OAuth2 Plugin for CloudFoundry UAA

Initial implementation  of a plugin that supports the
CloudFoundry UAA OAuth2 server protocol (see

UAA uses so-called JSON web tokens as access tokens,
which already contain the required user id and email
information. This makes an additional request for the
user detail information obsolete. JSON web tokens
have a signature that is verified by the service.
Both HMACSHA256 and SHA256withRSA signatures are

The plugin has been tested with UAA 2.4.0 but should work
also with older UAA versions.

Cloud Foundry UAA OAuth 2.0 Authentication Provider

With this plugin Gerrit can use OAuth2 protocol to authenticate users accessing Gerrit's Web UI with a CloudFoundry User Account and Authentication (UAA) server. The Sign In link will redirect the user to the UAA login screen.

For Git-over-HTTP communication users still need to generate and use an HTTP password.


Apache License 2.0