All Classes and Interfaces

Class
Description
The parts every Authentication shares: its authorities, its details and the name read off its principal.
Class AbstractCollection is an abstract implementation of the Collection interface.
AbstractList is an abstract implementation of the List interface, optimized for a backing store which supports random access.
This class is an abstract implementation of the Map interface.
A key-value mapping.
An immutable key-value mapping.
Exception thrown when an attempt is made to call an abstract method.
AbstractQueue is an abstract class which implements some of the methods in Queue.
AbstractSequentialList is an abstract implementation of the List interface.
An AbstractSet is an abstract implementation of the Set interface.
The caller may not do what it asked.
Answers a signed-in caller that asked for something it may not have.
Answers 403.
The account has expired.
The account exists and may not be used as it stands: locked, disabled or expired.
 
A mirror of java.lang.Annotation.
A mirror of java.lang.annotation.AnnotationFormatError.
Gives a request nobody signed in for an AnonymousAuthenticationToken, so the rules that follow always have an authentication to judge.
Who a request is from when nobody signed in: a principal called anonymousUser holding ROLE_ANONYMOUS, so authorization rules always have someone to ask about.
The authentication of a request nobody signed in for; see AnonymousAuthenticationToken.
Matches a request's path against an Ant-style pattern, and optionally its method.
Matches every request.
What a server keeps about an API key: who it acts for, what it may do, whether it has been revoked, and the SHA-256 by which a presented key is recognized.
Authenticates a request from the API key it presents, in X-API-Key or as Authorization: Bearer <key>.
Who a request is from, when an API key says so.
Sign-in with an API key on each request.
Makes API keys: a prefix, then 32 random bytes as base64url.
Where API keys are kept.
Declares methods to append characters or character sequences.
The client secret of Sign in with Apple, which is not a text Apple issues but a token this server signs: an ES256 JWT naming the team, the client and Apple, signed with the .p8 key downloaded from the developer account.
Thrown when an exceptional arithmetic condition has occurred.
Added this for Kotlin
An implementation of Deque, backed by an array.
Thrown to indicate that an array has been accessed with an illegal index.
ArrayList is an implementation of List, backed by an array.
Arrays contains static methods which operate on arrays.
Thrown to indicate that an attempt has been made to store the wrong type of object into an array of objects.
 
Runs this method on another thread; the caller returns at once.
A Future that is already complete: what an @Async method returns from its body.
CLDC11 subset stub.
CLDC11 subset stub.
CLDC11 subset stub.
CLDC11 subset stub.
Reflection-free conversion between a domain value and one SQL scalar.
Grants access by whether the caller signed in at all.
Who a request is from: a credential presented for checking, or -- once an AuthenticationManager has accepted it -- the principal and what it may do.
Keeps one kind of Authentication in the HTTP session, and makes it again on the next request.
Answers a request that has to authenticate first: with a challenge, or a redirect to where the user signs in.
The request could not be authenticated.
Answers a sign-in that was refused.
Decides whether a presented Authentication is genuine.
Chooses what authenticates a request, by the request: a server with several tenants, or tokens from several issuers.
Binds a handler parameter to the principal of whoever the request is from: the UserDetails the user store returned at sign-in, usually.
One way of checking an Authentication: a ProviderManager asks each of its providers that supports the token's class.
Authentication could not be attempted at all: the user store failed, or the layer is misconfigured.
Answers the request that signed a user in.
A decision that turned on what the caller is granted, with the authorities any one of which would have done.
Grants access to an authenticated caller holding one of a set of authorities.
Granted, or not.
Puts the request to the chain's authorization rules, and throws AccessDeniedException when they refuse it.
How a client obtains a token: the grant_type of RFC 6749 and RFC 8628.
Decides whether an authentication may reach something: for a request rule, a RequestAuthorizationContext.
Where an OAuth2AuthorizationRequest waits while the user is at the identity provider.
Makes the server an OAuth2 authorization server and OpenID Connect provider.
The keys an authorization server signs with.
Who the authorization server is and where its endpoints are.
The authorization rules of a chain: which requests need what.
 
Asks the build to inject this constructor, field or setter.
AWS Signature Version 4, and the request plumbing every AWS service shares.
A configured, running server: the twenty lines every main used to open with, written once.
 
Where the handlers are built, once the things they need exist.
Where a server's websocket endpoints come from.
Runs a test class against the application the build wired: what @SpringBootTest does.
How a BackendTest reaches the application.
The credentials are wrong: an unknown user or a password that does not match.
The token itself is not acceptable: it is malformed, its signature does not verify, it names an algorithm or a key the decoder does not accept, or it fails a validator.
Base32 encoder/decoder per RFC 4648.
Standard base64 (RFC 4648 section 4), with padding.
Base64url without padding, as JSON Web Tokens use it.
 
Answers 401 with the challenge that makes a client send HTTP Basic credentials: WWW-Authenticate: Basic realm="Realm".
Authenticates a request from its Authorization: Basic header.
bcrypt, as OpenBSD defined it and Spring's BCryptPasswordEncoder writes it: $2a$, $2b$ or $2y$, a cost, a 16 byte salt and a 23 byte hash.
A method of a Configuration class whose return value is a bean.
Answers a request whose token is good and does not grant what the request needs, as RFC 6750 3.1 says to:
Answers a request that needs a bearer token and has none, or has a bad one, as RFC 6750 3 says to:
Authenticates a request from its bearer token.
A bearer token as it came off a request: nobody yet, until something that can verify it says who.
An error a request with a bearer token is answered with (RFC 6750 3.1): the code, the status it is sent under, and the scope it would have needed.
The three errors of RFC 6750 3.1.
Finds the bearer token in a request.
 
