Package com.codename1.backend.security.oauth2.client
package com.codename1.backend.security.oauth2.client
Signing users in through another identity provider, with OAuth2 or OpenID
Connect: this server as a client of Google, GitHub, Microsoft, Apple or any
provider described by a ClientRegistration.
Turned on with http.oauth2Login(...); see
OAuth2LoginConfigurer. A server that does
not call it carries none of this.
-
ClassDescriptionThe client secret of Sign in with Apple, which is not a text Apple issues but a token this server signs: an ES256 JWT naming the team, the client and Apple, signed with the
.p8key downloaded from the developer account.Where anOAuth2AuthorizationRequestwaits while the user is at the identity provider.This server as a client of one identity provider: the id and secret the provider issued it, the scopes it asks for, and where the provider's endpoints are.Builds aClientRegistration.Where a client secret comes from when it is not a fixed text: Sign in with Apple's is a token this server signs.Where the provider is.The identity providers this server signs users in through.Registrations read from the server's configuration, and from an issuer's metadata.The settings of the identity providers most applications sign in through, so that a registration needs only the id and secret the provider issued.Keeps the request in a cookie of its own, for a provider that answers with a form the browser posts (ClientRegistration.FORM_POST): Sign in with Apple.The exchange over the runtime's HTTP client, which parks the request's thread while the provider answers.Starts a sign-in for aGETof/oauth2/authorization/{registrationId}.AnOAuth2Userthat holds what it is given.The user of a provider that is OAuth2 without OpenID Connect -- GitHub: its attributes are what the provider's user info address answers the access token with, and its name is the registration's name attribute among them.AnOidcUserthat holds what it is given.Which local user each identity at a provider is: the pairs of a registration's id and the provider's subject, each tied to one user name.Keeps the request in the HTTP session: the default, for every provider that answers with a redirect.Registrations given when the server starts.Identities kept in this process: gone when it stops, and unknown to any other.Identities kept in the server's database, in thecn1_federated_identitytable ofSecuritySchema.Signs the user of an identity provider in as a user of the application's own.What a token endpoint answered a successful exchange with.Exchanges an authorization code for tokens at the provider's token endpoint.A user who signed in through an identity provider.One user being sent to an identity provider: where to, and the three values that tie the provider's answer back to this browser -- thestate, thenoncethe ID token must repeat, and the PKCE verifier whose hash went with the request.Builds anOAuth2AuthorizationRequest.Decides whether a request starts a sign-in at an identity provider, and what is asked of the provider when it does.A user as an identity provider described them.What anOAuth2UserServiceis asked with: the provider the user signed in through, and the tokens it issued.Makes the user of a sign-in through an identity provider.Makes, and keeps, the decoder that verifies the ID tokens of one registration.A user an OpenID Connect provider vouched for with an ID token.AnOAuth2UserRequestfor a provider that also issued an ID token, which has been verified by the time a service sees it.The user of an OpenID Connect provider: the claims of the verified ID token, and -- when the registration names a user info address and a scope that has claims there was granted -- what that address adds to them.