Package com.codename1.backend.security.oauth2.server.resource
package com.codename1.backend.security.oauth2.server.resource
A server whose routes are reached with a bearer token (RFC 6750): finding the token in a request, verifying it as a JWT, turning its claims into who is calling and what they may do, and answering a request whose token is missing, bad or not enough.
Turned on with http.oauth2ResourceServer(...); see
OAuth2ResourceServerConfigurer.
-
ClassDescriptionAnswers a request whose token is good and does not grant what the request needs, as RFC 6750 3.1 says to:Answers a request that needs a bearer token and has none, or has a bad one, as RFC 6750 3 says to:A bearer token as it came off a request: nobody yet, until something that can verify it says who.An error a request with a bearer token is answered with (RFC 6750 3.1): the code, the status it is sent under, and the scope it would have needed.The three errors of RFC 6750 3.1.Finds the bearer token in a request.Finds the token in the
Authorization: Bearerheader.The bearer token of a request was looked at and refused; the message is why.Makes theJwtAuthenticationTokenof a verified token: its authorities, through aJwtGrantedAuthoritiesConverterunless another is set, and its name, from thesubclaim unless another is named.Authenticates a bearer token by verifying it as a JWT.Who a request is from, when a verified JWT says so.Reads a token's authorities out of one claim: each value, with a prefix in front.For a server that takes tokens from several issuers: each token is verified by the issuer it says it is from, and only by that one.