 
 
Conversion errors, submitted values, and application validation for one form.
The BitSet class implements a bit field.
The Boolean class wraps a value of the primitive type boolean in an object.
The Byte class is the standard wrapper for byte values.
A ByteArrayInputStream contains an internal buffer that contains bytes that may be read from the stream.
This class implements an output stream in which the data is written into a byte array.
A growable byte buffer that callers reuse.
Calendar is an abstract base class for converting between a Date object and a set of integer fields such as YEAR, MONTH, DAY, HOUR, and so on.
Deprecated
Thrown by Future.get() when the work was cancelled before it ran.
Operations propagated from an entity to its related entities.
The Character class wraps a value of the primitive type char in an object.
This interface represents an ordered set of characters and defines the methods to probe them.
Added this for Kotlin
Instances of the class Class represent classes and interfaces in a running Java application.
Thrown to indicate that the code has attempted to cast an object to a subclass of which it is not an instance.
 
Thrown when an application tries to load in a class through its string name using the forName method in class Class but no definition for the class with the specified name could be found.
How a client proves which client it is at the token endpoint.
This server as a client of one identity provider: the id and secret the provider issued it, the scopes it asks for, and where the provider's endpoints are.
Where a client secret comes from when it is not a fixed text: Sign in with Apple's is a token this server signs.
Where the provider is.
The identity providers this server signs users in through.
Registrations read from the server's configuration, and from an issuer's metadata.
What is asked of one client beyond what OAuth2 asks of every client.
Builds a ClientSettings.
Where the parts of the layer that judge time -- a token's expiry, a rate limit's window -- read it from, so a test can move it.
 
This (empty) interface must be implemented by all classes that wish to support cloning.
Thrown when a program attempts to clone an object which does not support the Cloneable interface.
Collection is the root of the collection hierarchy.
Collections contains static methods which operate on Collection classes.
 
 
Renames or constrains an @Entity field's column.
One persisted field of an entity: what it is called in Java, what it is called in the database, and what kind of value it holds.
The settings of the identity providers most applications sign in through, so that a registration needs only the id and secret the provider issued.
This interface should be implemented by all classes that wish to define a
A Comparator is used to compare two objects to determine their ordering with respect to each other.
Marks a class the build constructs and injects, once per server.
An ConcurrentModificationException is thrown when a Collection is modified and an existing iterator on the Collection is used to modify the Collection as well.
Constructs this bean only when no other bean has its type.
Constructs this bean only when a configuration key has a value.
Where a server's settings come from, in one resolution order.
A class whose Bean methods produce beans.
Binds a group of configuration keys to the setters of a bean.
 
 
Expectations of the response body, from MockMvcResultMatchers.content().
Build-time MVC declaration.
A public no-arg converter for a basic field; converters also receive null values.
Makes one thing out of another: an Authentication out of a verified token, its authorities out of its claims.
Keeps the token in a cookie, XSRF-TOKEN, for a page whose script reads the cookie and sends its value back in the X-XSRF-TOKEN header -- the convention Angular and axios follow.
Keeps the request in a cookie of its own, for a provider that answers with a form the browser posts (ClientRegistration.FORM_POST): Sign in with Apple.
Expectations of the cookies a response sets, from MockMvcResultMatchers.cookie().
A credential's public key as an authenticator sends it -- a COSE_Key, RFC 9052 -- turned into what Crypto.verify(String, byte[], byte[], byte[]) takes: an algorithm name and a SubjectPublicKeyInfo.
Counts the calls of this method, and separately the calls that threw.
A count that only goes up -- requests served, jobs run, errors seen.
 
One registered passkey: what the server keeps of a credential, as the WebAuthn specification's credential record lists it.
AWS credentials, and the ways a server actually obtains them.
The password was right and has expired.
The crypto a server needs to authenticate a request.
Thrown by classes in this package when a cryptographic operation fails.
Protection against cross-site request forgery.
A state-changing request did not prove it came from the application's own pages.
Refuses a state-changing request that does not carry the chain's CSRF token.
The token a page sends back with a state-changing request to show the request came from the application's own pages.
Where a chain keeps the CSRF token it expects a client to send back.
Configures one part of an HttpSecurity: the lambda handed to formLogin, csrf, authorizeHttpRequests and the rest.
Typed access to one entity's table.
Checks a username and password against a UserDetailsService: loads the user, compares the password through a PasswordEncoder, and refuses an account that is locked, disabled or expired.
A database operation failed: a statement the engine refused, a connection that could not be opened or was lost, a query that returned more rows than one.
One database API over SQLite, PostgreSQL and MySQL, chosen by URL.
A unit of work run inside Database.transaction(Database.Work).
The DataInput interface provides for reading bytes from a binary stream and reconstructing from them data in any of the Java primitive types.
A data input stream lets an application read primitive Java data types from an underlying input stream in a machine-independent way.
The DataOutput interface provides for converting data from any of the Java primitive types to a series of bytes and writing these bytes to a binary stream.
A data output stream lets an application write primitive Java data types to an output stream in a portable way.
A pool of connections to ONE database, whichever engine that database is.
A unit of work run against one borrowed connection.
The class Date represents a specific instant in time, with millisecond precision.
A class for parsing and formatting localisation sensitive dates, compatible with Jave 6 SDK.
 
 
 
 
SQLite persistence for server-side binaries, on the engine the translator already bundles.
A unit of work run inside Db.transaction(Db.Work).
A fixed pool of connections to one SQLite database.
Excludes an @Entity field from the generated table.
The exchange over the runtime's HTTP client, which parks the request's thread while the provider answers.
Finds the token in the Authorization: Bearer header.
A CsrfToken that is its three values.
Verifies tokens against keys it holds, or keys an issuer publishes.
Signs tokens with the keys of a JwkSource.
Serves a plain login page at GET /login for a chain that uses form login and names no page of its own.
Starts a sign-in for a GET of /oauth2/authorization/{registrationId}.
An OAuth2User that holds what it is given.
The user of a provider that is OAuth2 without OpenID Connect -- GitHub: its attributes are what the provider's user info address answers the access token with, and its name is the registration's name attribute among them.
An OidcUser that holds what it is given.
A SecurityFilterChain that is a matcher and a list of filters: what HttpSecurity.build() returns.
 
