Package com.codename1.backend.security.oauth2.core


package com.codename1.backend.security.oauth2.core
What the OAuth 2.0 parts of the security layer share: the error a token or a request is refused with, and the validators a token is put to.
  • Class
    Description
    How a client obtains a token: the grant_type of RFC 6749 and RFC 8628.
    How a client proves which client it is at the token endpoint.
    Makes one thing out of another: an Authentication out of a verified token, its authorities out of its claims.
    Puts a token to several validators and reports everything any of them found: a token that is both expired and from the wrong issuer says both.
    An authentication that failed for a reason OAuth 2.0 has a code for.
    Why something OAuth 2.0 was refused: a code from the specification that defines it, and optionally a sentence for a person and an address to read more at.
    The error codes this layer answers with: those of RFC 6749, RFC 6750, RFC 7009 and RFC 8628, and the ones a sign-in through another provider fails with.
    The small pieces of text an OAuth2 exchange is made of: a form, a query, a list of scopes, a random value, a PKCE challenge.
    One check a token is put to after its signature has verified: is it still in date, is it from the issuer this server trusts, is it meant for this server.
    What an OAuth2TokenValidator found: nothing, or the errors.