Avoid eager PasswordEncoder initialization in ClientSecretAuthenticationProvider
Maintainers usually reply within 3 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Domain
- authentication, security
Research direction
Start in oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/ClientSecretAuthenticationProvider.java and compare its encoder initialization with core/src/main/java/org/springframework/security/authentication/dao/DaoAuthenticationProvider.java. Check PasswordEncoderFactories.createDelegatingPasswordEncoder() and SingletonSupplier usage. Done means preserving the public API and default behavior while allowing construction with a custom FIPS-compatible encoder without eagerly creating the default encoder.
Written by the indexing model from the issue text.
Description
ClientSecretAuthenticationProvider eagerly initializes its default PasswordEncoder using PasswordEncoderFactories.createDelegatingPasswordEncoder()
in its constructor.
This factory creates legacy MessageDigestPasswordEncoder instances, including MD5. On a FIPS-compliant JDK where MD5 is unavailable, constructing ClientSecretAuthenticationProvider fails even
when a custom FIPS-compatible PasswordEncoder is configured.
This is similar to the issue discussed in gh-14670.
DaoAuthenticationProvider already avoids this problem by lazily initializing its default PasswordEncoder using SingletonSupplier.
I would like to suggest to apply the same pattern to ClientSecretAuthenticationProvider, preserving the existing public API and default behavior while avoiding construction of the default encoder
when setPasswordEncoder() is used.
I would be happy to submit a PR if this approach sounds correct.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.4k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 54
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from spring-projects/spring-security
-
status: waiting-for-triage type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
spring-projects/spring-security#19781 ·
Maintainers usually reply within 3 days
-
status: waiting-for-triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
spring-projects/spring-security#19733 ·
Maintainers usually reply within 3 days
-
status: waiting-for-triage type: enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
spring-projects/spring-security#19730 ·
Maintainers usually reply within 3 days
-
status: waiting-for-triage type: bug
Difficulty 1/5 Under an hour Newbie friendliness 90/100
spring-projects/spring-security#19728 · 1 comment ·
Maintainers usually reply within 3 days
-
status: waiting-for-triage type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
spring-projects/spring-security#19725 ·
Maintainers usually reply within 3 days
All issues in spring-projects/spring-security
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
checkstyle/checkstyle#21755 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
agentic-workflows
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/copilot-sdk#2782 ·
Maintainers usually reply within 1 day
-
documentation Good for newcomer quick win
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
CodeForPhilly/benefit-decision-toolkit#519 ·
Maintainers usually reply within 1 day
-
area-deployment triage:bot-seen triage:needs-human
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
microsoft/aspire#20533 · 1 comment ·
Maintainers usually reply within 1 day