Interface OidcUserInfoMapper


public interface OidcUserInfoMapper

What an authorization server says of a user: the claims of the /userinfo answer and of an ID token, beyond sub.

http.authorizationServer(as -> as.userInfoMapper((username, scopes) -> {
    Account account = accounts.byName(username);
    Map<String, Object> claims = new LinkedHashMap<>();
    if (scopes.contains("email")) {
        claims.put("email", account.getEmail());
        claims.put("email_verified", account.isEmailConfirmed());
    }
    if (scopes.contains("profile")) {
        claims.put("name", account.getDisplayName());
    }
    return claims;
}));

Without one, profile yields preferred_username, the user's name here, and email yields nothing: this server does not know that a user name is an address, let alone a verified one.

  • Method Summary

    Modifier and Type
    Method
    Description
    getClaims(String username, Set<String> scopes)
    The claims of username that scopes entitle a client to.
  • Method Details

    • getClaims

      Map<String,Object> getClaims(String username, Set<String> scopes)
      The claims of username that scopes entitle a client to. sub is added by the server and cannot be replaced.