 
 
Puts a token to several validators and reports everything any of them found: a token that is both expired and from the wrong issuer says both.
Reads which scheme a stored password was made with from the {id} in front of it, so one user store can hold passwords of several ages:
Maps an HTTP DELETE to this method.
Lets nobody call this method -- or any public method of this class.
An annotation for marking an element as deprecated.
A kind of collection that can insert or remove element at both ends("double ended queue").
The little ASN.1 DER a server needs to move keys and signatures between the shapes they travel in: a JSON Web Key's numbers and the SubjectPublicKeyInfo that Crypto.verify(String, byte[], byte[], byte[]) takes; a PKCS#1 or SEC 1 private key out of an older PEM file and the PKCS#8 that Crypto.sign(String, byte[], byte[]) takes; an ECDSA signature as OpenSSL and the JDK write it and as a JSON Web Signature carries it.
What the three engines spell differently, in one place.
**Note: Do not use this class since it is obsolete.
The account is disabled.
The persistent discriminator for a concrete class in an entity hierarchy.
 
The Double class wraps a value of the primitive type double in an object.
 
Mapping for an owned collection of scalar values.
A mirror of java.lang.annotation.ElementType.
A reusable value object whose scalar fields are stored in its owner table.
Flattens an embeddable value into the owner table using a field-name prefix.
Flattens an embeddable identifier into the owner table using a field-name prefix.
Thrown by methods in the Stack class to indicate that the stack is empty.
Marks a POJO or PropertyBusinessObject as a persistent entity, in the app and on the Codename One backend alike.
What the build generated about one entity class: its table, its columns, and reflection-free access to its fields.
The entry point to the build-time ORM: entities in, daos out.
Implementation class required to compile enums
An object that implements the Enumeration interface generates a series of elements, one at a time.
Signals that an end of file or end of stream has been reached unexpectedly during input.
An Error is a subclass of Throwable that indicates serious problems that a reasonable application should not try to catch.
EventListener is the superclass of all event listener interfaces.
This abstract class provides a simple wrapper for objects of type EventListener.
The class Exception and its subclasses are a form of Throwable that indicates conditions that a reasonable application might want to catch.
How a chain answers a request that must sign in, and one that may not have what it asked for.
Turns the security exceptions thrown by what follows it -- the authorization rules, a controller, a service the controller calls -- into answers.
Thrown by Future.get() when the work failed; the cause is what it threw.
Which local user each identity at a provider is: the pairs of a registration's id and the provider's subject, each tied to one user name.
Controls when a mapped relationship is loaded.
The file-system calls a static handler needs, isolated so that everything else in StaticFiles -- ranges, conditional requests, MIME types, the containment check -- is pure Java and shared by every target.
Signals that an attempt to open the file denoted by a specified pathname has failed.
The rest of the chain, as a SecurityFilter sees it: the filters after it and then the application's routes.
Simple version of filter input stream
Dummy implementation of filter output stream
The Float class wraps a value of primitive type float in an object.
Indicates that an output object can be flushed.
An abstract class for parsing and formatting localisation sensitive information, compatible with JDK 6.
Sign-in through an HTML form.
Strict scalar form conversion used by generated binders.
 
Marks an interface that is meant to be a functional interface: exactly one abstract method, so a lambda or method reference can implement it.
The result of work that finishes later -- on the backend, what an @Async method returns, completed when its body has run on its executor.
A value read when metrics are collected -- a queue's depth, a pool's size, a @ManagedAttribute.
Where a gauge with several labelled values comes from -- one per executor, say.
Where a gauge's value comes from.
Marks a class the backend processors wrote, so a later pass knows its own work.
A key that has just been made: the one moment its text exists.
Overrides the legacy Id.autoIncrement strategy for this identifier.
Identifier generation strategies for a single identifier field.
Maps an HTTP GET to this method.
One thing an Authentication has been granted: a role, written ROLE_ADMIN, or any other authority the application checks by name.
 
See also
 
 
What a Lambda-style handler implements.
Streaming and one-shot cryptographic hash (message digest) functions.
HashMap is an implementation of Map.
HashSet is an implementation of a Set.
Hashtable associates keys with values.
Expectations of the response headers, from MockMvcResultMatchers.header().
The security headers a chain puts on its responses.
Content-Security-Policy.
X-Frame-Options.
Strict-Transport-Security.
A header that is either sent or not.
Writes a header onto every response a chain's requests get:
The headers of the response being written.
Holds the chain's HeaderWriters.
A distribution of values -- durations, sizes -- kept as counts per bucket.
Keyed-hash message authentication (HMAC, RFC 2104) on top of any hash algorithm supported by Hash.
Primitives called by generated views; no template evaluation occurs here.
Helpers for the htmx wire protocol.
A minimal HTTP/1.1 client over Tcp.
One HTTP response: status line, headers and body.
The one date format HTTP/1.1 requires on the wire ("Sun, 06 Nov 1994 08:49:37 GMT"), formatted and parsed from epoch milliseconds directly.
One HTTP/2 connection, on nghttp2.
One request, once the client has finished sending it.
Answers 403: what a chain with no way of signing in says to a request that would have to.
Sign-in with HTTP Basic credentials on each request.
Request or response headers: names in any case, each with its values in order.
An HTTP/1.1 server built around a reactor and a bounded worker pool.
 
