Class ApiKeyConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.ApiKeyConfigurer

public final class ApiKeyConfigurer extends SecurityConfigurer

Sign-in with an API key on each request.

@Bean
SecurityFilterChain api(HttpSecurity http) {
    http.securityMatcher("/api/**")
        .authorizeHttpRequests(auth -> auth
                .requestMatchers("/api/deploy/**").hasAuthority("SCOPE_deploy")
                .anyRequest().authenticated())
        .apiKey(Customizer.withDefaults());
    return http.build();
}

A client sends its key as X-API-Key: cn1_... or as Authorization: Bearer cn1_.... Keys are looked up in the application's ApiKeyRepository bean unless repository names another, and are made with ApiKeyGenerator.

On a chain that also has oauth2ResourceServer(...), a bearer value that starts with the key prefix is an API key and any other is a token; that is the whole rule, and the reason the prefix here has to be the one the keys were generated with.

A request authenticated by its key is not asked for a CSRF token, and no session is started for it. A key's scopes are the authorities SCOPE_x.