Class SecurityMockMvcRequestPostProcessors

java.lang.Object
com.codename1.backend.test.SecurityMockMvcRequestPostProcessors

public final class SecurityMockMvcRequestPostProcessors extends Object

What a test says about one request's security, for static import:

mvc.perform(post("/notes").with(user("ada").roles("EDITOR")).with(csrf())
        .content("{}"));
mvc.perform(get("/api/orders").with(httpBasic("svc", "secret")));

user(String) and authentication(Authentication) say who the request is from, without asking a user store; csrf() gives a state-changing request the token its chain demands; httpBasic(String, String) sends real credentials for the chain to check. jwt() and apiKey(String) say the request came with a bearer token or an API key that was accepted -- with these claims, these scopes -- without a key to sign one with or a store to look one up in:

mvc.perform(get("/api/orders").with(jwt().subject("svc").scopes("orders:read")));
mvc.perform(get("/api/orders").with(apiKey("billing").scopes("orders:read")));