One part of a multipart/form-data request body: a form field, or an uploaded file when it has a filename.
What a handler receives.
What a handler returns.
Chooses the websocket endpoint for an upgrade request, or null when this router does not serve that path.
What a HttpServer.WebSocketRoutes callback puts its endpoints into.
Where websocket routes come from.
State kept for one client across requests, found again through a cookie.
Keeps the token in the HTTP session: the default.
Keeps the request in the HTTP session: the default, for every provider that answers with a redirect.
Remembers the address in the HTTP session, under HttpSessionRequestCache.SAVED_REQUEST.
Keeps who is signed in in the HTTP session, under HttpSessionSecurityContextRepository.SPRING_SECURITY_CONTEXT_KEY.
The common response statuses, so assertEquals(HttpStatus.OK, response.getStatusCode()) reads as it does in Spring.
A response status: an HttpStatus for the common ones, or any other code.
Answers with a status and nothing else: new HttpStatusEntryPoint(401) for an API whose clients know how to authenticate without being told.
After sign-out, answers with a status and no page: for an API.
Designates the primary-key field of an @Entity.
Immutable composite identity, in the model's declared identifier-field order.
IdentityHashMap is a variant on HashMap which tests equality by reference instead of equality by value.
Thrown when an application tries to load in a class, but the currently executing method does not have access to the definition of the specified class, because the class is not public and in another package.
Thrown to indicate that a method has been passed an illegal or inappropriate argument.
Thrown to indicate that a thread has attempted to wait on an object's monitor or to notify other threads waiting on an object's monitor without owning the specified monitor.
 
Thrown to indicate that a thread is not in an appropriate state for the requested operation.
IncompatibleClassChangeError is the superclass of all classes which represent errors that occur when inconsistent class files are loaded into the same running image.
A mirror of java.lang.annotation.IncompleteAnnotationException.
Database index over mapped field names, declared on an entity.
Thrown to indicate that an index of some sort (such as to an array, to a string, or to a vector) is out of range.
 
 
Stores an entity hierarchy in one table with an immutable discriminator.
 
API keys held in memory: for tests, and for a server whose few keys come from its configuration.
Registrations given when the server starts.
Identities kept in this process: gone when it stops, and unknown to any other.
Grants kept in this process: gone when it stops, and unknown to any other.
User handles kept in this process: gone when it stops, so that every passkey registered before then finds no user after.
A limit kept in this process's memory: a token bucket per key.
Recovery codes kept in this process: gone when it stops.
Clients given when the server starts, and kept in this process.
Remembered sign-ins kept in this process: gone when it stops, and unknown to any other process of the same deployment.
Secrets kept in this process: gone when it stops.
Credentials kept in this process: gone when it stops, and unknown to any other server.
Users kept in memory: for a demonstration, a test, or a server whose handful of accounts is part of its configuration.
This abstract class is the superclass of all classes representing an input stream of bytes.
An InputStreamReader is a bridge from byte streams to character streams: It reads bytes and translates them into characters.
 
Thrown when an application tries to create an instance of a class using the newInstance method in class Class, but the specified class object cannot be instantiated because it is an interface or is an abstract class.
One named measurement: a counter, a gauge or a histogram.
The request is anonymous, or not authenticated strongly enough, for what it asked for.
The Integer class wraps a value of the primitive type int in an object.
Thrown when a thread is waiting, sleeping, or otherwise paused for a long time and another thread interrupts it.
Signals that an I/O operation has been interrupted.
The bearer token of a request was looked at and refused; the message is why.
The request's CSRF token is not the one the server issued.
Signals that an I/O exception of some sort has occurred.
Objects of classes that implement this interface can be used within a foreach statement.
Thymeleaf-style iteration status for a compiled loop.
An Iterator is used to sequence over a collection of objects.
A migration written in Java, for a change SQL cannot express: recomputing a column, moving data between tables with logic in between.
API keys kept in the server's database, in the cn1_api_key table of SecuritySchema.
Identities kept in the server's database, in the cn1_federated_identity table of SecuritySchema.
Grants kept in the server's database, in the cn1_oauth2_authorization and cn1_oauth2_token tables of SecuritySchema: what lets tokens outlive a restart, and several processes be one authorization server.
User handles kept in the server's database, in the cn1_webauthn_user table of SecuritySchema.
Counts in the server's database, in the cn1_rate_limit table of SecuritySchema, so that every process of a deployment shares one limit.
Recovery codes kept in the server's database, in the cn1_mfa_recovery_code table of SecuritySchema.
Clients kept in the server's database, in the cn1_oauth2_registered_client table of SecuritySchema.
Remembered sign-ins kept in the server's database, in the cn1_persistent_logins table of SecuritySchema, so that any process of a deployment recognizes a cookie any other issued.
Secrets kept in the server's database, in the cn1_mfa_totp table of SecuritySchema.
Credentials kept in the server's database, in the cn1_webauthn_credential table of SecuritySchema.
Users kept in the server's database, in the cn1_users and cn1_authorities tables of SecuritySchema.
Foreign key column on the owning table.
Join table and key column names for an owning to-many association.
A mutable query obtained from Session.createQuery(String, Class).
A self-contained JSON reader/writer for server-side binaries.
A value that knows how to write itself as JSON.
Excludes a @Mapped field from the JSON projection.
Expectations of one JSONPath into the JSON body, from MockMvcResultMatchers.jsonPath(String, Object...).
Renames a @Mapped field in the JSON projection.
One key, as a JSON Web Key describes it (RFC 7517): an RSA key, an EC key on P-256 or P-384, or a shared secret.
A set of keys, as a JSON Web Key Set publishes one (RFC 7517 5): what a server that signs tokens serves at its jwks_uri, and what a server that verifies them reads from there.
Where keys come from: a set held in memory, a file read at start-up, another server's published set.
An algorithm a JSON Web Signature is made with: a SignatureAlgorithm, which a private key signs and its public key verifies, or a MacAlgorithm, which one shared secret does both of.
The header of a signature that is about to be made: which algorithm, and optionally which key and what type of token.
Builds a JwsHeader.
HS256 JSON Web Tokens: issue one, and verify one you are handed.
A JSON Web Token whose signature has been made or verified: its text, the headers of its signature and its claims.
Thrown for any token that is not valid and current.
Refuses a token that is not for this server: one whose aud names none of the audiences given here.
Makes the JwtAuthenticationToken of a verified token: its authorities, through a JwtGrantedAuthoritiesConverter unless another is set, and its name, from the sub claim unless another is named.
Authenticates a bearer token by verifying it as a JWT.
Who a request is from, when a verified JWT says so.
The claims RFC 7519 registers.
The claims of a token that is about to be signed.
Builds a JwtClaimsSet.
Refuses a token unless one of its claims passes a test.
Verifies a token and reads its claims.
Makes a decoder for an issuer from what the issuer says about itself.
Signs tokens.
What a JwtEncoder is asked to sign: claims, and optionally a header.
A token could not be signed: there is no key for it, or the key does not fit the algorithm.
A token could not be made or could not be judged: a key is missing or unusable, the server that publishes the keys did not answer.
Reads a token's authorities out of one claim: each value, with a prefix in front.
For a server that takes tokens from several issuers: each token is verified by the issuer it says it is from, and only by that one.
Refuses a token whose iss is not exactly the issuer this server trusts.
Refuses a token past its exp or ahead of its nbf, with a minute's allowance either way for two machines whose clocks disagree.
A token whose signature verified and whose claims did not pass: expired, not yet valid, from another issuer, meant for another audience.
The validators a decoder is usually given.
 
