Class OidcException
java.lang.Object
java.lang.Throwable
java.lang.Exception
java.io.IOException
com.codename1.io.oidc.OidcException
Thrown for failures during an OpenID Connect / OAuth 2.0 flow driven by
OidcClient. The getError() code mirrors the error field from RFC 6749
for authorization-server responses (e.g. "access_denied", "invalid_grant")
and uses Codename One-specific values for transport or client-side problems
("transport_error", "state_mismatch", "nonce_mismatch", "user_cancelled",
"discovery_failed", "invalid_id_token", "issuer_mismatch",
"storage_unavailable", "invalid_response").-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringAuthorization server returnederror=access_denied.static final StringDevice grant: the user has not finished approving the device yet.static final StringThe discovery document could not be fetched or parsed.static final StringDevice grant: the device code ran out before the user approved it.static final StringThe authorization grant or refresh token was rejected.static final StringThe ID token was not accepted: it is malformed, it is for another client or from another issuer, it has expired, it does not belong to the access token it came with, or its signature does not verify against the provider's keys -- which includes a platform that cannot check a signature of that kind.static final StringThe endpoint returned a missing, malformed or incomplete protocol response.static final StringThe authorization response names another issuer than the provider the request was sent to, or none where the provider says it always names one (RFC 9207).static final Stringnonceclaim on the returned ID token did not match the one we sent.static final StringDevice grant: the device asked too often; it must wait longer between requests.static final Stringstatereturned by the authorization server did not match the one we sent.static final StringATokenStorecould not read, write or remove the tokens -- the platform has no secure storage, or the store failed.static final StringGeneric transport / network failure: no answer, or an answer that is not an OAuth one -- a status other than success with no OAutherrorin its body.static final StringUser cancelled the system browser / native sign-in sheet. -
Constructor Summary
ConstructorsConstructorDescriptionOidcException(String error, String message) OidcException(String error, String message, Throwable cause) -
Method Summary
Modifier and TypeMethodDescriptiongetError()The short error code (see the constants on this class).Human-readable description supplied by the server or the client.Methods inherited from class Throwable
addSuppressed, getCause, getLocalizedMessage, getMessage, getStackTrace, getSuppressed, initCause, printStackTrace, printStackTrace, setStackTrace, toString
-
Field Details
-
ACCESS_DENIED
Authorization server returnederror=access_denied.- See Also:
-
USER_CANCELLED
User cancelled the system browser / native sign-in sheet.- See Also:
-
STATE_MISMATCH
statereturned by the authorization server did not match the one we sent.- See Also:
-
NONCE_MISMATCH
nonceclaim on the returned ID token did not match the one we sent.- See Also:
-
DISCOVERY_FAILED
The discovery document could not be fetched or parsed.- See Also:
-
INVALID_GRANT
The authorization grant or refresh token was rejected.- See Also:
-
INVALID_RESPONSE
The endpoint returned a missing, malformed or incomplete protocol response.- See Also:
-
INVALID_ID_TOKEN
The ID token was not accepted: it is malformed, it is for another client or from another issuer, it has expired, it does not belong to the access token it came with, or its signature does not verify against the provider's keys -- which includes a platform that cannot check a signature of that kind. SeeOidcClient.setVerifyIdTokenSignature(boolean).- See Also:
-
ISSUER_MISMATCH
The authorization response names another issuer than the provider the request was sent to, or none where the provider says it always names one (RFC 9207).- See Also:
-
TRANSPORT_ERROR
Generic transport / network failure: no answer, or an answer that is not an OAuth one -- a status other than success with no OAutherrorin its body.- See Also:
-
STORAGE_UNAVAILABLE
ATokenStorecould not read, write or remove the tokens -- the platform has no secure storage, or the store failed.- See Also:
-
AUTHORIZATION_PENDING
Device grant: the user has not finished approving the device yet. Polling continues.- See Also:
-
SLOW_DOWN
Device grant: the device asked too often; it must wait longer between requests.- See Also:
-
EXPIRED_TOKEN
Device grant: the device code ran out before the user approved it.- See Also:
-
-
Constructor Details
-
OidcException
-
OidcException
-
-
Method Details
-
getError
The short error code (see the constants on this class). -
getErrorDescription
Human-readable description supplied by the server or the client.
-