Class OidcIdTokenDecoderFactory
java.lang.Object
com.codename1.backend.security.oauth2.client.OidcIdTokenDecoderFactory
Makes, and keeps, the decoder that verifies the ID tokens of one registration.
A token is accepted when its signature verifies under a key the provider
publishes at its jwks_uri, with a public key algorithm the registration
allows -- never one the token merely names -- and when
issis the registration's issuer, or for a provider with one issuer per tenant, the template with the token's owntidin it;audcontains the client id, and when it names more than one audience,azpis the client id;exphas not passed, andiatandsubare there.
The nonce is checked by the sign-in, which is what knows the value that
was sent.
-
Constructor Summary
ConstructorsConstructorDescription -
Method Summary
Modifier and TypeMethodDescriptioncreateDecoder(ClientRegistration registration) The decoder ofregistration: one for as long as the server runs, so the provider's keys are fetched once and kept.
-
Constructor Details
-
OidcIdTokenDecoderFactory
public OidcIdTokenDecoderFactory() -
OidcIdTokenDecoderFactory
- Parameters:
fetcher- what reads the provider's keys
-
-
Method Details
-
createDecoder
The decoder ofregistration: one for as long as the server runs, so the provider's keys are fetched once and kept.
-