Class OAuth2AuthorizationServer
AuthorizationServerConfigurer,
which is also where every rule these endpoints apply is described.-
Field Summary
Fields -
Constructor Summary
ConstructorsConstructorDescriptionOAuth2AuthorizationServer(AuthorizationServerSettings settings, String fixedIssuer, String defaultAudience, RegisteredClientRepository clients, OAuth2AuthorizationService authorizations, JwkSource keys, JwtEncoder encoder, PasswordEncoder secrets, OAuth2TokenCustomizer customizer, OidcUserInfoMapper userInfo, RateLimiter verificationLimiter, int verificationAttempts, long verificationWindowSeconds, Clock clock) -
Method Summary
Modifier and TypeMethodDescriptionauthorize(HttpServer.Request request, Authentication authentication) Answers the authorization endpoint for a browser whose user isauthentication.deviceVerification(HttpServer.Request request, Authentication authentication, String csrfParameter, String csrfToken) Answers the device verification page for the signed-in userauthentication: the form that takes a user code, the question that follows a right one, and the answer to that question.deviceVerification(HttpServer.Request request, Authentication authentication, String csrfParameter, String csrfHeader, String csrfToken) deviceVerification(HttpServer.Request, Authentication, String, String), told the header a CSRF token may come back in as well.handle(HttpServer.Request request, String path) Answers a request to one of the endpoints that need no signed-in user: the token, revocation, device authorization, JWK Set, user info and metadata endpoints.booleanisUserEndpoint(String path) Whetherpathis an endpoint a user must be signed in for: the authorization endpoint or the device verification page.
-
Field Details
-
AUTH_TIME
Session attribute holding the last completed credential check, in epoch seconds.- See Also:
-
-
Constructor Details
-
OAuth2AuthorizationServer
public OAuth2AuthorizationServer(AuthorizationServerSettings settings, String fixedIssuer, String defaultAudience, RegisteredClientRepository clients, OAuth2AuthorizationService authorizations, JwkSource keys, JwtEncoder encoder, PasswordEncoder secrets, OAuth2TokenCustomizer customizer, OidcUserInfoMapper userInfo, RateLimiter verificationLimiter, int verificationAttempts, long verificationWindowSeconds, Clock clock) - Parameters:
fixedIssuer- the issuer, or null to read it off each request: a development profile onlydefaultAudience- theaudof an access token whose request named noresource; null for the issuersecrets- what client secrets were encoded with; null when no client has oneverificationLimiter- what bounds wrong user codes; null to count in this processverificationAttempts- how many user codes one user may try in a window, when this process countsverificationWindowSeconds- the length of that window
-
-
Method Details
-
getSettings
-
handle
Answers a request to one of the endpoints that need no signed-in user: the token, revocation, device authorization, JWK Set, user info and metadata endpoints.- Parameters:
path- the request's path- Returns:
- the answer, or null when
pathis none of them
-
isUserEndpoint
Whetherpathis an endpoint a user must be signed in for: the authorization endpoint or the device verification page. -
authorize
Answers the authorization endpoint for a browser whose user is
authentication.The client and the redirect address are checked before anything else, and a request that fails either is answered here, with a 400: an error is sent to a redirect address only once that address is known to be the client's own.
InsufficientAuthenticationException: when nobody is signed in and the request is a browser's, so that the chain sends it to sign in and back
- Parameters:
authentication- who is signed in; null for nobody
-
deviceVerification
public HttpServer.Response deviceVerification(HttpServer.Request request, Authentication authentication, String csrfParameter, String csrfToken) Answers the device verification page for the signed-in user
authentication: the form that takes a user code, the question that follows a right one, and the answer to that question.The chain's CSRF protection covers the two posts; the token to put in the forms is passed in.
InsufficientAuthenticationException: when nobody is signed in, so that the chain sends the browser to sign in and back
- Parameters:
authentication- who is signed in; null for nobodycsrfParameter- the name of the CSRF form field, or nullcsrfToken- its value
-
deviceVerification
public HttpServer.Response deviceVerification(HttpServer.Request request, Authentication authentication, String csrfParameter, String csrfHeader, String csrfToken) deviceVerification(HttpServer.Request, Authentication, String, String), told the header a CSRF token may come back in as well.The endpoint has two forms, and the request chooses. A browser gets the pages. A request that asks for JSON -- its
Acceptnamesapplication/jsonand nottext/html, or its body isapplication/json-- gets the same three steps as data, so that an application that signed the user in itself can put its own screen in front of them:GET:{"csrf": {"headerName", "parameterName", "token"}}, the token a post must carry when the chain protects against CSRF.POST {"user_code": "..."}: the question, as{"user_code", "client_id", "client_name", "scope", "principal", "ticket"}.POST {"user_code": "...", "ticket": "...", "decision": "approve"}or"deny":{"status": "approved"}or{"status": "denied"}.
Nothing is relaxed for it. The user must be signed in -- a request that is not is answered 401
login_requiredrather than sent to a login page -- the chain's CSRF protection covers both posts, each try at a code is counted, and an answer counts only with the ticket this server put in that session with the question, once. A code that is not valid is 400invalid_grant, an answer without its ticket 400invalid_request, and too many tries 429slow_down.- Parameters:
csrfHeader- the name of the header a CSRF token may be sent in, or null
-