5 min
A server that starts
Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.
- spring-boot
- spring-security
5 posts.
Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.
User administration, self-service and admin password changes, and a temporary lockout after repeated failed logins.
Scope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them.
ADMIN-only APIs for OAuth clients and a scope registry, with roles carried in the access token.
Replace the in-memory user with JPA entities, roles, and a database-backed UserDetailsService that accepts username or email.