Class ApiKeyAuthenticationFilter

java.lang.Object
com.codename1.backend.security.ApiKeyAuthenticationFilter
All Implemented Interfaces:
SecurityFilter

public final class ApiKeyAuthenticationFilter extends Object implements SecurityFilter

Authenticates a request from the API key it presents, in X-API-Key or as Authorization: Bearer <key>.

A bearer value is taken for an API key only when it starts with the configured prefix; any other is left for whatever verifies tokens. So one chain can accept both, and the prefix is what tells them apart. A value in X-API-Key is always a key, and one without the prefix is refused.

The key is checked on every request and nothing is kept. A request without one passes through untouched; one whose key is unknown or revoked is answered 401 at once, and is not told which.