Class OAuth2ResourceServerConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.OAuth2ResourceServerConfigurer

public final class OAuth2ResourceServerConfigurer extends SecurityConfigurer

Sign-in with a bearer token on each request: the routes under the chain are an OAuth 2.0 resource server, and the token is a JWT.

@Bean
SecurityFilterChain api(HttpSecurity http) {
    http.securityMatcher("/api/**")
        .authorizeHttpRequests(auth -> auth
                .requestMatchers("/api/orders/**").hasAuthority("SCOPE_orders:read")
                .anyRequest().authenticated())
        .oauth2ResourceServer(oauth2 -> oauth2.jwt(Customizer.withDefaults()));
    return http.build();
}

With nothing more said, the tokens are verified by the application's JwtDecoder bean, or else as these properties describe:

Property Meaning
cn1.security.oauth2.resourceserver.jwt.issuer-uri The issuer. Its metadata names the keys, and every token's iss must be it.
cn1.security.oauth2.resourceserver.jwt.jwk-set-uri Where the keys are, when the issuer publishes no metadata.
cn1.security.oauth2.resourceserver.jwt.public-key-location A PEM file holding the one public key.
cn1.security.oauth2.resourceserver.jwt.jws-algorithms The algorithms accepted, separated by commas; RS256 unless set.
cn1.security.oauth2.resourceserver.jwt.audiences What this server is called in a token's aud, separated by commas. Set it: without it a token the issuer made for another application is accepted here.

A request authenticated by its token is not asked for a CSRF token: a browser does not attach an Authorization header to a request another site made it send, which is the whole of what CSRF protection is against. No session is started for it either.

A token is refused with 401 and the reason in WWW-Authenticate; a good token that does not grant enough, with 403 and insufficient_scope. See BearerTokenAuthenticationEntryPoint and BearerTokenAccessDeniedHandler.