Class OAuth2AuthorizationServer

java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.OAuth2AuthorizationServer

public final class OAuth2AuthorizationServer extends Object
The endpoints of an authorization server, each a method that takes a request and answers it. The chain's filters decide which request goes to which; see AuthorizationServerConfigurer, which is also where every rule these endpoints apply is described.
  • Field Details

    • AUTH_TIME

      public static final String AUTH_TIME
      Session attribute holding the last completed credential check, in epoch seconds.
      See Also:
  • Constructor Details

    • OAuth2AuthorizationServer

      public OAuth2AuthorizationServer(AuthorizationServerSettings settings, String fixedIssuer, String defaultAudience, RegisteredClientRepository clients, OAuth2AuthorizationService authorizations, JwkSource keys, JwtEncoder encoder, PasswordEncoder secrets, OAuth2TokenCustomizer customizer, OidcUserInfoMapper userInfo, RateLimiter verificationLimiter, int verificationAttempts, long verificationWindowSeconds, Clock clock)
      Parameters:
      fixedIssuer - the issuer, or null to read it off each request: a development profile only
      defaultAudience - the aud of an access token whose request named no resource; null for the issuer
      secrets - what client secrets were encoded with; null when no client has one
      verificationLimiter - what bounds wrong user codes; null to count in this process
      verificationAttempts - how many user codes one user may try in a window, when this process counts
      verificationWindowSeconds - the length of that window
  • Method Details

    • getSettings

      public AuthorizationServerSettings getSettings()
    • handle

      public HttpServer.Response handle(HttpServer.Request request, String path)
      Answers a request to one of the endpoints that need no signed-in user: the token, revocation, device authorization, JWK Set, user info and metadata endpoints.
      Parameters:
      path - the request's path
      Returns:
      the answer, or null when path is none of them
    • isUserEndpoint

      public boolean isUserEndpoint(String path)
      Whether path is an endpoint a user must be signed in for: the authorization endpoint or the device verification page.
    • authorize

      public HttpServer.Response authorize(HttpServer.Request request, Authentication authentication)

      Answers the authorization endpoint for a browser whose user is authentication.

      The client and the redirect address are checked before anything else, and a request that fails either is answered here, with a 400: an error is sent to a redirect address only once that address is known to be the client's own.

      • InsufficientAuthenticationException: when nobody is signed in and the request is a browser's, so that the chain sends it to sign in and back
      Parameters:
      authentication - who is signed in; null for nobody
    • deviceVerification

      public HttpServer.Response deviceVerification(HttpServer.Request request, Authentication authentication, String csrfParameter, String csrfToken)

      Answers the device verification page for the signed-in user authentication: the form that takes a user code, the question that follows a right one, and the answer to that question.

      The chain's CSRF protection covers the two posts; the token to put in the forms is passed in.

      • InsufficientAuthenticationException: when nobody is signed in, so that the chain sends the browser to sign in and back
      Parameters:
      authentication - who is signed in; null for nobody
      csrfParameter - the name of the CSRF form field, or null
      csrfToken - its value
    • deviceVerification

      public HttpServer.Response deviceVerification(HttpServer.Request request, Authentication authentication, String csrfParameter, String csrfHeader, String csrfToken)

      deviceVerification(HttpServer.Request, Authentication, String, String), told the header a CSRF token may come back in as well.

      The endpoint has two forms, and the request chooses. A browser gets the pages. A request that asks for JSON -- its Accept names application/json and not text/html, or its body is application/json -- gets the same three steps as data, so that an application that signed the user in itself can put its own screen in front of them:

      1. GET: {"csrf": {"headerName", "parameterName", "token"}}, the token a post must carry when the chain protects against CSRF.
      2. POST {"user_code": "..."}: the question, as {"user_code", "client_id", "client_name", "scope", "principal", "ticket"}.
      3. POST {"user_code": "...", "ticket": "...", "decision": "approve"} or "deny": {"status": "approved"} or {"status": "denied"}.

      Nothing is relaxed for it. The user must be signed in -- a request that is not is answered 401 login_required rather than sent to a login page -- the chain's CSRF protection covers both posts, each try at a code is counted, and an answer counts only with the ticket this server put in that session with the question, once. A code that is not valid is 400 invalid_grant, an answer without its ticket 400 invalid_request, and too many tries 429 slow_down.

      Parameters:
      csrfHeader - the name of the header a CSRF token may be sent in, or null