I have run into some bugs while configuring crowd, this is a topic that I have put off tackling several times because of the amount of people saying it doesn't work with the official atlassian article.
I took on the task, most of it was fine but I think I found a couple of bugs.
- CrowdSecurityFilter - seems to just outright deny passage even for paths which are permitted. I had to exclude this bean and it was fine, this is annoying because it means the XML provided by atlassian cannot be used as is and I have to pull it into the project and comment out that bean.
- CrowdAuthenticationProvider - When debugging the auth process, inside the following method the authenticationToken.getDetails() doesn't return null, so it throws a false, which in turn causes the authenticate call to return null.
public boolean supports(AbstractAuthenticationToken authenticationToken) {
return authenticationToken.getDetails() == null || authenticationToken.getDetails() instanceof CrowdSSOAuthenticationDetails;
}public Authentication authenticate(Authentication authentication) throws AuthenticationException {
if (!this.supports(authentication.getClass())) {
return null;
} else if (!this.supports((AbstractAuthenticationToken)authentication)) {
return null;
} else {
Authentication authenticatedToken = null;
if (authentication instanceof UsernamePasswordAuthenticationToken) {
logger.debug("Processing a UsernamePasswordAuthenticationToken");
authenticatedToken = this.authenticateUsernamePassword((UsernamePasswordAuthenticationToken)authentication);
} else if (authentication instanceof CrowdSSOAuthenticationToken) {
logger.debug("Processing a CrowdSSOAuthenticationToken");
authenticatedToken = this.authenticateCrowdSSO((CrowdSSOAuthenticationToken)authentication);
}
return authenticatedToken;
}
} As a result the UI displays the following:
for org.springframework.security.authentication.UsernamePasswordAuthenticationTokenNo AuthenticationProvider found<span> </span>
I had to replace the implementation with authenticationToken.getDetails() != null but I am unsure of the intended direction here, going back before version 3 of this library it seems like it was a completely different implementation for this method.
I have written a blog about the topic to provide some more context and a bitbucket repo exists which replicates the issue.
https://fxqlabs.net/display/OSS/2019/08/20/Integrating+Atlassian+Crowd+with+Spring+Boot+via+Spring+Security
https://bitbucket.org/fxqlabs-oss/integrating-atlassian-crowd-with-spring-boot-via-spring/commits/1399518fe0f21f00fe2064991170585ac0bfe314
I would really like to get rid of these hacks to get the platform working because otherwise it's actually a very neat solution.
Thanks