Class OAuth2ResourceServerConfigurer
java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.OAuth2ResourceServerConfigurer
Sign-in with a bearer token on each request: the routes under the chain are an OAuth 2.0 resource server, and the token is a JWT.
@Bean
SecurityFilterChain api(HttpSecurity http) {
http.securityMatcher("/api/**")
.authorizeHttpRequests(auth -> auth
.requestMatchers("/api/orders/**").hasAuthority("SCOPE_orders:read")
.anyRequest().authenticated())
.oauth2ResourceServer(oauth2 -> oauth2.jwt(Customizer.withDefaults()));
return http.build();
}
With nothing more said, the tokens are verified by the application's
JwtDecoder bean, or else as these properties describe:
| Property | Meaning |
|---|---|
cn1.security.oauth2.resourceserver.jwt.issuer-uri |
The issuer. Its metadata names the keys, and every token's iss must be it. |
cn1.security.oauth2.resourceserver.jwt.jwk-set-uri |
Where the keys are, when the issuer publishes no metadata. |
cn1.security.oauth2.resourceserver.jwt.public-key-location |
A PEM file holding the one public key. |
cn1.security.oauth2.resourceserver.jwt.jws-algorithms |
The algorithms accepted, separated by commas; RS256 unless set. |
cn1.security.oauth2.resourceserver.jwt.audiences |
What this server is called in a token's aud, separated by commas. Set it: without it a token the issuer made for another application is accepted here. |
A request authenticated by its token is not asked for a CSRF token: a
browser does not attach an Authorization header to a request another site
made it send, which is the whole of what CSRF protection is against. No
session is started for it either.
A token is refused with 401 and the reason in WWW-Authenticate; a good
token that does not grant enough, with 403 and insufficient_scope. See
BearerTokenAuthenticationEntryPoint and BearerTokenAccessDeniedHandler.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final classHow the JWTs of a resource server are verified and read. -
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe audiences a token must name one of, separated by commas.static final StringThe issuer whose tokens are accepted.static final StringThe address of the issuer's JSON Web Key Set.static final StringThe signature algorithms accepted, separated by commas.static final StringA PEM file holding the public key tokens are verified with. -
Method Summary
Modifier and TypeMethodDescriptionaccessDeniedHandler(AccessDeniedHandler handler) What answers a request whose token does not grant enough.authenticationEntryPoint(AuthenticationEntryPoint entryPoint) What answers a request whose token is missing or refused.Chooses what authenticates each request's token, in place ofjwt: aJwtIssuerAuthenticationManagerResolverfor a server that trusts several issuers.bearerTokenResolver(BearerTokenResolver resolver) Where the token is looked for in a request; theAuthorizationheader unless set.voidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.voidinit(HttpSecurity http) Shares what other parts need to know; nothing by default.jwt(Customizer<OAuth2ResourceServerConfigurer.JwtConfigurer> customizer) The tokens are JWTs, verified here; seeOAuth2ResourceServerConfigurer.JwtConfigurer.The realm the challenges name:WWW-Authenticate: Bearer realm="...".Methods inherited from class SecurityConfigurer
disable, getBuilder
-
Field Details
-
ISSUER_URI
-
JWK_SET_URI
-
PUBLIC_KEY_LOCATION
A PEM file holding the public key tokens are verified with.- See Also:
-
JWS_ALGORITHMS
The signature algorithms accepted, separated by commas.- See Also:
-
AUDIENCES
The audiences a token must name one of, separated by commas.- See Also:
-
-
Method Details
-
jwt
public OAuth2ResourceServerConfigurer jwt(Customizer<OAuth2ResourceServerConfigurer.JwtConfigurer> customizer) The tokens are JWTs, verified here; seeOAuth2ResourceServerConfigurer.JwtConfigurer. -
bearerTokenResolver
Where the token is looked for in a request; theAuthorizationheader unless set. SeeDefaultBearerTokenResolver. -
realmName
The realm the challenges name:WWW-Authenticate: Bearer realm="...". None unless set. It applies to the entry point and the access-denied handler this configurer brings, not to ones given in their place. -
authenticationEntryPoint
What answers a request whose token is missing or refused. -
accessDeniedHandler
What answers a request whose token does not grant enough. -
authenticationManagerResolver
public OAuth2ResourceServerConfigurer authenticationManagerResolver(AuthenticationManagerResolver resolver) Chooses what authenticates each request's token, in place ofjwt: aJwtIssuerAuthenticationManagerResolverfor a server that trusts several issuers. -
init
Description copied from class:SecurityConfigurerShares what other parts need to know; nothing by default.- Overrides:
initin classSecurityConfigurer
-
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-