|
28 | 28 | import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
|
29 | 29 | import org.springframework.security.config.test.SpringTestRule;
|
30 | 30 | import org.springframework.security.core.context.SecurityContext;
|
| 31 | +import org.springframework.security.core.userdetails.PasswordEncodedUser; |
31 | 32 | import org.springframework.security.web.context.HttpRequestResponseHolder;
|
| 33 | +import org.springframework.security.web.context.NullSecurityContextRepository; |
32 | 34 | import org.springframework.security.web.context.SecurityContextPersistenceFilter;
|
33 | 35 | import org.springframework.security.web.context.SecurityContextRepository;
|
34 | 36 | import org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter;
|
35 | 37 | import org.springframework.test.web.servlet.MockMvc;
|
| 38 | +import org.springframework.test.web.servlet.MvcResult; |
36 | 39 |
|
| 40 | +import javax.servlet.http.HttpSession; |
| 41 | + |
| 42 | +import static org.assertj.core.api.Assertions.assertThat; |
37 | 43 | import static org.mockito.ArgumentMatchers.any;
|
38 | 44 | import static org.mockito.Mockito.*;
|
| 45 | +import static org.springframework.security.config.Customizer.withDefaults; |
| 46 | +import static org.springframework.security.test.web.servlet.request.SecurityMockMvcRequestBuilders.formLogin; |
39 | 47 | import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.get;
|
40 | 48 |
|
41 | 49 | /**
|
@@ -151,4 +159,97 @@ protected void configure(AuthenticationManagerBuilder auth) throws Exception {
|
151 | 159 | // @formatter:on
|
152 | 160 | }
|
153 | 161 | }
|
| 162 | + |
| 163 | + @Test |
| 164 | + public void requestWhenSecurityContextWithDefaultsInLambdaThenSessionIsCreated() throws Exception { |
| 165 | + this.spring.register(SecurityContextWithDefaultsInLambdaConfig.class).autowire(); |
| 166 | + |
| 167 | + MvcResult mvcResult = this.mvc.perform(formLogin()).andReturn(); |
| 168 | + HttpSession session = mvcResult.getRequest().getSession(false); |
| 169 | + assertThat(session).isNotNull(); |
| 170 | + } |
| 171 | + |
| 172 | + @EnableWebSecurity |
| 173 | + static class SecurityContextWithDefaultsInLambdaConfig extends WebSecurityConfigurerAdapter { |
| 174 | + @Override |
| 175 | + protected void configure(HttpSecurity http) throws Exception { |
| 176 | + // @formatter:off |
| 177 | + http |
| 178 | + .formLogin(withDefaults()) |
| 179 | + .securityContext(withDefaults()); |
| 180 | + // @formatter:on |
| 181 | + } |
| 182 | + |
| 183 | + @Override |
| 184 | + protected void configure(AuthenticationManagerBuilder auth) throws Exception { |
| 185 | + // @formatter:off |
| 186 | + auth |
| 187 | + .inMemoryAuthentication() |
| 188 | + .withUser(PasswordEncodedUser.user()); |
| 189 | + // @formatter:on |
| 190 | + } |
| 191 | + } |
| 192 | + |
| 193 | + @Test |
| 194 | + public void requestWhenSecurityContextDisabledInLambdaThenContextNotSavedInSession() throws Exception { |
| 195 | + this.spring.register(SecurityContextDisabledInLambdaConfig.class).autowire(); |
| 196 | + |
| 197 | + MvcResult mvcResult = this.mvc.perform(formLogin()).andReturn(); |
| 198 | + HttpSession session = mvcResult.getRequest().getSession(false); |
| 199 | + assertThat(session).isNull(); |
| 200 | + } |
| 201 | + |
| 202 | + @EnableWebSecurity |
| 203 | + static class SecurityContextDisabledInLambdaConfig extends WebSecurityConfigurerAdapter { |
| 204 | + @Override |
| 205 | + protected void configure(HttpSecurity http) throws Exception { |
| 206 | + // @formatter:off |
| 207 | + http |
| 208 | + .formLogin(withDefaults()) |
| 209 | + .securityContext(AbstractHttpConfigurer::disable); |
| 210 | + // @formatter:on |
| 211 | + } |
| 212 | + |
| 213 | + @Override |
| 214 | + protected void configure(AuthenticationManagerBuilder auth) throws Exception { |
| 215 | + // @formatter:off |
| 216 | + auth |
| 217 | + .inMemoryAuthentication() |
| 218 | + .withUser(PasswordEncodedUser.user()); |
| 219 | + // @formatter:on |
| 220 | + } |
| 221 | + } |
| 222 | + |
| 223 | + @Test |
| 224 | + public void requestWhenNullSecurityContextRepositoryInLambdaThenContextNotSavedInSession() throws Exception { |
| 225 | + this.spring.register(NullSecurityContextRepositoryInLambdaConfig.class).autowire(); |
| 226 | + |
| 227 | + MvcResult mvcResult = this.mvc.perform(formLogin()).andReturn(); |
| 228 | + HttpSession session = mvcResult.getRequest().getSession(false); |
| 229 | + assertThat(session).isNull(); |
| 230 | + } |
| 231 | + |
| 232 | + @EnableWebSecurity |
| 233 | + static class NullSecurityContextRepositoryInLambdaConfig extends WebSecurityConfigurerAdapter { |
| 234 | + @Override |
| 235 | + protected void configure(HttpSecurity http) throws Exception { |
| 236 | + // @formatter:off |
| 237 | + http |
| 238 | + .formLogin(withDefaults()) |
| 239 | + .securityContext(securityContext -> |
| 240 | + securityContext |
| 241 | + .securityContextRepository(new NullSecurityContextRepository()) |
| 242 | + ); |
| 243 | + // @formatter:on |
| 244 | + } |
| 245 | + |
| 246 | + @Override |
| 247 | + protected void configure(AuthenticationManagerBuilder auth) throws Exception { |
| 248 | + // @formatter:off |
| 249 | + auth |
| 250 | + .inMemoryAuthentication() |
| 251 | + .withUser(PasswordEncodedUser.user()); |
| 252 | + // @formatter:on |
| 253 | + } |
| 254 | + } |
154 | 255 | }
|
0 commit comments