Class ExceptionHandlingConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.ExceptionHandlingConfigurer

public final class ExceptionHandlingConfigurer extends SecurityConfigurer

How a chain answers a request that must sign in, and one that may not have what it asked for.

http.exceptionHandling(handling -> handling
        .authenticationEntryPoint(new HttpStatusEntryPoint(401))
        .accessDeniedHandler((request, denied) ->
                HttpServer.Response.json(403, "{\"error\":\"forbidden\"}")));

Without an entry point set here, form login's is the answer -- a redirect to the login page -- and HTTP Basic's challenge when that is the only way in, or when a script made the request. A chain with neither answers 403.