Class DefaultJwtEncoder

java.lang.Object
com.codename1.backend.security.oauth2.jwt.DefaultJwtEncoder
All Implemented Interfaces:
JwtEncoder

public final class DefaultJwtEncoder extends Object implements JwtEncoder

Signs tokens with the keys of a JwkSource.

JwtEncoder encoder = new DefaultJwtEncoder(JwkSet.of(
        Jwk.ofPrivateKey(KeyFiles.readPrivateKey("/etc/app/signing.pem"))));
String token = encoder.encode(JwtEncoderParameters.from(claims)).getTokenValue();

The key is the first in the source that can sign and fits what the header asks for: the key of that kid when the header names one, a key of the algorithm's kind otherwise. With no header the first private key signs, under the algorithm its kind is for -- RS256 for RSA, ES256 or ES384 for an EC key by its curve, HS256 for a secret. The token's kid is the key's.

The source is asked on every call, so a source that starts answering with a new key first has rotated it; see JwkSource.

  • Constructor Details

    • DefaultJwtEncoder

      public DefaultJwtEncoder(JwkSource keys)
  • Method Details