Class DefaultJwtDecoder
- All Implemented Interfaces:
JwtDecoder
Verifies tokens against keys it holds, or keys an issuer publishes.
JwtDecoder local = DefaultJwtDecoder.withPublicKey(KeyFiles.readPublicKey(path)).build();
JwtDecoder remote = DefaultJwtDecoder.withJwkSetUri("https://id.example.com/jwks")
.jwsAlgorithms(SignatureAlgorithm.RS256, SignatureAlgorithm.ES256).build();
JwtDecoder own = DefaultJwtDecoder.withSecretKey(secret).build();
Which algorithm verifies a token
Not the one the token asks for. A decoder is built with the algorithms it accepts -- RS256 unless told otherwise, or the one a single key is for -- and a token is verified only when all of these agree:
- its
algheader is one of the accepted algorithms; - the decoder has a key of the kind that algorithm is defined over: an RSA key for RS256/384/512 and PS256, a P-256 key for ES256, a P-384 key for ES384, a shared secret for HS256/384/512;
- when the token names a
kid, that key has it.
So alg: none is refused, because no decoder accepts it; and a token signed
with HMAC using an RSA public key as the secret is refused, because the
decoder that holds that public key does not accept HS256, and would have no
shared secret to check it with if it did.
What else is checked
The validators given with setJwtValidator(OAuth2TokenValidator); exp and nbf unless set.
A decoder does not check iss or aud until it is told what they should
be -- JwtDecoders.fromIssuerLocation(String) tells it the first.
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionThe token, once its signature has verified and its claims have passed the decoder's validators.voidsetJwtValidator(OAuth2TokenValidator<Jwt> jwtValidator) What a token's claims are put to once its signature has verified;JwtValidators.createDefault()unless set.static DefaultJwtDecoder.BuilderwithJwkSetUri(String jwkSetUri) A decoder over the keys published atjwkSetUri, fetched when first needed; seeRemoteJwkSet.static DefaultJwtDecoder.BuilderwithJwkSource(JwkSource keys) A decoder over these keys; RS256 unless told otherwise.static DefaultJwtDecoder.BuilderwithPublicKey(byte[] publicKey) A decoder for tokens signed by the private half of one public key, given as SubjectPublicKeyInfo DER; seeKeyFiles.publicKey(String).static DefaultJwtDecoder.BuilderwithSecretKey(byte[] secret) A decoder for tokens this server signed itself with a shared secret; HS256 unless told otherwise.
-
Method Details
-
withPublicKey
A decoder for tokens signed by the private half of one public key, given as SubjectPublicKeyInfo DER; seeKeyFiles.publicKey(String). It accepts RS256 for an RSA key and the curve's algorithm for an EC key. -
withJwkSource
A decoder over these keys; RS256 unless told otherwise. -
withJwkSetUri
A decoder over the keys published atjwkSetUri, fetched when first needed; seeRemoteJwkSet. RS256 unless told otherwise. -
withSecretKey
A decoder for tokens this server signed itself with a shared secret; HS256 unless told otherwise. -
setJwtValidator
What a token's claims are put to once its signature has verified;JwtValidators.createDefault()unless set. -
decode
Description copied from interface:JwtDecoderThe token, once its signature has verified and its claims have passed the decoder's validators.
BadJwtException: when the token is not acceptable, with whyJwtException: when it could not be judged at all
- Specified by:
decodein interfaceJwtDecoder
-