Class JdbcOAuth2AuthorizationService

java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.JdbcOAuth2AuthorizationService
All Implemented Interfaces:
OAuth2AuthorizationService

public final class JdbcOAuth2AuthorizationService extends Object implements OAuth2AuthorizationService

Grants kept in the server's database, in the cn1_oauth2_authorization and cn1_oauth2_token tables of SecuritySchema: what lets tokens outlive a restart, and several processes be one authorization server.

@Bean
OAuth2AuthorizationService authorizations(DataSource dataSource) {
    return new JdbcOAuth2AuthorizationService(dataSource);
}

A secret is one row, keyed by its SHA-256. Using one up is

UPDATE cn1_oauth2_token SET used = 1, polled_at = ?
 WHERE token_hash = ? AND kind = ? AND used = 0 AND expires_at > ?

and the call that sees one row changed is the one that used it: the database decides between two processes, and no lock is held here. The row stays, marked, until it expires -- that is how a code or a refresh token presented a second time is told from one that never existed.