Package com.codename1.backend.security.oauth2.jwt


package com.codename1.backend.security.oauth2.jwt

JSON Web Tokens signed with a public key algorithm or a shared secret: JwtDecoder verifies one and reads its claims, JwtEncoder makes one.

JwtDecoder decoder = JwtDecoders.fromIssuerLocation("https://accounts.example.com");
Jwt jwt = decoder.decode(token);       // BadJwtException says why not
String user = jwt.getSubject();

Which algorithm verifies a token is settled by the key the decoder holds and the algorithms it was told to accept, and the token's own alg header has to agree with both. A token that says none, or says HS256 to a decoder that holds an RSA public key, is refused before anything is computed.

com.codename1.backend.Jwt is not part of this: it issues and checks HS256 tokens between a server and itself, and stays as it is.

  • Class
    Description
    The token itself is not acceptable: it is malformed, its signature does not verify, it names an algorithm or a key the decoder does not accept, or it fails a validator.
    Verifies tokens against keys it holds, or keys an issuer publishes.
    Signs tokens with the keys of a JwkSource.
    The header of a signature that is about to be made: which algorithm, and optionally which key and what type of token.
    Builds a JwsHeader.
    A JSON Web Token whose signature has been made or verified: its text, the headers of its signature and its claims.
    Refuses a token that is not for this server: one whose aud names none of the audiences given here.
    The claims RFC 7519 registers.
    The claims of a token that is about to be signed.
    Builds a JwtClaimsSet.
    Refuses a token unless one of its claims passes a test.
    Verifies a token and reads its claims.
    Makes a decoder for an issuer from what the issuer says about itself.
    Signs tokens.
    What a JwtEncoder is asked to sign: claims, and optionally a header.
    A token could not be signed: there is no key for it, or the key does not fit the algorithm.
    A token could not be made or could not be judged: a key is missing or unusable, the server that publishes the keys did not answer.
    Refuses a token whose iss is not exactly the issuer this server trusts.
    Refuses a token past its exp or ahead of its nbf, with a minute's allowance either way for two machines whose clocks disagree.
    A token whose signature verified and whose claims did not pass: expired, not yet valid, from another issuer, meant for another audience.
    The validators a decoder is usually given.
    The keys another server publishes at its jwks_uri, fetched when they are first needed and kept.
    Fetches the text at an address.
    A decoder that is made when the first token arrives, and then kept.