Class SecurityMockMvcRequestPostProcessors
java.lang.Object
com.codename1.backend.test.SecurityMockMvcRequestPostProcessors
What a test says about one request's security, for static import:
mvc.perform(post("/notes").with(user("ada").roles("EDITOR")).with(csrf())
.content("{}"));
mvc.perform(get("/api/orders").with(httpBasic("svc", "secret")));
user(String) and authentication(Authentication) say who the request is from, without asking a
user store; csrf() gives a state-changing request the token its chain
demands; httpBasic(String, String) sends real credentials for the chain to check.
jwt() and apiKey(String) say the request came with a bearer token or an API
key that was accepted -- with these claims, these scopes -- without a key to
sign one with or a store to look one up in:
mvc.perform(get("/api/orders").with(jwt().subject("svc").scopes("orders:read")));
mvc.perform(get("/api/orders").with(apiKey("billing").scopes("orders:read")));
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final classapiKey(String), to refine.static final classcsrf(), to refine.static final classjwt(), to refine.static final classuser(String), to refine. -
Method Summary
Modifier and TypeMethodDescriptionstatic RequestPostProcessorThe request is from nobody, whoever the test runs as.The request carries an API key of this owner that was accepted, with no scopes until told otherwise.static RequestPostProcessorauthentication(Authentication authentication) The request is from this authentication.csrf()The request carries a valid CSRF token, in the_csrfparameter.static RequestPostProcessorThe request carries these credentials in anAuthorization: Basicheader.jwt()The request carries a bearer token that was accepted: a JWT whose subject isuserand whose scope isread, until told otherwise.static RequestPostProcessoruser(UserDetails user) The request is from this user.The request is from a user of this name, with the roleUSERunless told otherwise.
-
Method Details
-
user
The request is from a user of this name, with the roleUSERunless told otherwise. -
user
The request is from this user. -
authentication
The request is from this authentication. -
anonymous
The request is from nobody, whoever the test runs as. -
csrf
The request carries a valid CSRF token, in the_csrfparameter. -
httpBasic
The request carries these credentials in anAuthorization: Basicheader. -
jwt
The request carries a bearer token that was accepted: a JWT whose subject isuserand whose scope isread, until told otherwise. What the chain's rules and the handler see is theJwtAuthenticationTokena resource server would have made; no token is sent and none is verified. -
apiKey
The request carries an API key of this owner that was accepted, with no scopes until told otherwise. What the chain's rules and the handler see is theApiKeyAuthenticationTokenthe key would have made; no key is sent and no repository is asked.
-