Class JwtIssuerAuthenticationManagerResolver

java.lang.Object
com.codename1.backend.security.oauth2.server.resource.JwtIssuerAuthenticationManagerResolver
All Implemented Interfaces:
AuthenticationManagerResolver

public final class JwtIssuerAuthenticationManagerResolver extends Object implements AuthenticationManagerResolver

For a server that takes tokens from several issuers: each token is verified by the issuer it says it is from, and only by that one.

http.oauth2ResourceServer(o -> o.authenticationManagerResolver(
        JwtIssuerAuthenticationManagerResolver.fromTrustedIssuers(
                "https://login.example.com", "https://partners.example.com")));

The iss claim is read out of the token before anything has verified it, and used for one thing: choosing which trusted issuer's keys to verify with. A token that names an issuer not on the list is refused without a request being made anywhere -- the list is what stops a token from pointing the server at keys of its author's choosing. A token that names a trusted issuer it did not come from fails that issuer's signature check.

An issuer's metadata is fetched when its first token arrives, and kept.