Class BearerTokenAuthenticationEntryPoint
java.lang.Object
com.codename1.backend.security.oauth2.server.resource.BearerTokenAuthenticationEntryPoint
- All Implemented Interfaces:
AuthenticationEntryPoint
public final class BearerTokenAuthenticationEntryPoint
extends Object
implements AuthenticationEntryPoint
Answers a request that needs a bearer token and has none, or has a bad one, as RFC 6750 3 says to:
401 WWW-Authenticate: Bearer
401 WWW-Authenticate: Bearer realm="orders", scope="orders:read"
401 WWW-Authenticate: Bearer error="invalid_token", error_description="Jwt expired at ...",
error_uri="https://tools.ietf.org/html/rfc6750#section-3.1"
400 WWW-Authenticate: Bearer error="invalid_request", error_description="Found multiple ..."
A request that sent no token is told that one is wanted, never an error. When the rule that refused it asks for a scope the challenge names it, and it names the realm when one was set. One that sent a token is told what was wrong with it.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptioncommence(HttpServer.Request request, AuthenticationException authException) The answer.voidsetRealmName(String realmName) A realm to name in the challenge; none unless set.
-
Constructor Details
-
BearerTokenAuthenticationEntryPoint
public BearerTokenAuthenticationEntryPoint()
-
-
Method Details
-
setRealmName
A realm to name in the challenge; none unless set. -
commence
public HttpServer.Response commence(HttpServer.Request request, AuthenticationException authException) Description copied from interface:AuthenticationEntryPointThe answer.- Specified by:
commencein interfaceAuthenticationEntryPoint- Parameters:
authException- why the request was not let through
-