docs: B-0 — deploy the BFF and read what autoconfiguration actually chose
The authorized client repository is AuthenticatedPrincipalOAuth2AuthorizedClientRepository, keyed by principal with no session id in it, which is the mechanism behind the sharing problem Q1 and Q3 describe. Sharing a store does not fix a lookup key. Five problems on the way in: only build output was committed under bff/, a duplicate YAML key broke the image build and was invisible until the full log was captured, env placeholders without defaults broke the tests, actuator was behind the login redirect so a 200 was the login page, and the 117KB beans response failed through the proxy. Deploying two replicas made the login itself fail before any experiment started, because the authorization request lives in per-instance memory and the callback lands elsewhere. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
8f6d67df35
commit
e62bbb4df0
@@ -0,0 +1,52 @@
|
||||
server:
|
||||
port: ${SERVER_PORT:8083}
|
||||
servlet:
|
||||
session:
|
||||
cookie:
|
||||
name: AP3_SESSION
|
||||
http-only: true
|
||||
same-site: lax
|
||||
|
||||
spring:
|
||||
application:
|
||||
name: keycloak-bff
|
||||
security:
|
||||
oauth2:
|
||||
client:
|
||||
registration:
|
||||
keycloak:
|
||||
provider: keycloak
|
||||
client-id: bff-confidential
|
||||
client-secret: ${KEYCLOAK_CLIENT_SECRET}
|
||||
client-authentication-method: client_secret_basic
|
||||
authorization-grant-type: authorization_code
|
||||
redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
|
||||
scope:
|
||||
- openid
|
||||
- profile
|
||||
- email
|
||||
provider:
|
||||
keycloak:
|
||||
# 브라우저가 리다이렉트되는 주소와 BFF 가 서버끼리 부르는 주소는 다르다.
|
||||
# 앞의 것은 외부에서 닿는 이름이어야 하고, 뒤의 것은 클러스터 안 주소여도 된다.
|
||||
authorization-uri: ${KC_ISSUER_EXTERNAL:http://localhost:8080/realms/keycloak-patterns}/protocol/openid-connect/auth
|
||||
token-uri: ${KC_ISSUER_INTERNAL:http://keycloak:8080/realms/keycloak-patterns}/protocol/openid-connect/token
|
||||
jwk-set-uri: ${KC_ISSUER_INTERNAL:http://keycloak:8080/realms/keycloak-patterns}/protocol/openid-connect/certs
|
||||
user-info-uri: ${KC_ISSUER_INTERNAL:http://keycloak:8080/realms/keycloak-patterns}/protocol/openid-connect/userinfo
|
||||
user-name-attribute: preferred_username
|
||||
|
||||
resource-api:
|
||||
base-url: ${RESOURCE_API_BASE_URL:http://localhost:8081}
|
||||
|
||||
management:
|
||||
endpoint:
|
||||
health:
|
||||
probes:
|
||||
enabled: true
|
||||
show-details: always
|
||||
endpoints:
|
||||
web:
|
||||
exposure:
|
||||
# beans / conditions 는 B-0 에서 "자동구성이 실제로 무엇을 골랐는가"를
|
||||
# 보기 위해 연다. 운영에 그대로 두면 내부 구조가 노출된다.
|
||||
include: health,info,beans,conditions,env
|
||||
@@ -0,0 +1,59 @@
|
||||
const result = document.querySelector("#result");
|
||||
|
||||
function render(value) {
|
||||
result.textContent = JSON.stringify(value, null, 2);
|
||||
}
|
||||
|
||||
function readCookie(name) {
|
||||
const prefix = `${encodeURIComponent(name)}=`;
|
||||
const value = document.cookie
|
||||
.split("; ")
|
||||
.find((cookie) => cookie.startsWith(prefix));
|
||||
return value ? decodeURIComponent(value.slice(prefix.length)) : null;
|
||||
}
|
||||
|
||||
async function request(path, options = {}) {
|
||||
const response = await fetch(path, {
|
||||
...options,
|
||||
headers: { Accept: "application/json", ...options.headers },
|
||||
});
|
||||
if (response.redirected || response.status === 401) {
|
||||
window.location.assign("/oauth2/authorization/keycloak");
|
||||
return null;
|
||||
}
|
||||
const body = await response.json();
|
||||
render({ status: response.status, ...body });
|
||||
return { response, body };
|
||||
}
|
||||
|
||||
document.querySelector("#login").addEventListener("click", () => {
|
||||
window.location.assign("/oauth2/authorization/keycloak");
|
||||
});
|
||||
|
||||
document.querySelector("#inspect").addEventListener("click", () => {
|
||||
void request("/bff/token-boundary");
|
||||
});
|
||||
|
||||
document.querySelector("#call-bff").addEventListener("click", () => {
|
||||
void request("/bff/api/me");
|
||||
});
|
||||
|
||||
document.querySelector("#change-with-csrf").addEventListener("click", async () => {
|
||||
const csrfResponse = await fetch("/bff/csrf", {
|
||||
headers: { Accept: "application/json" },
|
||||
});
|
||||
const csrf = await csrfResponse.json();
|
||||
const csrfToken = readCookie("XSRF-TOKEN");
|
||||
if (!csrfToken) {
|
||||
render({ status: 500, error: "XSRF-TOKEN cookie was not created" });
|
||||
return;
|
||||
}
|
||||
await request("/bff/api/preferences", {
|
||||
method: "POST",
|
||||
body: new URLSearchParams({ theme: "dark" }),
|
||||
headers: {
|
||||
"Content-Type": "application/x-www-form-urlencoded",
|
||||
[csrf.headerName]: csrfToken,
|
||||
},
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,31 @@
|
||||
<!doctype html>
|
||||
<html lang="ko">
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||
<title>AP3 · Backend-for-Frontend</title>
|
||||
<style>
|
||||
:root { color-scheme: light dark; font-family: system-ui, sans-serif; }
|
||||
body { max-width: 58rem; margin: 6vh auto; padding: 0 1.5rem; line-height: 1.6; }
|
||||
button { margin: 0 0.5rem 0.5rem 0; padding: 0.6rem 0.9rem; cursor: pointer; }
|
||||
pre { min-height: 9rem; padding: 1rem; border-radius: 0.4rem;
|
||||
background: color-mix(in srgb, CanvasText 9%, Canvas); white-space: pre-wrap; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<main>
|
||||
<h1>AP3 · Backend-for-Frontend</h1>
|
||||
<p>
|
||||
브라우저에는 OAuth token이 전혀 전달되지 않습니다. HttpOnly session
|
||||
cookie로 BFF만 호출하고, BFF가 서버 보관 access token을 Resource
|
||||
Server 요청에 붙입니다.
|
||||
</p>
|
||||
<button id="login" type="button">Keycloak 로그인</button>
|
||||
<button id="inspect" type="button">token 경계 확인</button>
|
||||
<button id="call-bff" type="button">BFF 경유 API 호출</button>
|
||||
<button id="change-with-csrf" type="button">CSRF token으로 상태 변경</button>
|
||||
<pre id="result" aria-live="polite"></pre>
|
||||
</main>
|
||||
<script type="module" src="/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
Reference in New Issue
Block a user