From fe62c4eab21d30356e64d9eb50022533d40afbf4 Mon Sep 17 00:00:00 2001 From: stigus Date: Mon, 9 Dec 2024 10:34:01 +0100 Subject: [PATCH] Revert "change/azure-app-client-deprecated (#3686)" This reverts commit d307c602d6408259b8c88341080269ee92a85a13. --- .../src/test/resources/application-test.yml | 9 +-------- .../src/test/resources/application-test.yml | 9 +-------- .../src/test/resources/application-test.yml | 1 + .../domain/azuread/AzureNavClientCredential.java | 5 ++--- .../fullmakt-proxy/src/main/resources/application.yml | 2 +- .../src/main/resources/application.yml | 2 +- .../src/main/resources/application-dev.yml | 10 ++++++++++ .../src/main/resources/application.yml | 5 +++-- .../src/test/resources/application-test.yml | 10 ++++------ 9 files changed, 24 insertions(+), 29 deletions(-) diff --git a/apps/endringsmelding-frontend/src/test/resources/application-test.yml b/apps/endringsmelding-frontend/src/test/resources/application-test.yml index 9a6e5057ae3..0aeb22a14f6 100644 --- a/apps/endringsmelding-frontend/src/test/resources/application-test.yml +++ b/apps/endringsmelding-frontend/src/test/resources/application-test.yml @@ -2,11 +2,4 @@ spring: cloud: gcp: secretmanager: - enabled: false - security: - oauth2: - client: - registration: - aad: - client-id: dummy - client-secret: dummy \ No newline at end of file + enabled: false \ No newline at end of file diff --git a/apps/faste-data-frontend/src/test/resources/application-test.yml b/apps/faste-data-frontend/src/test/resources/application-test.yml index 9a6e5057ae3..0aeb22a14f6 100644 --- a/apps/faste-data-frontend/src/test/resources/application-test.yml +++ b/apps/faste-data-frontend/src/test/resources/application-test.yml @@ -2,11 +2,4 @@ spring: cloud: gcp: secretmanager: - enabled: false - security: - oauth2: - client: - registration: - aad: - client-id: dummy - client-secret: dummy \ No newline at end of file + enabled: false \ No newline at end of file diff --git a/apps/testnorge-statisk-data-forvalter/src/test/resources/application-test.yml b/apps/testnorge-statisk-data-forvalter/src/test/resources/application-test.yml index 2741c689790..a4c5a1d25d2 100644 --- a/apps/testnorge-statisk-data-forvalter/src/test/resources/application-test.yml +++ b/apps/testnorge-statisk-data-forvalter/src/test/resources/application-test.yml @@ -61,6 +61,7 @@ aareg: pageSize: 2 controller.staticdata.cache.hours: 24 +azure.app.client.id: dummy KAFKA_SCHEMA_REGISTRY: http://localhost:9009 kafka.groupid: organisasjon-forvalter-v1 diff --git a/libs/security-core/src/main/java/no/nav/testnav/libs/securitycore/domain/azuread/AzureNavClientCredential.java b/libs/security-core/src/main/java/no/nav/testnav/libs/securitycore/domain/azuread/AzureNavClientCredential.java index caf3c8a43b4..f01de4e0e94 100644 --- a/libs/security-core/src/main/java/no/nav/testnav/libs/securitycore/domain/azuread/AzureNavClientCredential.java +++ b/libs/security-core/src/main/java/no/nav/testnav/libs/securitycore/domain/azuread/AzureNavClientCredential.java @@ -7,10 +7,9 @@ public class AzureNavClientCredential extends ClientCredential { public AzureNavClientCredential( - @Value("${spring.security.oauth2.client.registration.aad.client-id:#{null}}") String clientId, - @Value("${spring.security.oauth2.client.registration.aad.client-secret:#{null}}") String clientSecret + @Value("${azure.app.client.id:#{null}}") String clientId, + @Value("${azure.app.client.secret:#{null}}") String clientSecret ) { super(clientId, clientSecret); } - } diff --git a/proxies/fullmakt-proxy/src/main/resources/application.yml b/proxies/fullmakt-proxy/src/main/resources/application.yml index 653461daebf..da6230fc5bd 100644 --- a/proxies/fullmakt-proxy/src/main/resources/application.yml +++ b/proxies/fullmakt-proxy/src/main/resources/application.yml @@ -10,7 +10,7 @@ spring: aad: issuer-uri: ${AAD_ISSUER_URI}/v2.0 jwk-set-uri: ${AAD_ISSUER_URI}/discovery/v2.0/keys - accepted-audience: ${AZURE_APP_CLIENT_ID}, api://${AZURE_APP_CLIENT_ID} + accepted-audience: ${azure.app.client.id}, api://${azure.app.client.id} tokenx: issuer-uri: ${TOKEN_X_ISSUER} jwk-set-uri: ${TOKEN_X_JWKS_URI} diff --git a/proxies/sykemelding-proxy/src/main/resources/application.yml b/proxies/sykemelding-proxy/src/main/resources/application.yml index a9cbc9053b1..1d29c30041d 100644 --- a/proxies/sykemelding-proxy/src/main/resources/application.yml +++ b/proxies/sykemelding-proxy/src/main/resources/application.yml @@ -10,7 +10,7 @@ spring: aad: issuer-uri: ${AAD_ISSUER_URI}/v2.0 jwk-set-uri: ${AAD_ISSUER_URI}/discovery/v2.0/keys - accepted-audience: ${AZURE_APP_CLIENT_ID}, api://${AZURE_APP_CLIENT_ID} + accepted-audience: ${azure.app.client.id}, api://${azure.app.client.id} tokenx: issuer-uri: ${TOKEN_X_ISSUER} jwk-set-uri: ${TOKEN_X_JWKS_URI} diff --git a/proxies/synthdata-meldekort-proxy/src/main/resources/application-dev.yml b/proxies/synthdata-meldekort-proxy/src/main/resources/application-dev.yml index c37992c9d91..0931b73834a 100644 --- a/proxies/synthdata-meldekort-proxy/src/main/resources/application-dev.yml +++ b/proxies/synthdata-meldekort-proxy/src/main/resources/application-dev.yml @@ -6,6 +6,16 @@ spring: config: import: "sm://" +azure: + nav: + app: + client: + id: ${sm://azure-app-client-id} + secret: ${sm://azure-app-client-secret} + openid: + config: + issuer: https://login.microsoftonline.com/62366534-1ec3-4962-8869-9b5535279d0b + consumers: synt-meldekort: url: https://synthdata-arena-meldekort.intern.dev.nav.no \ No newline at end of file diff --git a/proxies/synthdata-meldekort-proxy/src/main/resources/application.yml b/proxies/synthdata-meldekort-proxy/src/main/resources/application.yml index 48c88a26e19..72804a26497 100644 --- a/proxies/synthdata-meldekort-proxy/src/main/resources/application.yml +++ b/proxies/synthdata-meldekort-proxy/src/main/resources/application.yml @@ -1,12 +1,13 @@ spring: application: name: testnav-synthdata-meldekort-proxy + desciption: Proxy for synthdata-arena-meldekort som legger på sikkerhet. security: oauth2: resourceserver: trygdeetaten: - issuer-uri: ${AZURE_OPENID_CONFIG_ISSUER} - jwk-set-uri: ${AZURE_OPENID_CONFIG_JWKS_URI} + issuer-uri: ${azure.openid.config.issuer} + jwk-set-uri: ${azure.openid.config.jwks.uri} accepted-audience: ${AZURE_APP_CLIENT_ID}, api:// ${AZURE_APP_CLIENT_ID} codec: max-in-memory-size: 15MB diff --git a/proxies/synthdata-meldekort-proxy/src/test/resources/application-test.yml b/proxies/synthdata-meldekort-proxy/src/test/resources/application-test.yml index 21870a92a7e..0664d10716c 100644 --- a/proxies/synthdata-meldekort-proxy/src/test/resources/application-test.yml +++ b/proxies/synthdata-meldekort-proxy/src/test/resources/application-test.yml @@ -1,6 +1,4 @@ -spring: - security: - oauth2: - resourceserver: - trygdeetaten: - issuer-uri: # Intentionally left blank. \ No newline at end of file +azure: + openid: + config: + issuer: dummy \ No newline at end of file