticationFilter, we've established a robust and modular JWT authentication flow within Spring Security. This separation of concerns makes your security configuration flexible and maintainable!

常见问题解答

「AuthenticationManager 与身份验证提供程序集成」课时是免费的吗?

是的 — 「AuthenticationManager 与身份验证提供程序集成」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Security 6 & JWT Authentication 课程的其余内容,请升级到 CoddyKit PRO。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

「AuthenticationManager 与身份验证提供程序集成」这节课中我会学到什么?

将您的 JWT 过滤器与 Spring Security 的 `AuthenticationManager` 和自定义身份验证提供程序连接起来。 你通过在浏览器中直接运行的动手代码来练习 Spring Security 6 & JWT Authentication,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Spring Security 6 & JWT Authentication 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Spring Security 6 & JWT Authentication 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。

「AuthenticationManager 与身份验证提供程序集成」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Spring Security 6 & JWT Authentication 课中编写并运行代码吗?

能。每节 Spring Security 6 & JWT Authentication 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 设计 JWT 身份验证流程
  2. 实现自定义 JWT 过滤器
  3. AuthenticationManager 与身份验证提供程序集成
  4. 处理身份验证错误与入口点
← 返回 Spring Security 6 & JWT Authentication