Class RegisteredClient

java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.RegisteredClient

public final class RegisteredClient extends Object

A client this authorization server issues tokens to.

RegisteredClient app = RegisteredClient.withId("mobile")
        .clientId("acme-app")
        .clientAuthenticationMethod(ClientAuthenticationMethod.NONE)   // public: PKCE
        .authorizationGrantType(AuthorizationGrantType.AUTHORIZATION_CODE)
        .authorizationGrantType(AuthorizationGrantType.REFRESH_TOKEN)
        .redirectUri("com.acme.app:/oauth2redirect")
        .scope("openid").scope("profile").scope("orders:read")
        .build();

A redirect address is matched whole, character for character: there are no wildcards. The one exception is RFC 8252's: an http address on 127.0.0.1 or [::1] may be asked for with any port, because a native application cannot know which one it will get.

A secret is stored as its PasswordEncoder wrote it, never as it was issued.

  • Method Details

    • withId

      public static RegisteredClient.Builder withId(String id)
      A client stored under id, which is the server's own name for it and never changes; the clientId is what the client calls itself.
    • getId

      public String getId()
    • getClientId

      public String getClientId()
    • getClientSecret

      public String getClientSecret()
      The encoded secret, or null for a client without one.
    • getClientName

      public String getClientName()
    • getClientAuthenticationMethods

      public Set<ClientAuthenticationMethod> getClientAuthenticationMethods()
    • getAuthorizationGrantTypes

      public Set<AuthorizationGrantType> getAuthorizationGrantTypes()
    • getRedirectUris

      public Set<String> getRedirectUris()
    • getScopes

      public Set<String> getScopes()
      Every scope the client may be granted.
    • getResources

      public Set<String> getResources()
      The resource servers the client may ask for tokens for, each by the address it is named with in a token's aud; empty when the client was registered with none, and may then name any. See RegisteredClient.Builder.resource(String).
    • getClientSettings

      public ClientSettings getClientSettings()
    • getTokenSettings

      public TokenSettings getTokenSettings()
    • isPublic

      public boolean isPublic()
      Whether the client is a public one: it authenticates with nothing, and so must prove with PKCE that the code it redeems is the one it asked for.
    • toString

      public String toString()
      Description copied from class: Object
      Returns a string representation of the object. In general, the toString method returns a string that "textually represents" this object. The result should be a concise but informative representation that is easy for a person to read. It is recommended that all subclasses override this method. The toString method for class Object returns a string consisting of the name of the class of which the object is an instance, the at-sign character `@', and the unsigned hexadecimal representation of the hash code of the object. In other words, this method returns a string equal to the value of: getClass().getName() + '@' + Integer.toHexString(hashCode())
      Overrides:
      toString in class Object
    • isResource

      public static boolean isResource(String resource)
      Whether resource can name a resource server: an absolute URI with no fragment, as RFC 8707 section 2 requires of the parameter.