All Packages
Package Summary
Package
Description
Codename One specific Java annotations used by the build pipeline and the
ParparVM bytecode translator to mark methods and classes for special
treatment -- e.g.
Mapping annotations for managed database persistence.
The Codename One backend runtime: the server side of an application, written
in the same Java as the app and compiled to a native server binary.
Annotations that turn an ordinary class into an HTTP or websocket endpoint.
Amazon Web Services from a backend: request signing, credentials, and S3.
Metrics for a backend: counters, gauges and histograms named after the
OpenTelemetry semantic conventions.
Typed models, form binding results, and HTML/htmx helpers for build-time compiled views.
The build-time ORM on the server: entity classes in, typed data access objects
out.
OpenTelemetry tracing and metrics for a backend, exported over OTLP/HTTP
without an OpenTelemetry library.
Authentication and authorization for the routes of a backend, in the shape
of Spring Security: an application declares one or more
SecurityFilterChain beans, each built from
the HttpSecurity its method is handed, and
every request the server does not answer on its own behalf is put to them.API keys: long-lived secrets a program presents instead of signing in.
Users as the security layer sees them:
UserDetails, the
UserDetailsService a chain authenticates against, and an in-memory store.Password hashing: the
PasswordEncoder contract, the delegating encoder that
reads the {id} in front of a stored password, and the encoders behind it.A second factor at sign-in: one-time codes from an authenticator app, and
the recovery codes that stand in for a lost phone.
Signing users in through another identity provider, with OAuth2 or OpenID
Connect: this server as a client of Google, GitHub, Microsoft, Apple or any
provider described by a
ClientRegistration.What the OAuth 2.0 parts of the security layer share: the error a token or a
request is refused with, and the validators a token is put to.
The names of the algorithms a JSON Web Signature is made with (RFC 7518 3),
for the ones this runtime signs and verifies.
JSON Web Tokens signed with a public key algorithm or a shared secret:
JwtDecoder verifies one and
reads its claims, JwtEncoder
makes one.An OAuth2 authorization server and OpenID Connect provider: the server
that signs users in on behalf of clients and issues them tokens.
A server whose routes are reached with a bearer token (RFC 6750): finding
the token in a request, verifying it as a JWT, turning its claims into who
is calling and what they may do, and answering a request whose token is
missing, bad or not enough.
Limits on how often a client may ask: a
RateLimiter counts requests under
a key, and a
RateLimitKeyResolver says which
key a request counts under -- its client's address, who it is signed in as,
its session, its API key.Remember-me: recognizing a returning user by a cookie, so that closing the
browser does not sign them out.
Passkeys: signing in with a credential an authenticator holds, as the Web
Authentication specification defines it.
The database engines a backend talks to, and what they spell differently.
Testing a backend the way Spring Boot tests are written, on the JVM and as a
compiled native test.
gzip support based on https://github.com/ymnk/jzlib
Versioned database migrations, shared by applications and the Codename One backend.
Managed persistence contexts and queries for the client and backend ORMs.
The part of the client's cryptography a server shares with it: the
portable Java digests and message authentication codes, and the one-time
passwords built on them.