Class JwtDecoders
Makes a decoder for an issuer from what the issuer says about itself.
JwtDecoder decoder = JwtDecoders.fromIssuerLocation("https://accounts.example.com");
The issuer's metadata is read from, in order,
<issuer>/.well-known/openid-configuration,
<host>/.well-known/openid-configuration/<path> and
<host>/.well-known/oauth-authorization-server/<path> (OpenID Connect
Discovery and RFC 8414). The metadata must name this very issuer, or it is
refused: that is what stops one tenant's metadata being served for
another's. The decoder that comes back verifies with the keys at the
metadata's jwks_uri and requires every token's iss to be the issuer.
The metadata is fetched by this call. The keys are fetched when the first token arrives.
-
Method Summary
Modifier and TypeMethodDescriptionstatic JwtDecoderfromIssuerLocation(String issuer) A decoder for the tokens ofissuer.static JwtDecoderfromIssuerLocation(String issuer, RemoteJwkSet.Fetcher fetcher) fromIssuerLocation(String)reading throughfetcher.static JwtDecoderfromIssuerLocation(String issuer, RemoteJwkSet.Fetcher fetcher, JwsAlgorithm[] accepted) fromIssuerLocation(String, RemoteJwkSet.Fetcher)accepting the algorithms named here and no others, whatever the issuer's metadata lists.static JwtDecoderfromOidcIssuerLocation(String issuer) The same, for an issuer that serves OpenID Connect Discovery.static Mapmetadata(String issuer, RemoteJwkSet.Fetcher fetcher) The metadata document ofissuer, checked to be its own.
-
Method Details
-
fromIssuerLocation
A decoder for the tokens of
issuer.IllegalArgumentException: when the issuer's metadata cannot be read, names another issuer, or has nojwks_uri
-
fromOidcIssuerLocation
The same, for an issuer that serves OpenID Connect Discovery. -
fromIssuerLocation
fromIssuerLocation(String)reading throughfetcher. -
fromIssuerLocation
public static JwtDecoder fromIssuerLocation(String issuer, RemoteJwkSet.Fetcher fetcher, JwsAlgorithm[] accepted) fromIssuerLocation(String, RemoteJwkSet.Fetcher)accepting the algorithms named here and no others, whatever the issuer's metadata lists. A deployment that allows only ES256 says so with this. ID-token signing metadata does not describe the access-token algorithms this resource server accepts.Parameters
-
issuer: the issuer -
fetcher: what reads the metadata and the keys -
accepted: the access-token algorithms to accept; null or empty for RS256
-
-
metadata
The metadata document of
issuer, checked to be its own.IllegalArgumentException: when it cannot be read or names another issuer
-