I'm developing small monolith Spring-based REST API application with next key points:
authentication will be only by username/password that are provided directly from mobile app.
as sending username/password on each request is bad practice I want to get some token (say JWT) that is then used to authenticate the user.
That seems to be quite standard task.
As application is quite small I see it too excessive to implement Spring OAuth Authorization Server and Spring OAuth Resource Server. Moreover, resource owner password workflow is now deprecated and common workflow is code workflow that uses Authorization Server login form, that is not acceptable in my case, as I need to provide username/password directly in REST API call (password is actually read from device, not typed by user).
Unfortunately I did not found standard solution for this case nor in Spring documentation, nor googling, nor AI.
All recommendation are like this (just a piece of solution):
private fun extractJwtFromRequest(request: HttpServletRequest): String? {
val bearerToken = request.getHeader("Authorization")
return if (bearerToken != null && bearerToken.startsWith("Bearer ")) {
bearerToken.substring(7)
} else null
}
What looks more like a hack, than a framework backed standard solution.
It seems that Spring Security provides standard support for very simple cases like basic or form authentication, but if you need more mature token based solution it forces you to use OAuth infrastructure.
So, do I understand right, that if I want to use authentication with token, then Spring offers only 2 ways:
using OAuth infrastructure with Resource Server and Authorization Server.
manually writing filters, extracting token, etc.
Or am I missing something?