Class OidcException


public class OidcException extends IOException
Thrown for failures during an OpenID Connect / OAuth 2.0 flow driven by OidcClient. The getError() code mirrors the error field from RFC 6749 for authorization-server responses (e.g. "access_denied", "invalid_grant") and uses Codename One-specific values for transport or client-side problems ("transport_error", "state_mismatch", "nonce_mismatch", "user_cancelled", "discovery_failed", "invalid_id_token", "issuer_mismatch", "storage_unavailable", "invalid_response").
  • Field Details

    • ACCESS_DENIED

      public static final String ACCESS_DENIED
      Authorization server returned error=access_denied.
      See Also:
    • USER_CANCELLED

      public static final String USER_CANCELLED
      User cancelled the system browser / native sign-in sheet.
      See Also:
    • STATE_MISMATCH

      public static final String STATE_MISMATCH
      state returned by the authorization server did not match the one we sent.
      See Also:
    • NONCE_MISMATCH

      public static final String NONCE_MISMATCH
      nonce claim on the returned ID token did not match the one we sent.
      See Also:
    • DISCOVERY_FAILED

      public static final String DISCOVERY_FAILED
      The discovery document could not be fetched or parsed.
      See Also:
    • INVALID_GRANT

      public static final String INVALID_GRANT
      The authorization grant or refresh token was rejected.
      See Also:
    • INVALID_RESPONSE

      public static final String INVALID_RESPONSE
      The endpoint returned a missing, malformed or incomplete protocol response.
      See Also:
    • INVALID_ID_TOKEN

      public static final String INVALID_ID_TOKEN
      The ID token was not accepted: it is malformed, it is for another client or from another issuer, it has expired, it does not belong to the access token it came with, or its signature does not verify against the provider's keys -- which includes a platform that cannot check a signature of that kind. See OidcClient.setVerifyIdTokenSignature(boolean).
      See Also:
    • ISSUER_MISMATCH

      public static final String ISSUER_MISMATCH
      The authorization response names another issuer than the provider the request was sent to, or none where the provider says it always names one (RFC 9207).
      See Also:
    • TRANSPORT_ERROR

      public static final String TRANSPORT_ERROR
      Generic transport / network failure: no answer, or an answer that is not an OAuth one -- a status other than success with no OAuth error in its body.
      See Also:
    • STORAGE_UNAVAILABLE

      public static final String STORAGE_UNAVAILABLE
      A TokenStore could not read, write or remove the tokens -- the platform has no secure storage, or the store failed.
      See Also:
    • AUTHORIZATION_PENDING

      public static final String AUTHORIZATION_PENDING
      Device grant: the user has not finished approving the device yet. Polling continues.
      See Also:
    • SLOW_DOWN

      public static final String SLOW_DOWN
      Device grant: the device asked too often; it must wait longer between requests.
      See Also:
    • EXPIRED_TOKEN

      public static final String EXPIRED_TOKEN
      Device grant: the device code ran out before the user approved it.
      See Also:
  • Constructor Details

  • Method Details

    • getError

      public String getError()
      The short error code (see the constants on this class).
    • getErrorDescription

      public String getErrorDescription()
      Human-readable description supplied by the server or the client.