Class DefaultBearerTokenResolver
java.lang.Object
com.codename1.backend.security.oauth2.server.resource.DefaultBearerTokenResolver
- All Implemented Interfaces:
BearerTokenResolver
Finds the token in the Authorization: Bearer header.
A token in the address -- ?access_token=... -- is read only when
setAllowUriQueryParameter(boolean) says so, and then on a GET alone. An address is
what ends up in access logs, browser history and the Referer of the next
page, which is no place for a credential; the switch exists for the client
that cannot set a header, an EventSource or a download link.
A request with a token in both places is refused rather than guessed at.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionresolve(HttpServer.Request request) The token, or null when the request carries none.voidsetAllowUriQueryParameter(boolean allowUriQueryParameter) Whetheraccess_tokenin the query of a GET is read; not, unless set.voidsetBearerTokenHeaderName(String bearerTokenHeaderName) The header the token is read from;Authorizationunless set.
-
Constructor Details
-
DefaultBearerTokenResolver
public DefaultBearerTokenResolver()
-
-
Method Details
-
setAllowUriQueryParameter
public void setAllowUriQueryParameter(boolean allowUriQueryParameter) Whetheraccess_tokenin the query of a GET is read; not, unless set. -
setBearerTokenHeaderName
The header the token is read from;Authorizationunless set. For a server behind a proxy that keepsAuthorizationfor itself. -
resolve
Description copied from interface:BearerTokenResolverThe token, or null when the request carries none.
OAuth2AuthenticationException: when the request carries one that is malformed, or more than one
- Specified by:
resolvein interfaceBearerTokenResolver
-