Class OAuth2LoginConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.OAuth2LoginConfigurer

public final class OAuth2LoginConfigurer extends SecurityConfigurer

Sign-in through another identity provider, with OAuth2 or OpenID Connect.

http.authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
    .oauth2Login(Customizer.withDefaults());

with, in application.properties,

cn1.security.oauth2.client.registration.google.client-id=...
cn1.security.oauth2.client.registration.google.client-secret=...

The providers are the application's ClientRegistrationRepository bean, or the registrations the configuration declares; see ClientRegistrations and CommonOAuth2Provider.

A sign-in starts at GET /oauth2/authorization/{registrationId}, which sends the browser to the provider, and ends at /login/oauth2/code/{registrationId}, where the provider sends it back. Every request carries a state, a PKCE challenge and, with OpenID Connect, a nonce; the answer is taken only when it repeats the state this browser was given, the code is exchanged with the PKCE verifier, and an ID token is accepted only as OidcIdTokenDecoderFactory describes and with that nonce in it.

Who the provider's user is here is the OAuth2UserService's to say; see userService and oidcUserService, and LinkingOAuth2UserService for tying them to the application's own users. The sign-in then ends the way every sign-in to a session does -- see SessionSignIn -- so a second factor and remember-me apply to it.

A signed-in user goes back to the page that asked for the sign-in, or to defaultSuccessUrl: nothing the provider or the request says chooses the address. A refused one goes to /login?error, and is told nothing of why; the reason, as an OAuth2 error code, is the AuthenticationFailureHandler's to read from the exception.

A chain that serves no login page of its own serves a plain one at GET /login with a link per provider, and sends a request that must sign in straight to the provider when there is only one.