Broadleaf Microservices
  • v1.0.0-latest-prod

Auth Release Notes for 2.1.7-GA

Tip
The 2.x versions are Spring Boot 3 compatible.

Requirements

  • JDK 17 is required for Broadleaf release trains 2.0.0-GA, and beyond.

  • Spring Authorization Server 1.5.6+ is required for this version of AuthenticationServices, and beyond

New Features & Notable Changes

Improved Bean Overridability

Added @ConditionalOnMissingBean annotations to several auto-configured beans in AuthI18nAutoConfiguration and AuthServiceTemplateAutoConfiguration to support easier customization and overriding in client implementations:

  • Internationalization & Mapping:

    • authMessageSourcePostProcessor

    • authTranslationPostMapperMember

  • Thymeleaf & OAuth2 Template Engine / Resolvers:

    • oAuth2ClientIdTemplateEngine

    • viewResolverPostProcessor (updated to return the concrete ViewResolverPostProcessor type, which has been made public)

    • oAuth2DefaultTemplateResolver

    • broadleafTemplateResolver

    • broadleafOAuth2DefaultTemplateResolver

Public Client Access of Token Revocation Endpoint

The OAuth2 Token Revocation Endpoint is now accessible to public clients. Please review OAuth2 Token Revocation endpoint documentation for more details.

  • Introduced a new PublicClientTokenRevocationAuthenticationConverter that specifically targets the token revocation endpoint and establishes a PublicClientTokenRevocationAuthenticationToken authentication

  • Updated PublicRefreshPublicClientAuthenticationProvider to handle PublicClientTokenRevocationAuthenticationToken

Impersonation Security Scope

Add the IMPERSONATE security scope and its root permission-scope mapping to the required starter data. This is the Authentication Services half of the admin change that hides the View Quote Details action from users who lack impersonation permissions — without the scope in place, the action is hidden from every user because there is nothing for the permission to map to.

The changesets are guarded by preconditions and will not insert rows that already exist, so a deployment that added the scope by hand needs no further action.