Class ApiKeyConfigurer
java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.ApiKeyConfigurer
Sign-in with an API key on each request.
@Bean
SecurityFilterChain api(HttpSecurity http) {
http.securityMatcher("/api/**")
.authorizeHttpRequests(auth -> auth
.requestMatchers("/api/deploy/**").hasAuthority("SCOPE_deploy")
.anyRequest().authenticated())
.apiKey(Customizer.withDefaults());
return http.build();
}
A client sends its key as X-API-Key: cn1_... or as
Authorization: Bearer cn1_.... Keys are looked up in the application's
ApiKeyRepository bean unless repository names another, and are made
with ApiKeyGenerator.
On a chain that also has oauth2ResourceServer(...), a bearer value that
starts with the key prefix is an API key and any other is a token; that is
the whole rule, and the reason the prefix here has to be the one the keys
were generated with.
A request authenticated by its key is not asked for a CSRF token, and no
session is started for it. A key's scopes are the authorities SCOPE_x.
-
Method Summary
Modifier and TypeMethodDescriptionauthenticationEntryPoint(AuthenticationEntryPoint entryPoint) What answers a request whose key is refused, and -- when this is the chain's only way in -- one that sent none.voidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.headerName(String headerName) The header a key is sent in, besideAuthorization: Bearer;X-API-Keyunless set.voidinit(HttpSecurity http) Shares what other parts need to know; nothing by default.What every key starts with;cn1_unless set.repository(ApiKeyRepository repository) Where keys are looked up, in place of the application's bean.Methods inherited from class SecurityConfigurer
disable, getBuilder
-
Method Details
-
repository
Where keys are looked up, in place of the application's bean. -
prefix
What every key starts with;cn1_unless set. It must be the prefix the keys were generated with. -
headerName
The header a key is sent in, besideAuthorization: Bearer;X-API-Keyunless set. -
authenticationEntryPoint
What answers a request whose key is refused, and -- when this is the chain's only way in -- one that sent none. -
init
Description copied from class:SecurityConfigurerShares what other parts need to know; nothing by default.- Overrides:
initin classSecurityConfigurer
-
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-