Class ClientRegistrations

java.lang.Object
com.codename1.backend.security.oauth2.client.ClientRegistrations

public final class ClientRegistrations extends Object

Registrations read from the server's configuration, and from an issuer's metadata.

cn1.security.oauth2.client.registration.google.client-id=...
cn1.security.oauth2.client.registration.google.client-secret=...

cn1.security.oauth2.client.registration.acme.client-id=web
cn1.security.oauth2.client.registration.acme.client-secret=...
cn1.security.oauth2.client.registration.acme.scope=openid,profile,email
cn1.security.oauth2.client.registration.acme.provider=acme-id
cn1.security.oauth2.client.provider.acme-id.issuer-uri=https://id.example.com

A registration's provider names either one of CommonOAuth2Provider or a cn1.security.oauth2.client.provider.<id> block; when it is not set, the registration's own id is tried as both. Under a registration: client-id, client-secret, client-authentication-method (client_secret_basic, client_secret_post, none), scope, redirect-uri, client-name, response-mode and provider. Under a provider: issuer-uri, authorization-uri, token-uri, user-info-uri, user-emails-uri, jwk-set-uri, user-name-attribute, and authorization-response-iss-parameter-supported (true for a provider whose endpoints are named here and that sends iss with its answers; one read from its issuer's metadata says so itself).

Sign in with Apple is declared in code, as a ClientRegistrationRepository bean, because its secret is a token signed with a key and not a setting -- see AppleClientSecret -- and a server that does not sign in with Apple should not carry what signs one. A registration here whose provider is apple, or whose provider block names Apple's issuer or token endpoint, is refused when the configuration is read, with the code to write in its place.

  • Field Details

  • Method Details

    • fromConfig

      public static List<ClientRegistration> fromConfig(Config config) throws IOException

      The registrations the configuration declares; empty when it declares none.

      • IllegalArgumentException: when one of them is incomplete, or is for Sign in with Apple
      Throws:
      IOException
    • fromIssuerLocation

      public static ClientRegistration.Builder fromIssuerLocation(String issuer)

      A builder with the endpoints of issuer read from its metadata now.

      • IllegalArgumentException: when the metadata cannot be read or names another issuer
    • resolve

      public static ClientRegistration resolve(ClientRegistration registration, RemoteJwkSet.Fetcher fetcher)
      registration with the endpoints it does not name read from its issuer's metadata; itself when it names them all.