Class JwtClaimValidator

java.lang.Object
com.codename1.backend.security.oauth2.jwt.JwtClaimValidator
All Implemented Interfaces:
OAuth2TokenValidator<Jwt>

public final class JwtClaimValidator extends Object implements OAuth2TokenValidator<Jwt>

Refuses a token unless one of its claims passes a test.

// An ID token must carry the nonce this server sent with the request.
OAuth2TokenValidator<Jwt> nonce = new JwtClaimValidator("nonce", expected::equals);

The test is handed the claim as the JSON had it -- a String, a Long or Double, a Boolean, a List or a Map -- and null when the token has none of that name. It is handed an Object and not something narrower on purpose: what type a claim has is the issuer's choice, and a test that assumed one would be casting a value it has not looked at. Ask with instanceof.