Class RemoteJwkSet
java.lang.Object
com.codename1.backend.security.oauth2.jwt.RemoteJwkSet
- All Implemented Interfaces:
JwkSource
The keys another server publishes at its jwks_uri, fetched when they are
first needed and kept.
- The set is kept for five minutes, then fetched again by the next request that needs it.
- A token naming a key the set does not have makes it fetch early -- that is how a rotated key is picked up -- but no more than once in thirty seconds, so tokens with invented key ids cannot turn this server into a stream of requests at the issuer.
- One request fetches at a time. The others carry on with the set they have, or fail if the first fetch has not supplied any keys yet. Failed initial fetches observe the same retry interval. No request waits for another request's network operation.
- When a fetch fails and there is a set, the set goes on being used and the fetch is tried again later. An issuer that is briefly unreachable does not sign everybody out.
Use an https address. The keys are what every token is trusted by, and
they are only as trustworthy as the connection they came over.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic interfaceFetches the text at an address. -
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final RemoteJwkSet.FetcherThe runtime's HTTP client, asking for JSON. -
Constructor Summary
ConstructorsConstructorDescriptionRemoteJwkSet(String uri) RemoteJwkSet(String uri, RemoteJwkSet.Fetcher fetcher) -
Method Summary
Modifier and TypeMethodDescriptiongetKeys()The keys, the one to sign with first.getUri()refresh()The keys, fetched again unless a fetch is in progress or the refresh interval has not elapsed.voidsetCacheSeconds(long seconds) How long a fetched set is used before it is fetched again; five minutes unless set.voidvoidsetRefreshIntervalSeconds(long seconds) The least time between two fetches, whatever asks for them; thirty seconds unless set.
-
Field Details
-
WEB
The runtime's HTTP client, asking for JSON.
-
-
Constructor Details
-
RemoteJwkSet
-
RemoteJwkSet
-
-
Method Details
-
setCacheSeconds
public void setCacheSeconds(long seconds) How long a fetched set is used before it is fetched again; five minutes unless set. -
setRefreshIntervalSeconds
public void setRefreshIntervalSeconds(long seconds) The least time between two fetches, whatever asks for them; thirty seconds unless set. -
setClock
-
getUri
-
getKeys
Description copied from interface:JwkSourceThe keys, the one to sign with first.- Specified by:
getKeysin interfaceJwkSource- Throws:
IOException- when the keys cannot be had: a server that publishes them is not answering
-
refresh
The keys, fetched again unless a fetch is in progress or the refresh interval has not elapsed.- Throws:
IOException
-