Class DefaultJwtDecoder

java.lang.Object
com.codename1.backend.security.oauth2.jwt.DefaultJwtDecoder
All Implemented Interfaces:
JwtDecoder

public final class DefaultJwtDecoder extends Object implements JwtDecoder

Verifies tokens against keys it holds, or keys an issuer publishes.

JwtDecoder local = DefaultJwtDecoder.withPublicKey(KeyFiles.readPublicKey(path)).build();
JwtDecoder remote = DefaultJwtDecoder.withJwkSetUri("https://id.example.com/jwks")
        .jwsAlgorithms(SignatureAlgorithm.RS256, SignatureAlgorithm.ES256).build();
JwtDecoder own = DefaultJwtDecoder.withSecretKey(secret).build();
Which algorithm verifies a token

Not the one the token asks for. A decoder is built with the algorithms it accepts -- RS256 unless told otherwise, or the one a single key is for -- and a token is verified only when all of these agree:

  • its alg header is one of the accepted algorithms;
  • the decoder has a key of the kind that algorithm is defined over: an RSA key for RS256/384/512 and PS256, a P-256 key for ES256, a P-384 key for ES384, a shared secret for HS256/384/512;
  • when the token names a kid, that key has it.

So alg: none is refused, because no decoder accepts it; and a token signed with HMAC using an RSA public key as the secret is refused, because the decoder that holds that public key does not accept HS256, and would have no shared secret to check it with if it did.

What else is checked

The validators given with setJwtValidator(OAuth2TokenValidator); exp and nbf unless set. A decoder does not check iss or aud until it is told what they should be -- JwtDecoders.fromIssuerLocation(String) tells it the first.

  • Method Details

    • withPublicKey

      public static DefaultJwtDecoder.Builder withPublicKey(byte[] publicKey)
      A decoder for tokens signed by the private half of one public key, given as SubjectPublicKeyInfo DER; see KeyFiles.publicKey(String). It accepts RS256 for an RSA key and the curve's algorithm for an EC key.
    • withJwkSource

      public static DefaultJwtDecoder.Builder withJwkSource(JwkSource keys)
      A decoder over these keys; RS256 unless told otherwise.
    • withJwkSetUri

      public static DefaultJwtDecoder.Builder withJwkSetUri(String jwkSetUri)
      A decoder over the keys published at jwkSetUri, fetched when first needed; see RemoteJwkSet. RS256 unless told otherwise.
    • withSecretKey

      public static DefaultJwtDecoder.Builder withSecretKey(byte[] secret)
      A decoder for tokens this server signed itself with a shared secret; HS256 unless told otherwise.
    • setJwtValidator

      public void setJwtValidator(OAuth2TokenValidator<Jwt> jwtValidator)
      What a token's claims are put to once its signature has verified; JwtValidators.createDefault() unless set.
    • decode

      public Jwt decode(String token)
      Description copied from interface: JwtDecoder

      The token, once its signature has verified and its claims have passed the decoder's validators.

      Specified by:
      decode in interface JwtDecoder