Package com.codename1.backend.security.oauth2.server.authorization
package com.codename1.backend.security.oauth2.server.authorization
An OAuth2 authorization server and OpenID Connect provider: the server that signs users in on behalf of clients and issues them tokens. The clients it knows, the grants it has made, its settings and keys, and the endpoints themselves.
Turned on with http.authorizationServer(...); see
AuthorizationServerConfigurer. A server
that does not call it carries none of this.
-
ClassDescriptionThe keys an authorization server signs with.Who the authorization server is and where its endpoints are.Builds an
AuthorizationServerSettings.What is asked of one client beyond what OAuth2 asks of every client.Builds aClientSettings.Grants kept in this process: gone when it stops, and unknown to any other.Clients given when the server starts, and kept in this process.Grants kept in the server's database, in thecn1_oauth2_authorizationandcn1_oauth2_tokentables ofSecuritySchema: what lets tokens outlive a restart, and several processes be one authorization server.Clients kept in the server's database, in thecn1_oauth2_registered_clienttable ofSecuritySchema.One grant: a user -- or, for the device grant, nobody yet -- having let one client act with some scopes.The endpoints of an authorization server, each a method that takes a request and answers it.Where an authorization server keeps the grants it has made and the secrets it issued under them.One stored secret, asOAuth2AuthorizationService.findToken(String, String)reports it.Checks a signed access token against its live authorization grant, including client-credentials grants.One token about to be signed, as anOAuth2TokenCustomizersees it.Changes the claims of the tokens an authorization server signs: adds the user's roles to an access token, a tenant to an ID token.What an authorization server says of a user: the claims of the/userinfoanswer and of an ID token, beyondsub.A client this authorization server issues tokens to.Builds aRegisteredClient.The clients an authorization server knows.How long what is issued to one client lasts, in seconds.Builds aTokenSettings.