Reads keys out of PEM text, in the shapes key files come in, and hands back the one shape the runtime signs and verifies with: PKCS#8 DER for a private key, SubjectPublicKeyInfo DER for a public one.
Deprecated
The AWS Lambda custom-runtime loop.
Constructs this bean the first time something calls it, instead of at start-up.
An unloaded association was accessed after its session was detached or closed.
LinkageError is the superclass of all error classes that occur when loading and linking class files.
LinkedHashMap is a variant of HashMap.
LinkedHashSet is a variant of HashSet.
LinkedList is an implementation of List, backed by a linked list.
Signs the user of an identity provider in as a user of the application's own.
A List is a collection which maintains an ordering for its elements.
An ListIterator is used to sequence over a List of objects.
 
 
 
Injects the port the BackendTest's server listens on into an int field.
 
The account is locked.
Explicit row-lock modes.
Sends a request that has to sign in to the login page, with a 302.
Sign-out: POST /logout ends the session, forgets who was signed in and redirects to /login?logout.
Signs the user out when a request asks for it -- POST /logout unless configured otherwise -- and answers with the chain's LogoutSuccessHandler.
Something to undo when a user signs out: a session, a cookie, a stored token.
Answers the request that signed a user out.
The Long class wraps a value of the primitive type long in an object.
The shared secret algorithms: whoever can verify a token can also make one, so these suit a server checking tokens it issued itself and nothing wider.
A getter of a ManagedResource bean published as a gauge.
A method of a ManagedResource bean that the management endpoint and the development MCP server can invoke.
Publishes this bean's ManagedAttribute getters as metrics and its ManagedOperation methods as operations -- the JMX model, over OpenTelemetry.
Maps entity collection membership through a join table or an inverse mappedBy field.
Maps a single related entity using a foreign key on the owning table.
A Map is a data structure consisting of a set of keys and values in which each key is mapped to a single value.
Map.Entry is a key/value mapping contained in a Map.
Uses a target attribute as the key of an entity relationship Map.
Names the key column of a scalar element-collection Map.
Contributes inherited scalar and relationship mappings to concrete entities.
The class Math contains methods for performing basic numeric operations.
Names and describes one parameter of an McpTool method.
Publishes this method of a bean as a tool on the server's MCP endpoint, so an agent can call it.
Media types, for contentType(...) and accept(...).
 
Deprecated
Deprecated
 
Deprecated
Something that reads Metrics periodically and sends them somewhere -- the OTLP exporter.
The server's metrics: every Instrument by name, and the ones the server records about itself.
A second factor at sign-in.
What one Migrator.migrate() call did.
Marks a com.codename1.migration.JavaMigration the build should register beside the project's SQL migration files.
What a JavaMigration may do to the database it is migrating.
A migration run that was refused or failed.
One row of Migrator.info(): a migration this build carries, one the database recorded, or both.
Versioned schema migrations for the server's database.
A named group of migrations with its own history table.
Collects the migrations of a set.
Where one migration stands, as reported by Migrator.info().
Runs one MigrationSet against one database.
The request carried a CSRF token and the server holds none to compare it with -- the session it belonged to is gone -- or carried none at all.
Replaces every bean of the field's type with a Mockito mock, and injects it:
A multipart/form-data request, from MockMvcRequestBuilders.multipart(String, Object...): files and fields, encoded as a browser's form post would be.
Calls a running backend's routes in the same process: no socket, no port, the same answer.
The requests MockMvc sends, for static import:
Handlers for andDo(...), for static import.
The expectations andExpect(...) takes, for static import:
One request for MockMvc, built by MockMvcRequestBuilders.
What a MockMvc request came back with.
Request-owned model shared by a controller and its compiled view.
A compiled view name and the values supplied to it.
Build-time MVC declaration.
One MockMvc exchange: what was sent and what came back.
A MySQL client speaking the client/server protocol directly, for the same reason as Postgres: a translated server binary has no JDBC.
NavigableMap is a SortedMap with navigation methods answering the closest matches for specified item.
NavigableSet is a SortedSet with navigation methods answering the closest matches for specified item.
Thrown if an application tries to create an array with negative size.
Thrown if the Java Virtual Machine tries to load in the definition of a class (as part of a normal method call or as part of creating a new instance using the new expression) and no definition of the class could be found.
Stores a password as it is: {noop}secret.
Thrown by the nextElement method of an Enumeration to indicate that there are no more elements in the enumeration.
Thrown when the virtual machine notices that a program tries to reference, on a class or object, a field that does not exist.
Thrown when an application attempts to use null in a case where an object is required.
Remembers nothing.
Keeps nothing: every request authenticates itself.
 
