Class OidcIdTokenDecoderFactory

java.lang.Object
com.codename1.backend.security.oauth2.client.OidcIdTokenDecoderFactory

public final class OidcIdTokenDecoderFactory extends Object

Makes, and keeps, the decoder that verifies the ID tokens of one registration.

A token is accepted when its signature verifies under a key the provider publishes at its jwks_uri, with a public key algorithm the registration allows -- never one the token merely names -- and when

  • iss is the registration's issuer, or for a provider with one issuer per tenant, the template with the token's own tid in it;
  • aud contains the client id, and when it names more than one audience, azp is the client id;
  • exp has not passed, and iat and sub are there.

The nonce is checked by the sign-in, which is what knows the value that was sent.

  • Constructor Details

    • OidcIdTokenDecoderFactory

      public OidcIdTokenDecoderFactory()
    • OidcIdTokenDecoderFactory

      public OidcIdTokenDecoderFactory(RemoteJwkSet.Fetcher fetcher)
      Parameters:
      fetcher - what reads the provider's keys
  • Method Details

    • createDecoder

      public JwtDecoder createDecoder(ClientRegistration registration)
      The decoder of registration: one for as long as the server runs, so the provider's keys are fetched once and kept.