Further refactor OAuth handling
Improve architecture to better fit in with Spring Security: * Create an unauthenticated token first and pass it to an AuthenticationProvider. * Let Spring Security handle everything else.
Showing
- src/main/java/de/thm/arsnova/config/SecurityConfig.java 24 additions, 16 deletionssrc/main/java/de/thm/arsnova/config/SecurityConfig.java
- src/main/java/de/thm/arsnova/security/pac4j/OauthAuthenticationProvider.java 11 additions, 15 deletions...m/arsnova/security/pac4j/OauthAuthenticationProvider.java
- src/main/java/de/thm/arsnova/security/pac4j/OauthCallbackFilter.java 43 additions, 26 deletions...va/de/thm/arsnova/security/pac4j/OauthCallbackFilter.java
Please register or sign in to comment