Thrown to indicate that the application has attempted to convert a string to one of the numeric types, but that the string does not have the appropriate format.
What a token endpoint answered a successful exchange with.
Exchanges an authorization code for tokens at the provider's token endpoint.
An authentication that failed for a reason OAuth 2.0 has a code for.
A user who signed in through an identity provider.
One grant: a user -- or, for the device grant, nobody yet -- having let one client act with some scopes.
Answers the endpoints of an authorization server a user must be signed in for: the authorization endpoint and the device verification page.
One user being sent to an identity provider: where to, and the three values that tie the provider's answer back to this browser -- the state, the nonce the ID token must repeat, and the PKCE verifier whose hash went with the request.
Starts a sign-in at an identity provider: keeps the request this browser is sent away with, and redirects it to the provider.
Decides whether a request starts a sign-in at an identity provider, and what is asked of the provider when it does.
The endpoints of an authorization server, each a method that takes a request and answers it.
Answers the endpoints of an authorization server that a client calls as itself: the token, revocation, device authorization, JWK Set, user info and metadata endpoints.
Where an authorization server keeps the grants it has made and the secrets it issued under them.
Checks a signed access token against its live authorization grant, including client-credentials grants.
Why something OAuth 2.0 was refused: a code from the specification that defines it, and optionally a sentence for a person and an address to read more at.
The error codes this layer answers with: those of RFC 6749, RFC 6750, RFC 7009 and RFC 8628, and the ones a sign-in through another provider fails with.
Ends a sign-in at an identity provider: takes the provider's answer at /login/oauth2/code/{registrationId}, holds it to the request this browser was sent away with, exchanges the code, verifies the ID token and signs the user in.
Sign-in through another identity provider, with OAuth2 or OpenID Connect.
The small pieces of text an OAuth2 exchange is made of: a form, a query, a list of scopes, a random value, a PKCE challenge.
Sign-in with a bearer token on each request: the routes under the chain are an OAuth 2.0 resource server, and the token is a JWT.
How the JWTs of a resource server are verified and read.
One token about to be signed, as an OAuth2TokenCustomizer sees it.
Changes the claims of the tokens an authorization server signs: adds the user's roles to an access token, a tenant to an ID token.
One check a token is put to after its signature has verified: is it still in date, is it from the issuer this server trusts, is it meant for this server.
What an OAuth2TokenValidator found: nothing, or the errors.
A user as an identity provider described them.
What an OAuth2UserService is asked with: the provider the user signed in through, and the tokens it issued.
Makes the user of a sign-in through an identity provider.
Class Object is the root of the class hierarchy.
This is a compatibility class which supports the java.util.Objects API.
Observable is used to notify a group of Observer objects when a change occurs.
Observer is the interface to be implemented by objects that receive notification of updates on an Observable object.
 
Makes, and keeps, the decoder that verifies the ID tokens of one registration.
A user an OpenID Connect provider vouched for with an ID token.
What an authorization server says of a user: the claims of the /userinfo answer and of an ID token, beyond sub.
An OAuth2UserRequest for a provider that also issued an ID token, which has been verified by the time a service sees it.
The user of an OpenID Connect provider: the claims of the verified ID token, and -- when the registration names a user info address and a scope that has claims there was granted -- what that address adds to them.
Maps a collection of related entities using a join table or an inverse mappedBy field.
Maps a single related entity with a unique owning foreign key, or an inverse mappedBy field.
Traces this server with OpenTelemetry.
The row was changed or removed since it was loaded.
Where a bean stands among the beans of its type: the lower the value, the earlier it comes in a List an injection point receives, and the earlier a SecurityFilterChain is asked whether a request is its own.
Orders a loaded entity collection by target attributes.
Persists the positions of elements in an owning List.
Exports Metrics over OTLP/HTTP, every cn1.otel.metrics.intervalMillis (OTEL_METRIC_EXPORT_INTERVAL, one minute by default), with cumulative temporality.
OpenTelemetry tracing over OTLP/HTTP, with no OpenTelemetry library behind it.
Counter-based (HOTP, RFC 4226) and time-based (TOTP, RFC 6238) one-time password generators.
Thrown when the Java Virtual Machine cannot allocate an object because it is out of memory, and no more memory could be made available by the garbage collector.
This abstract class is the superclass of all classes representing an output stream of bytes.
An OutputStreamWriter is a bridge from character streams to byte streams: Characters written to it are translated into bytes.
An annotation to indicate that a method is intended to override a superclass method.
Names a parameter for a PreAuthorize expression, which refers to it as #name.
An error occurred during parsing.
Turns a password into what is stored, and checks a password against it.
Makes the PasswordEncoder an application should use unless it has a reason to choose its own.
Maps an HTTP PATCH to this method.
Binds a {name} segment of the path to this parameter.
Reads the PBKDF2 passwords Spring Security's Pbkdf2PasswordEncoder wrote, so a user table brought over from a Spring application signs its users in as it is.
PBKDF2-HMAC-SHA256 through the runtime's own Crypto.hashPassword(String) and Crypto.verifyPassword(String, String): a random salt per password, and the round count written into the result, so a stored value says how it is to be checked.
 
Lets anyone call this method -- or every public method of this class.
An ORM failure, including an underlying database failure during lazy access.
One remembered sign-in, as the server keeps it: whose it is, the series the cookie names, the hash of the token the cookie must carry next, and when it was last used.
Remember-me with a series and a rotating token.
Where remembered sign-ins are kept.
Called once the bean is constructed and every member is injected.
A PostgreSQL client speaking the v3 frontend/backend protocol directly.
Invokes a public no-argument callback after an entity is loaded or refreshed.
Maps an HTTP POST to this method.
Invokes a public no-argument callback after the entity insert succeeds, before commit.
Invokes a public no-argument callback after the entity row is deleted, before commit.
Invokes a public no-argument callback after the entity update succeeds, before commit.
Lets this method -- or every public method of this class -- run only when an expression about the caller holds.
Called when the server stops, after it has finished the requests in flight and before the database closes.
 
Invokes a public no-argument callback before inserting a new entity during flush.
Invokes a public no-argument callback before the entity row is deleted during flush.
Invokes a public no-argument callback before a dirty entity update during flush.
The bean an injection point receives when several have its type and it names none.
A PrintStream adds functionality to another output stream, namely the ability to print representations of various data values conveniently.
A PriorityQueue holds elements on a priority heap, which orders the elements according to their natural order or according to the comparator specified at construction time.
Constructs this bean only when a profile is active.
What a Transactional method does about a transaction that is already open on the calling thread.
 
