A RestClient or WebClient OAuth2 interceptor can attach a token automatically; the chosen principal and registration define whose token it sends.
Spring OAuth2 client tokens: bind the authorized client to the intended caller and host
A default can cross the wrong boundary
A shared WebClient configured to use the currently authorized OAuth2 client by default can attach the user's token to every request it makes, including a newly added host. Resolve the client registration deliberately at the call site, or use one client per trusted downstream. A client-credentials token represents the application, while an authorization-code token represents a user session. Refresh and storage follow the selected authorized client, not the Java HTTP interface.
Keep the principal key stable
Spring Security's authorized-client manager stores tokens under a principal identity and registration. A background job without the request's SecurityContext must use an explicit service principal; pretending it is the last browser user is a data-leak risk. For a user-delegated call, verify that the target service, scopes and tenant match the current caller. HTTP service groups are a useful place to constrain hosts and client setup.
Test both identities
Send one request as operator A, another as operator B, and inspect only the test server's received Authorization header claims. Then run a scheduled job and verify it uses its own client-credentials registration. Do not log raw tokens in production. The interface sketch names the call but leaves the OAuth2 filter configuration to the application's security setup.
Implementation sketch
return reportsWebClient.get()
.uri("/v1/reports/{reportId}", reportId)
.attributes(clientRegistrationId("reports-service"))
.retrieve()
.bodyToMono(ReportView.class);Cost and verification
Token acquisition and refresh add network calls at expiry; sharing a wrong token has a security cost far beyond that latency. Cache authorized clients by the correct principal and registration.
Common Mistakes
- Do not enable a default OAuth2 token on a client used for arbitrary hosts.
- Do not reuse a browser user's authorized client in background work.
- Do not treat client credentials as proof of an end user's tenant or permission.
Read next
Spring OAuth2 client credentials: acquire and reuse a service token, Spring HTTP service groups: configure one host policy for several interfaces, Spring HTTP service client: the interface is a contract, not a transport policy, Spring JWT tenant claims: reject missing or malformed ownership before conversion.
