Class RemoteJwkSet

java.lang.Object
com.codename1.backend.security.oauth2.jwt.RemoteJwkSet
All Implemented Interfaces:
JwkSource

public final class RemoteJwkSet extends Object implements JwkSource

The keys another server publishes at its jwks_uri, fetched when they are first needed and kept.

  • The set is kept for five minutes, then fetched again by the next request that needs it.
  • A token naming a key the set does not have makes it fetch early -- that is how a rotated key is picked up -- but no more than once in thirty seconds, so tokens with invented key ids cannot turn this server into a stream of requests at the issuer.
  • One request fetches at a time. The others carry on with the set they have, or fail if the first fetch has not supplied any keys yet. Failed initial fetches observe the same retry interval. No request waits for another request's network operation.
  • When a fetch fails and there is a set, the set goes on being used and the fetch is tried again later. An issuer that is briefly unreachable does not sign everybody out.

Use an https address. The keys are what every token is trusted by, and they are only as trustworthy as the connection they came over.

  • Field Details

  • Constructor Details

  • Method Details

    • setCacheSeconds

      public void setCacheSeconds(long seconds)
      How long a fetched set is used before it is fetched again; five minutes unless set.
    • setRefreshIntervalSeconds

      public void setRefreshIntervalSeconds(long seconds)
      The least time between two fetches, whatever asks for them; thirty seconds unless set.
    • setClock

      public void setClock(Clock clock)
    • getUri

      public String getUri()
    • getKeys

      public List<Jwk> getKeys() throws IOException
      Description copied from interface: JwkSource
      The keys, the one to sign with first.
      Specified by:
      getKeys in interface JwkSource
      Throws:
      IOException - when the keys cannot be had: a server that publishes them is not answering
    • refresh

      public List<Jwk> refresh() throws IOException
      The keys, fetched again unless a fetch is in progress or the refresh interval has not elapsed.
      Throws:
      IOException