An AuthenticationManager that asks a list of AuthenticationProviders in order and takes the first answer.
No AuthenticationProvider of a ProviderManager checks tokens of the class it was handed.
What a client is given to make a passkey with: the relying party, the user, a challenge, and what kind of credential is wanted.
What a client is given to sign in with a passkey: a challenge, the relying party, and -- when the user said who they are first -- which credentials may answer.
The relying party of a passkey: the site a credential belongs to.
A user as passkeys know them: the name they sign in with, and the user handle -- random bytes that stand for the account inside an authenticator, and that a sign-in without a user name hands back.
Where each user's passkey handle is kept; see PublicKeyCredentialUserEntity.
Maps an HTTP PUT to this method.
Picks one bean by name where several have the type an injection point asks for.
A query named in the entity's own terms.
A mutable, parameterized query obtained from Session.query(Class).
This kind of collection provides advanced operations compared to basic collections, such as insertion, extraction, and inspection.
An instance of this class is used to generate a stream of pseudorandom numbers.
RandomAccess is implemented by List implementations that support fast (usually constant time) random access.
Counts requests under a key and says when there have been too many.
Answers 429 to a request that is over one of the chain's rate limits; see HttpSecurity.rateLimit(RequestMatcher, RateLimitKeyResolver, RateLimiter).
Says which key a request counts under.
The keys a request is usually counted under.
Readiness notification over epoll (Linux) or kqueue (macOS/BSD).
Abstract class for reading character streams.
Base class for Java record types.
Where recovery codes are kept: as hashes, never as the codes.
Recovery codes: what signs a user in when their authenticator app is gone.
Abstract base class for reference objects.
A client this authorization server issues tokens to.
The clients an authorization server knows.
Recognizes a returning user by their remember-me cookie, on a request nobody has signed in for.
Who a request is from when the user was recognized by a remember-me cookie rather than signing in during this session.
Remember-me: a cookie that signs a returning user in.
What remembers a user between sessions: issues the cookie at sign-in, and recognizes it on a request nobody has signed in for.
The keys another server publishes at its jwks_uri, fetched when they are first needed and kept.
Fetches the text at an address.
What a request rule is asked about: the request, and the variables its pattern bound.
Binds the decoded request body to this parameter.
Remembers where an anonymous request was going, so that signing in can send the user there instead of to a fixed page.
Whether a chain remembers where an anonymous request was going; see RequestCache.
Binds a request header to this parameter.
A path, and optionally a verb, for a controller or one of its methods.
Decides whether a rule applies to a request: which chain guards it, which authorization rule covers it, which requests CSRF protection leaves alone.
Whether a request matched, and the variables its pattern bound.
Combines matchers: all of them, any of them, or not one.
Binds a request parameter to this parameter: the query string's value, or, when the query has none, a field of the form the body carries -- application/x-www-form-urlencoded, or a multipart/form-data part that is not a file.
Binds one part of a multipart/form-data request body to this parameter.
Changes a request MockMvc is about to send: what MockRequestBuilder.with(RequestPostProcessor) takes.
Build-time MVC declaration.
A TestRestTemplate response: status, headers and the body converted to the type asked for.
The status this method answers with when it returns normally.
Marks a class whose methods answer HTTP requests.
What to do with a MockMvc result: assert on it, act on it, or return it.
Something done with a MockMvc result, such as MockMvcResultHandlers.print().
One expectation of a MockMvc result, from MockMvcResultMatchers.
 
A mirror of java.lang.annotation.RetentionPolicy.
Lets this method -- or every public method of this class -- run only for a caller holding one of these roles: @RolesAllowed("ADMIN") asks for the authority ROLE_ADMIN.
The Runnable interface should be implemented by any class whose instances are intended to be executed by a thread.
Every Java application has a single instance of class Runtime that allows the application to interface with the environment in which the application is running.
RuntimeException is the superclass of those exceptions that can be thrown during the normal operation of the Java Virtual Machine.
Amazon S3, and anything that speaks its API (MinIO, Cloudflare R2, Backblaze B2, Wasabi, Ceph) -- which is why the endpoint is configurable rather than assembled from a region alone.
 
After sign-in, sends the user to the page that asked them to sign in, or to a default when they came to the login page on their own.
Runs this method of a bean on a schedule.
How many instances of a bean there are, and how long each lives.
Asks a user who has a second factor for it, between their password being accepted and their being signed in.
Stands between a user passing their first factor and being signed in.
Lets this method -- or every public method of this class -- run only for a caller holding one of these authorities, each written in full: @Secured("ROLE_ADMIN").
One configurable part of an HttpSecurity: form login, CSRF protection, the authorization rules.
What the security layer knows about the thread's current request: who it is from.
Where a chain keeps who is signed in between requests.
Who the calling thread's request is from.
Loads who is signed in from the chain's SecurityContextRepository into SecurityContextHolder before anything else looks.
A SecurityContext that holds its authentication and nothing else.
Where a chain keeps who is signed in between one request and the next.
Thrown by the system to indicate a security violation.
What a chain keeps about the request the calling thread is serving, beyond the request itself: attributes filters hand one another, and headers for the response that is yet to come back.
One step of a SecurityFilterChain.
The filters that guard some of a server's requests.
What a test says about one request's security, for static import:
The tables the security layer's database-backed stores keep, as a migration set of the layer's own.
Here to simplify porting, won't actually work...
A listening TCP socket and the blocking read/write a worker uses once it owns a connection.
Thrown when a read or write deadline expires.
The server is doing as much of something expensive as it was told it may, and this request would have been one more: it is turned away at once, rather than queued behind work that is already late.
A persistence context obtained from an entity manager's openSession() method.
Whether a chain may use the HTTP session.
Whether a chain uses the HTTP session, and what happens to it at sign-in.
How a chain signs a user in to a session, once some mechanism has established who they are.
Where HttpSessions are kept between requests.
A Set is a data structure which does not allow duplicate elements.
The Short class is the standard wrapper for short values.
Turns SIGTERM into an ordinary blocking call, so a server can shut down cleanly when its container asks it to.
The public key algorithms: a token signed with a private key that anyone holding the public key can verify, and only the signer could have made.
Makes and checks the tokens a server mails out: the link that confirms an address, the link that resets a password, an invitation.
A class for parsing and formatting dates with a given pattern, compatible with the Java 6 API.
An authority that is its name and nothing else.
After a refused sign-in, sends the user to a page -- the login page with ?error, usually -- or, with no page set, answers 401.
After sign-out, sends the user to a page.
A reference the collector keeps while the referent is being used and memory allows, and clears before the process runs out.
A map that has its keys ordered.
SortedSet is a Set which iterates over its elements in a sorted order.
One timed operation inside a distributed trace.
Stack is a Last-In/First-Out(LIFO) data structure which represents a stack of objects.
 
