Client API. The Codename One framework your app is built on: this runs on the device, not in a backend.
public class OidcException
- Object
- Throwable
- Exception
- IOException
- OidcException
Thrown for failures during an OpenID Connect / OAuth 2.0 flow driven by
OidcClient. The getError() code mirrors the error field from RFC 6749
for authorization-server responses (e.g. "access_denied", "invalid_grant")
and uses Codename One-specific values for transport or client-side problems
("transport_error", "state_mismatch", "nonce_mismatch", "user_cancelled",
"discovery_failed", "invalid_id_token", "issuer_mismatch",
"storage_unavailable", "invalid_response").Fields
public static final String ACCESS_DENIED = "access_denied" | Authorization server returned error=access_denied. |
public static final String USER_CANCELLED = "user_cancelled" | User cancelled the system browser / native sign-in sheet. |
public static final String STATE_MISMATCH = "state_mismatch" | state returned by the authorization server did not match the one we sent. |
public static final String NONCE_MISMATCH = "nonce_mismatch" | nonce claim on the returned ID token did not match the one we sent. |
public static final String DISCOVERY_FAILED = "discovery_failed" | The discovery document could not be fetched or parsed. |
public static final String INVALID_GRANT = "invalid_grant" | The authorization grant or refresh token was rejected. |
public static final String INVALID_RESPONSE = "invalid_response" | The endpoint returned a missing, malformed or incomplete protocol response. |
public static final String INVALID_ID_TOKEN = "invalid_id_token" | The ID token was not accepted: it is malformed, it is for another client or from another issuer, it has expired, it does not belong to the access token it came with, or its signature does not verify against the provider’s keys – which includes a platform that cannot check a signature of that kind. |
public static final String ISSUER_MISMATCH = "issuer_mismatch" | The authorization response names another issuer than the provider the request was sent to, or none where the provider says it always names one (RFC 9207). |
public static final String TRANSPORT_ERROR = "transport_error" | Generic transport / network failure: no answer, or an answer that is not an OAuth one – a status other than success with no OAuth error in its body. |
public static final String STORAGE_UNAVAILABLE = "storage_unavailable" | A TokenStore could not read, write or remove the tokens – the platform has no secure storage, or the store failed. |
public static final String AUTHORIZATION_PENDING = "authorization_pending" | Device grant: the user has not finished approving the device yet. |
public static final String SLOW_DOWN = "slow_down" | Device grant: the device asked too often; it must wait longer between requests. |
public static final String EXPIRED_TOKEN = "expired_token" | Device grant: the device code ran out before the user approved it. |
Constructors
public OidcException(String error, String message) | |
public OidcException(String error, String message, Throwable cause) |
Methods
public String getError() | The short error code (see the constants on this class). |
public String getErrorDescription() | Human-readable description supplied by the server or the client. |
Inherited methods
Field details
ACCESS_DENIED
public static final String ACCESS_DENIED = "access_denied"Authorization server returned
error=access_denied.USER_CANCELLED
public static final String USER_CANCELLED = "user_cancelled"User cancelled the system browser / native sign-in sheet.
STATE_MISMATCH
public static final String STATE_MISMATCH = "state_mismatch"state returned by the authorization server did not match the one we sent.NONCE_MISMATCH
public static final String NONCE_MISMATCH = "nonce_mismatch"nonce claim on the returned ID token did not match the one we sent.DISCOVERY_FAILED
public static final String DISCOVERY_FAILED = "discovery_failed"The discovery document could not be fetched or parsed.
INVALID_GRANT
public static final String INVALID_GRANT = "invalid_grant"The authorization grant or refresh token was rejected.
INVALID_RESPONSE
public static final String INVALID_RESPONSE = "invalid_response"The endpoint returned a missing, malformed or incomplete protocol response.
INVALID_ID_TOKEN
public static final String INVALID_ID_TOKEN = "invalid_id_token"The ID token was not accepted: it is malformed, it is for another client or from
another issuer, it has expired, it does not belong to the access token it came
with, or its signature does not verify against the provider’s keys – which
includes a platform that cannot check a signature of that kind. See
OidcClient.setVerifyIdTokenSignature(boolean).ISSUER_MISMATCH
public static final String ISSUER_MISMATCH = "issuer_mismatch"The authorization response names another issuer than the provider the request was
sent to, or none where the provider says it always names one (RFC 9207).
TRANSPORT_ERROR
public static final String TRANSPORT_ERROR = "transport_error"Generic transport / network failure: no answer, or an answer that is not an OAuth
one – a status other than success with no OAuth
error in its body.STORAGE_UNAVAILABLE
public static final String STORAGE_UNAVAILABLE = "storage_unavailable"A
TokenStore could not read, write or remove the tokens – the platform has no
secure storage, or the store failed.AUTHORIZATION_PENDING
public static final String AUTHORIZATION_PENDING = "authorization_pending"Device grant: the user has not finished approving the device yet. Polling continues.
SLOW_DOWN
public static final String SLOW_DOWN = "slow_down"Device grant: the device asked too often; it must wait longer between requests.
EXPIRED_TOKEN
public static final String EXPIRED_TOKEN = "expired_token"Device grant: the device code ran out before the user approved it.
Constructor details
OidcException
public OidcException(String error, String message)OidcException
public OidcException(String error, String message, Throwable cause)Method details
getError
public String getError()The short error code (see the constants on this class).
getErrorDescription
public String getErrorDescription()Human-readable description supplied by the server or the client.