【问题标题】:Spring Boot and JWT - JSESSIONID allows REST request without need for JWT?Spring Boot 和 JWT - JSESSIONID 允许 REST 请求而不需要 JWT?
【发布时间】:2020-08-11 14:09:37
【问题描述】:

我已经在我的Spring Boot REST API 中使用Auth0 实现了JWT 授权。

它通常按预期工作,但是我在POSTMAN 中进行测试时发现了一个奇怪的问题。

当我成功验证任何一个请求时,例如使用来自 Auth0 的 Bearer JWT 令牌的 GET 请求,然后我在所有其他请求中填充了以下 Cookie:

现在,有了这个 JESSIONID cookie,我可以在 没有 JWT 令牌的情况下执行我的其他 REST 请求?

这是为什么?它似乎不安全,我希望每个 REST 请求都需要传递一个 JWT?

我的春天SecurityConfig供参考:

/**
 * Configures our application with Spring Security to restrict access to our API endpoints.
 */
@EnableWebSecurity

    public class SecurityConfig extends WebSecurityConfigurerAdapter {

        @Value("${auth0.audience}")
        private String audience;

        @Value("${spring.security.oauth2.resourceserver.jwt.issuer-uri}")
        private String issuer;

        @Override
        public void configure(HttpSecurity http) throws Exception {
            /*
            This is where we configure the security required for our endpoints and setup our app to serve as
            an OAuth2 Resource Server, using JWT validation.
            */
            http.cors().and().csrf().disable().authorizeRequests()
                .mvcMatchers(HttpMethod.GET,"/users/**").authenticated()
                .mvcMatchers(HttpMethod.POST,"/users/**").authenticated()
                .mvcMatchers(HttpMethod.DELETE,"/users/**").authenticated()
                .mvcMatchers(HttpMethod.PUT,"/users/**").authenticated()
                .and()
                .oauth2ResourceServer().jwt();
        }

        @Bean
        JwtDecoder jwtDecoder() {
            /*
            By default, Spring Security does not validate the "aud" claim of the token, to ensure that this token is
            indeed intended for our app. Adding our own validator is easy to do:
            */

            NimbusJwtDecoder jwtDecoder = (NimbusJwtDecoder)
                JwtDecoders.fromOidcIssuerLocation(issuer);

            OAuth2TokenValidator<Jwt> audienceValidator = new AudienceValidator(audience);
            OAuth2TokenValidator<Jwt> withIssuer = JwtValidators.createDefaultWithIssuer(issuer);
            OAuth2TokenValidator<Jwt> withAudience = new DelegatingOAuth2TokenValidator<>(withIssuer, audienceValidator);

            jwtDecoder.setJwtValidator(withAudience);

            return jwtDecoder;
        }


        @Bean
        CorsConfigurationSource corsConfigurationSource() {
            CorsConfiguration configuration = new CorsConfiguration();
            configuration.setAllowedOrigins(Arrays.asList("*"));
            configuration.setAllowedMethods(Arrays.asList("*"));
            configuration.setAllowedHeaders(Arrays.asList("*"));
            configuration.setAllowCredentials(true);
            UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
            source.registerCorsConfiguration("/**", configuration);
            return source;
        }
    }

【问题讨论】:

    标签: spring spring-boot http cookies jwt


    【解决方案1】:

    在 Spring Security 中有 4 种方式来管理 session,

    1. 始终 - 如果会话尚不存在,则始终创建会话
    2. ifRequired – 只有在需要时才会创建会话(默认)
    3. 从不 - 框架永远不会自己创建会话,但如果会话已经存在,它将使用它
    4. 无状态 - Spring Security 不会创建或使用任何会话

    所以查看您的配置,您的应用程序似乎正在使用第二个选项,即“ifRequired”,它创建会话,如果请求带有现有的 sessionId,它允许用户访问资源,因为该用户已经被授权.

    因此,如果您希望您的应用程序完全无状态并且不应该创建会话,您应该使用最后一个无状态选项。 因此,要使其无状态,请将您的配置更改为,

    http.cors().and().csrf().disable().sessionManagement()
            .sessionCreationPolicy(SessionCreationPolicy.STATELESS).and().authorizeRequests()
            .mvcMatchers(HttpMethod.GET, "/users/**").authenticated()
            .mvcMatchers(HttpMethod.POST, "/users/**").authenticated()
            .mvcMatchers(HttpMethod.DELETE, "/users/**").authenticated()
            .mvcMatchers(HttpMethod.PUT, "/users/**").authenticated().and().oauth2ResourceServer()
            .jwt();
    

    希望对你有帮助

    【讨论】:

    • 谢谢!关于 http.cors().and().csrf().disable() - 这会使我的代码不那么安全吗?另外 - 您是否建议使用完全无状态的会话?
    • 看看在这方面能不能帮到你,golb.hplar.ch/2019/05/stateless.html
    • 我可以确认这已经奏效了。这也是一种更安全的方式,因为每次都必须传递一个 jwt?
    猜你喜欢
    • 1970-01-01
    • 2021-08-27
    • 2021-03-30
    • 2016-10-06
    • 2016-02-23
    • 2021-03-20
    • 2020-06-19
    • 2020-12-09
    • 2017-10-24
    相关资源
    最近更新 更多