Minimal charset constants supported by CLDC11 stubs.
Serves files out of a document root, on the kernel's zero-copy path.
Expectations of the response status, from MockMvcResultMatchers.status().
 
The String class represents character strings.
A string buffer implements a mutable sequence of characters.
A string builder implements a mutable sequence of characters.
Deprecated
Thrown by the charAt method in class String and by other String methods to indicate that an index is either negative or greater than or equal to the size of the string.
A specialized Reader that reads characters from a String in a sequential manner.
The StringTokenizer class allows an application to break a string into tokens by performing code point comparison.
 
 
A decoder that is made when the first token arrives, and then kept.
An annotation that indicates a compiler should suppress any warnings of the type specified in the #value().
The System class contains several useful class fields and methods.
 
A named place background work runs: a pool of platform threads, or virtual threads on the server's hosts.
Where background work runs: the named TaskExecutors, and two shorthands for running something once.
Blocking TCP client socket for server-side (clean-target) binaries.
 
A class whose @Bean methods add beans for a BackendTest, and only for it.
An HTTP client for a BackendTest served on a port -- webEnvironment = RANDOM_PORT -- through the backend's own outbound client, so a compiled test sends real requests from the native binary too.
Who the calling thread's tests are running as.
A thread is a thread of execution in a program.
Which kind of thread runs background work: an Async method or a Scheduled job.
THE VALUES LIVE ON THE THREAD, under a WEAK key, and both halves of that are load bearing.
 
The Throwable class is the superclass of all errors and exceptions in the Java language.
Records how long each call of this method takes, as a histogram.
Thrown by Future.get(long, TimeUnit) when the work has not finished in time.
 
 
A unit of time, for timeouts such as Future.get(long, TimeUnit).
TimeZone represents a time zone offset, and also figures out daylight savings.
Server-side TLS.
How long what is issued to one client lasts, in seconds.
Builds a TokenSettings.
What the server keeps of one user's authenticator app.
What a user needs to add the server to their authenticator app: shown once, when enrolment begins.
Where the secrets of users' authenticator apps are kept.
Time-based one-time codes (RFC 6238): enrolling a user's authenticator app, and checking the codes it shows.
Where spans come from and where they go.
Distributed tracing for the server, and the hooks it is instrumented through.
Runs this method -- or every public method of this class -- in a database transaction.
A transaction could not begin, commit or roll back the way a @Transactional method asked.
A MANDATORY method was called with no transaction, or a NEVER one inside one.
The transaction ran past its timeout and was rolled back.
A transaction was rolled back although its own method returned normally, because a method that joined it failed and marked it rollback-only.
The transaction a @Transactional method runs in, bound to the calling thread.
TreeMap is an implementation of SortedMap.
TreeSet is an implementation of SortedSet.
 
 
The Character Encoding is not supported.
 
An implementation of a Univeral Resource Identifier (URI).
 
The UserDetails the runtime provides.
Builds a User.
Where the passkeys users have registered are kept.
A user as the security layer needs to know one: a name, an encoded password, what it has been granted, and whether the account may be used.
A UserDetailsService that can also create, change and delete its users.
Stores a password re-encoded on sign-in, for a user store that wants old hashes replaced as their owners come back.
Finds a user by the name typed at sign-in.
A UserDetailsService has no user of the name it was asked for.
Signs a user in from the login form: a POST to the login processing URL carrying username and password.
A username and password: as a client presented them, or -- with authorities -- as an AuthenticationProvider accepted them.
Signals that a malformed UTF-8 string has been read in a data input stream or by any class that implements the data input interface.
Injects a configuration value.
Vector is a variable size contiguous indexable array of objects.
An int or long counter maintained by a managed session for optimistic locking.
Thrown to indicate that the Java Virtual Machine is broken or has run out of resources necessary for it to continue operating.
A thread of control that is not an OS thread.
 
This class provides support for weak references.
Outbound HTTP and HTTPS for server-side binaries.
An outbound response: status, body, and libcurl's message when it failed.
Who signed in with a passkey.
Signs a user in with a passkey: hands out the options of a sign-in at POST /webauthn/authenticate/options, and takes the authenticator's answer at POST /login/webauthn.
Passkeys: a user who is signed in registers one, and from then on signs in with it.
A passkey ceremony that was refused, with which check refused it.
Lets a signed-in user register a passkey, and remove one of theirs:
The two passkey ceremonies, as the relying party performs them: making the options a client starts from, and verifying what the authenticator answered.
A verified sign-in.
Told when a signature counter did not advance.
What an application implements to serve a websocket route.
Marks a com.codename1.backend.WebSocket as the endpoint for a path.
One websocket connection: the decoder that turns bytes into messages, and the handle an application sends through.
Runs a test as nobody: for one test of a class that is otherwise WithMockUser.
Runs a test, or every test of a class, as a signed-in user who exists nowhere but in the test: no user store is asked and no password checked.
Abstract class for writing to character streams.
 
 
 
Deprecated.