Class ClientRegistrations
Registrations read from the server's configuration, and from an issuer's metadata.
cn1.security.oauth2.client.registration.google.client-id=...
cn1.security.oauth2.client.registration.google.client-secret=...
cn1.security.oauth2.client.registration.acme.client-id=web
cn1.security.oauth2.client.registration.acme.client-secret=...
cn1.security.oauth2.client.registration.acme.scope=openid,profile,email
cn1.security.oauth2.client.registration.acme.provider=acme-id
cn1.security.oauth2.client.provider.acme-id.issuer-uri=https://id.example.com
A registration's provider names either one of CommonOAuth2Provider or a
cn1.security.oauth2.client.provider.<id> block; when it is not set, the
registration's own id is tried as both. Under a registration:
client-id, client-secret, client-authentication-method
(client_secret_basic, client_secret_post, none), scope,
redirect-uri, client-name, response-mode and provider. Under a
provider: issuer-uri, authorization-uri, token-uri, user-info-uri,
user-emails-uri, jwk-set-uri, user-name-attribute, and
authorization-response-iss-parameter-supported (true for a provider
whose endpoints are named here and that sends iss with its answers; one
read from its issuer's metadata says so itself).
Sign in with Apple is declared in code, as a
ClientRegistrationRepository bean, because its secret is a token signed
with a key and not a setting -- see AppleClientSecret -- and a server
that does not sign in with Apple should not carry what signs one. A
registration here whose provider is apple, or whose provider block names
Apple's issuer or token endpoint, is refused when the configuration is
read, with the code to write in its place.
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionstatic List<ClientRegistration> fromConfig(Config config) The registrations the configuration declares; empty when it declares none.static ClientRegistration.BuilderfromIssuerLocation(String issuer) A builder with the endpoints ofissuerread from its metadata now.static ClientRegistrationresolve(ClientRegistration registration, RemoteJwkSet.Fetcher fetcher) registrationwith the endpoints it does not name read from its issuer's metadata; itself when it names them all.
-
Field Details
-
REGISTRATION
-
PROVIDER
-
-
Method Details
-
fromConfig
The registrations the configuration declares; empty when it declares none.
IllegalArgumentException: when one of them is incomplete, or is for Sign in with Apple
- Throws:
IOException
-
fromIssuerLocation
A builder with the endpoints of
issuerread from its metadata now.IllegalArgumentException: when the metadata cannot be read or names another issuer
-
resolve
public static ClientRegistration resolve(ClientRegistration registration, RemoteJwkSet.Fetcher fetcher) registrationwith the endpoints it does not name read from its issuer's metadata; itself when it names them all.
-