Broadleaf Microservices
  • v1.0.0-latest-prod

Auth Release Notes for 2.3.1-GA

Tip
The 2.x versions are Spring Boot 3 compatible.

New Features & Notable Changes

Improved Bean Overridability

Added @ConditionalOnMissingBean annotations to several auto-configured beans in AuthI18nAutoConfiguration and AuthServiceTemplateAutoConfiguration to support easier customization and overriding in client implementations:

  • Internationalization & Mapping:

    • authMessageSourcePostProcessor

    • authTranslationPostMapperMember

  • Thymeleaf & OAuth2 Template Engine / Resolvers:

    • oAuth2ClientIdTemplateEngine

    • viewResolverPostProcessor (updated to return the concrete ViewResolverPostProcessor type, which has been made public)

    • oAuth2DefaultTemplateResolver

    • broadleafTemplateResolver

    • broadleafOAuth2DefaultTemplateResolver

Public Client Access of Token Revocation Endpoint

The OAuth2 Token Revocation Endpoint is now accessible to public clients. Please review OAuth2 Token Revocation endpoint documentation for more details.

  • Introduced a new PublicClientTokenRevocationAuthenticationConverter that specifically targets the token revocation endpoint and establishes a PublicClientTokenRevocationAuthenticationToken authentication

  • Updated PublicRefreshPublicClientAuthenticationProvider to handle PublicClientTokenRevocationAuthenticationToken

Impersonation Security Scope

Add the IMPERSONATE security scope and its root permission-scope mapping to the required starter data. This is the Authentication Services half of the admin change that hides the View Quote Details action from users who lack impersonation permissions — without the scope in place, the action is hidden from every user because there is nothing for the permission to map to.

The changesets are guarded by preconditions and will not insert rows that already exist, so a deployment that added the scope by hand needs no further action.

Bug Fixes

  • Fixed incorrect default Caffeine and EHCache heap/offheap size properties — they were previously specified in raw megabyte values (e.g. 500) under keys expecting a unit suffix, so the configured sizes were not actually being applied. The defaults now use unit-suffixed values (e.g. 500MB).

Miscellaneous

  • Failing to verify or parse a login token now throws a custom exception.

    • The custom exception is an UnverifiedTokenException. This allows specific handling based on the context in which the token is being verified.