Package com.codename1.backend.security.apikey
package com.codename1.backend.security.apikey
API keys: long-lived secrets a program presents instead of signing in.
A key is generated once and shown once. What is stored is its SHA-256, so a copy of the table is not a set of working keys, and a request is authenticated by hashing what it presents and looking that up.
GeneratedApiKey made = new ApiKeyGenerator().generate("ci-bot", "deploy", "read");
repository.save(made.getApiKey()); // the hash, the owner, the scopes
show(made.getPlaintext()); // cn1_Zm9v...; never available again
Turned on with http.apiKey(...); see
ApiKeyConfigurer.
-
ClassDescriptionWhat a server keeps about an API key: who it acts for, what it may do, whether it has been revoked, and the SHA-256 by which a presented key is recognized.Who a request is from, when an API key says so.Makes API keys: a prefix, then 32 random bytes as base64url.Where API keys are kept.A key that has just been made: the one moment its text exists.API keys held in memory: for tests, and for a server whose few keys come from its configuration.API keys kept in the server's database, in the
cn1_api_keytable ofSecuritySchema.