Skip to content

support easy per-platform sql initialization #19776

Description

@joshlong

im doign an audit of spring security as a project to understand how and where it supports persistent, durable state in a SQL database and what the .sql files provided out of the box look like.

coudl there be a chance to make it easy to initalize-schema = always in spring boot for the various tranches?

first scan reveals the following candidates:

  • UserDetailsService (implemented by JdbcDaoImpl) requires core/.../userdetails/jdbc/users.ddl
  • UserDetailsManager, GroupManager implemented by JdbcUserDetailsManager requires te schema documented in docs/modules/ROOT/pages/servlet/appendix/database-schema.adoc:60
  • PersistentTokenRepositoryimplemented byJdbcTokenRepositoryImplrequires theCREATE_TABLE_SQLconstant atrememberme/JdbcTokenRepositoryImpl.java:42`
  • OneTimeTokenService implemented by JdbcOneTimeTokenService requires core/.../core/ott/jdbc/one-time-tokens-schema.sql
  • AclService and MutableAclService implemented by JdbcAclService and JdbcMutableAclService requires the .sql files at acl/src/main/resources/createAclSchema*.sql(this one is in the best shape of everything)
    • LookupStrategy implemented by BasicLookupStrategy uses the same ACL schema as above
  • OAuth2AuthorizedClientService implemented by JdbcOAuth2AuthorizedClientService requires oauth2-client/.../oauth2-client-schema.sql and -postgres)
  • ReactiveOAuth2AuthorizedClientService implemented by R2dbcReactiveOAuth2AuthorizedClientService requires oauth2-client-schema.sql (same as for blocking equivlaent)
  • RegisteredClientRepository implemented by JdbcRegisteredClientRepository requires .../authorization/client/oauth2-registered-client-schema.sql
  • OAuth2AuthorizationService implemented by JdbcOAuth2AuthorizationService requires .../authorization/oauth2-authorization-schema.sql
  • OAuth2AuthorizationConsentService implemented by JdbcOAuth2AuthorizationConsentService requires .../authorization/oauth2-authorization-consent-schema.sql
  • AssertingPartyMetadataRepository implemented by JdbcAssertingPartyMetadataRepository requires saml2-asserting-party-metadata-schema.sql ( and -postgres.sql variant)

Activity

  1. joshlong commented on Sep 21, 2026

    @joshlong
    MemberAuthor

    discovefed that some schema assumes column values that are case-agnostic, which doesnt begin to work portably. might need to refactor the core class to (based on the passed in platform name) do the equivalent of select * from blah where lowerrcase (bar) = lowercase(?) IF the supported database doesnt have a case agnostic text type.

  2. joshlong commented on Sep 25, 2026

    @joshlong
    MemberAuthor

    first cut at the very first .sql file - users and authorities - is here https://github.com/joshlong/spring-security/tree/users-sql

  3. joshlong commented on Oct 8, 2026

    @joshlong
    MemberAuthor

    if we add a -all.sql file or -all.ddl file, be sure to symlink the new -all.ddl file so that the old file points to the new one -all.ddl file

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions