> For the complete documentation index, see [llms.txt](https://andifalk.gitbook.io/openid-connect-workshop/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://andifalk.gitbook.io/openid-connect-workshop/introduction/application-architecture.md).

# Sample Application Architecture

For the hands-on workshop labs you will be provided a complete spring mvc web server application together with a corresponding spring mvc thymeleaf web client app.

**Table of Contents**

* [Application Component View](/openid-connect-workshop/introduction/application-architecture.md#application-components)
* [Technology Stack](/openid-connect-workshop/introduction/application-architecture.md#tech-stack)
* [Server Architecture](/openid-connect-workshop/introduction/application-architecture.md#server-architecture)
  * [REST Api](/openid-connect-workshop/introduction/application-architecture.md#rest-api)
  * [Server Layers](/openid-connect-workshop/introduction/application-architecture.md#server-layers)
  * [Users and Roles](/openid-connect-workshop/introduction/application-architecture.md#server-users-and-roles)
  * [Provided application](/openid-connect-workshop/introduction/application-architecture.md#provided-server-application)
* [Client Architecture](/openid-connect-workshop/introduction/application-architecture.md#client-architecture)
  * [Client Layers](/openid-connect-workshop/introduction/application-architecture.md#client-layers)
  * [Users and Roles](/openid-connect-workshop/introduction/application-architecture.md#client-users-and-roles)
  * [Provided application](/openid-connect-workshop/introduction/application-architecture.md#provided-client-application)

## Application Components

![Workshop Architecture](https://4189093407-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LzvpQFqmIPIQLOTnN02%2F-LzvpxSC6eywXLt4xPDU%2F-Lzvpy7g-qurDrvL9yn7%2Fdemo-architecture.png?generation=1580478228544887\&alt=media)

The server application provides a RESTful service for administering books and users (a very *lightweight* books library).

Use cases of this application are:

* Administer books (Creating/editing/deleting books)
* List available books
* Borrow a book
* Return a borrowed book
* Administer library users&#x20;

## Tech Stack

The demo client and server application both are build using the [Java](https://adoptopenjdk.net/) programming language and utilizing the [Spring Framework](https://spring.io).

The following figure shows a typical Microservice technology stack implemented by various Spring projects.

![Workshop Tech Stack](https://4189093407-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LzvpQFqmIPIQLOTnN02%2Fsync%2F847df90bec99850bc5d6653f8df806cbb665a13e.png?generation=1595280629087088\&alt=media)

## Server Architecture

The RESTful service for books and users is build using the Spring MVC annotation model and Spring HATEOAS.

The application also contains a complete documentation for the RESTful API that is automatically generated with spring rest docs. You can find this in the directory *'build/asciidoc/html5'* after performing a full gradle build or online here: [REST API documentation](https://andifalk.github.io/secure-oauth2-oidc-workshop/api-doc.html).

The server application is already secured by basic authentication and also includes authorization using static roles.

### Server Layers

The domain model of the server application is quite simple and just consists of *Book* and *User* models.\
The packages of the application are organized according to the different application layers:

* **api**: Contains the complete RESTful service
* **business**: The service classes (quite simple for workshop, usually these contain the business logic)
* **dataaccess**: All domain models and repositories

In addition there more packages with supporting functions:

* **common**: Classes that are reused in multiple other packages
* **config**: All spring configuration classes
* **security**: All security relevant classes, e.g. a *UserDetailsService* implementation

### REST API

To call the provided REST API you can use curl or httpie. For details on how to call the REST API please consult the [REST API documentation](https://andifalk.github.io/secure-oauth2-oidc-workshop/api-doc.html) which also provides sample requests for curl and httpie.

### Server Users and roles

There are three target user roles for this application:

* LIBRARY\_USER: Standard library user who can list, borrow and return his currently borrowed books
* LIBRARY\_CURATOR: A curator user who can add, edit or delete books
* LIBRARY\_ADMIN: An administrator user who can list, add or remove users

**Important:** We will use the following users in all subsequent labs from now on:

| Username | Email                      | Password | Role             |
| -------- | -------------------------- | -------- | ---------------- |
| bwayne   | <bruce.wayne@example.com>  | wayne    | LIBRARY\_USER    |
| bbanner  | <bruce.banner@example.com> | banner   | LIBRARY\_USER    |
| pparker  | <peter.parker@example.com> | parker   | LIBRARY\_CURATOR |
| ckent    | <clark.kent@example.com>   | kent     | LIBRARY\_ADMIN   |

These users are configured for basic authentication and also later for authenticating using keycloak.

### Provided Server application

You can find the provided initial server application beneath the [lab 1 folder](/openid-connect-workshop/hands-on-labs/lab1.md) as [library-server-initial](https://github.com/andifalk/secure-oauth2-oidc-workshop/tree/be2f0785f4e1fa2f6934370974dca7c22feb24ca/lab1/library-server-initial/README.md).

## Client Architecture

The client is able to fulfill most of the provided uses cases by the server application like:

* View all available books in a list
* Borrow available books
* Return my borrowed books
* Create new books

All action buttons are visible depending on user authorizations, e.g. only users with *LIBRARY\_USER* role can see the *Borrow* and *Return* buttons. The *Return*

![Library Client](https://4189093407-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LzvpQFqmIPIQLOTnN02%2F-LzvpxSC6eywXLt4xPDU%2F-Lzvpy7tZQNPNG1NyWFo%2Flibrary_client.png?generation=1580478230191590\&alt=media)

### Client Layers

The domain model of the client application is quite simple and just consists of *Book* and *User* models.\
The packages of the application are organized according to the different application layers:

* **web**: Contains the complete spring web mvc layer with all required client side resources

In addition there is one more package with supporting functions:

* **config**: All spring configuration classes

In *resources/templates* you find all thymeleaf html templates.\
These templates use the bootstrap framework that resides in *resources/static* folder.

### Client Users and Roles

There are three target user roles for this client application:

* LIBRARY\_USER: Standard library user who can list, borrow and return his currently borrowed books
* LIBRARY\_CURATOR: A curator user who can add, edit or delete books
* LIBRARY\_ADMIN: An administrator user who can list, add or remove users

| Username | Email                      | Password | Role             |
| -------- | -------------------------- | -------- | ---------------- |
| bwayne   | <bruce.wayne@example.com>  | wayne    | LIBRARY\_USER    |
| bbanner  | <bruce.banner@example.com> | banner   | LIBRARY\_USER    |
| pparker  | <peter.parker@example.com> | parker   | LIBRARY\_CURATOR |
| ckent    | <clark.kent@example.com>   | kent     | LIBRARY\_ADMIN   |

### Provided Client application

You can find the provided initial client application beneath the [lab 2 folder](/openid-connect-workshop/hands-on-labs/lab2.md) as [library-client-initial](https://github.com/andifalk/secure-oauth2-oidc-workshop/tree/be2f0785f4e1fa2f6934370974dca7c22feb24ca/lab2/library-client-initial/README.md).
