Interface OAuth2TokenCustomizer


public interface OAuth2TokenCustomizer

Changes the claims of the tokens an authorization server signs: adds the user's roles to an access token, a tenant to an ID token.

http.authorizationServer(as -> as.tokenCustomizer(context -> {
    if (OAuth2TokenContext.ACCESS_TOKEN.equals(context.getTokenType())) {
        context.getClaims().claim("tenant", tenants.of(context.getPrincipalName()));
    }
}));
  • Method Summary

    Modifier and Type
    Method
    Description
    void
    Called once for every token, before it is signed.
  • Method Details

    • customize

      void customize(OAuth2TokenContext context)
      Called once for every token, before it is signed.