Class JwtDecoders

java.lang.Object
com.codename1.backend.security.oauth2.jwt.JwtDecoders

public final class JwtDecoders extends Object

Makes a decoder for an issuer from what the issuer says about itself.

JwtDecoder decoder = JwtDecoders.fromIssuerLocation("https://accounts.example.com");

The issuer's metadata is read from, in order, <issuer>/.well-known/openid-configuration, <host>/.well-known/openid-configuration/<path> and <host>/.well-known/oauth-authorization-server/<path> (OpenID Connect Discovery and RFC 8414). The metadata must name this very issuer, or it is refused: that is what stops one tenant's metadata being served for another's. The decoder that comes back verifies with the keys at the metadata's jwks_uri and requires every token's iss to be the issuer.

The metadata is fetched by this call. The keys are fetched when the first token arrives.

  • Method Details

    • fromIssuerLocation

      public static JwtDecoder fromIssuerLocation(String issuer)

      A decoder for the tokens of issuer.

      • IllegalArgumentException: when the issuer's metadata cannot be read, names another issuer, or has no jwks_uri
    • fromOidcIssuerLocation

      public static JwtDecoder fromOidcIssuerLocation(String issuer)
      The same, for an issuer that serves OpenID Connect Discovery.
    • fromIssuerLocation

      public static JwtDecoder fromIssuerLocation(String issuer, RemoteJwkSet.Fetcher fetcher)
      fromIssuerLocation(String) reading through fetcher.
    • fromIssuerLocation

      public static JwtDecoder fromIssuerLocation(String issuer, RemoteJwkSet.Fetcher fetcher, JwsAlgorithm[] accepted)

      fromIssuerLocation(String, RemoteJwkSet.Fetcher) accepting the algorithms named here and no others, whatever the issuer's metadata lists. A deployment that allows only ES256 says so with this. ID-token signing metadata does not describe the access-token algorithms this resource server accepts.

      Parameters
      • issuer: the issuer

      • fetcher: what reads the metadata and the keys

      • accepted: the access-token algorithms to accept; null or empty for RS256

    • metadata

      public static Map metadata(String issuer, RemoteJwkSet.Fetcher fetcher)

      The metadata document of issuer, checked to be its own.

      • IllegalArgumentException: when it cannot be read or names another issuer