Class RegisteredClient
java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.RegisteredClient
A client this authorization server issues tokens to.
RegisteredClient app = RegisteredClient.withId("mobile")
.clientId("acme-app")
.clientAuthenticationMethod(ClientAuthenticationMethod.NONE) // public: PKCE
.authorizationGrantType(AuthorizationGrantType.AUTHORIZATION_CODE)
.authorizationGrantType(AuthorizationGrantType.REFRESH_TOKEN)
.redirectUri("com.acme.app:/oauth2redirect")
.scope("openid").scope("profile").scope("orders:read")
.build();
A redirect address is matched whole, character for character: there are no
wildcards. The one exception is RFC 8252's: an http address on
127.0.0.1 or [::1] may be asked for with any port, because a native
application cannot know which one it will get.
A secret is stored as its PasswordEncoder
wrote it, never as it was issued.
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionThe encoded secret, or null for a client without one.getId()The resource servers the client may ask for tokens for, each by the address it is named with in a token'saud; empty when the client was registered with none, and may then name any.Every scope the client may be granted.booleanisPublic()Whether the client is a public one: it authenticates with nothing, and so must prove with PKCE that the code it redeems is the one it asked for.static booleanisResource(String resource) Whetherresourcecan name a resource server: an absolute URI with no fragment, as RFC 8707 section 2 requires of the parameter.toString()Returns a string representation of the object.static RegisteredClient.BuilderA client stored underid, which is the server's own name for it and never changes; theclientIdis what the client calls itself.
-
Method Details
-
withId
A client stored underid, which is the server's own name for it and never changes; theclientIdis what the client calls itself. -
getId
-
getClientId
-
getClientSecret
The encoded secret, or null for a client without one. -
getClientName
-
getClientAuthenticationMethods
-
getAuthorizationGrantTypes
-
getRedirectUris
-
getScopes
-
getResources
The resource servers the client may ask for tokens for, each by the address it is named with in a token'saud; empty when the client was registered with none, and may then name any. SeeRegisteredClient.Builder.resource(String). -
getClientSettings
-
getTokenSettings
-
isPublic
public boolean isPublic()Whether the client is a public one: it authenticates with nothing, and so must prove with PKCE that the code it redeems is the one it asked for. -
toString
Description copied from class:ObjectReturns a string representation of the object. In general, the toString method returns a string that "textually represents" this object. The result should be a concise but informative representation that is easy for a person to read. It is recommended that all subclasses override this method. The toString method for class Object returns a string consisting of the name of the class of which the object is an instance, the at-sign character `@', and the unsigned hexadecimal representation of the hash code of the object. In other words, this method returns a string equal to the value of: getClass().getName() + '@' + Integer.toHexString(hashCode()) -
isResource
Whetherresourcecan name a resource server: an absolute URI with no fragment, as RFC 8707 section 2 requires of the parameter.
-