Package com.codename1.backend.security.oauth2.jwt
package com.codename1.backend.security.oauth2.jwt
JSON Web Tokens signed with a public key algorithm or a shared secret:
JwtDecoder verifies one and
reads its claims, JwtEncoder
makes one.
JwtDecoder decoder = JwtDecoders.fromIssuerLocation("https://accounts.example.com");
Jwt jwt = decoder.decode(token); // BadJwtException says why not
String user = jwt.getSubject();
Which algorithm verifies a token is settled by the key the decoder holds and
the algorithms it was told to accept, and the token's own alg header has
to agree with both. A token that says none, or says HS256 to a decoder
that holds an RSA public key, is refused before anything is computed.
com.codename1.backend.Jwt is not part of this: it issues and checks HS256
tokens between a server and itself, and stays as it is.
-
ClassDescriptionThe token itself is not acceptable: it is malformed, its signature does not verify, it names an algorithm or a key the decoder does not accept, or it fails a validator.Verifies tokens against keys it holds, or keys an issuer publishes.Builds a
DefaultJwtDecoder.Signs tokens with the keys of aJwkSource.The header of a signature that is about to be made: which algorithm, and optionally which key and what type of token.Builds aJwsHeader.A JSON Web Token whose signature has been made or verified: its text, the headers of its signature and its claims.Refuses a token that is not for this server: one whoseaudnames none of the audiences given here.The claims RFC 7519 registers.The claims of a token that is about to be signed.Builds aJwtClaimsSet.Refuses a token unless one of its claims passes a test.Verifies a token and reads its claims.Makes a decoder for an issuer from what the issuer says about itself.Signs tokens.What aJwtEncoderis asked to sign: claims, and optionally a header.A token could not be signed: there is no key for it, or the key does not fit the algorithm.A token could not be made or could not be judged: a key is missing or unusable, the server that publishes the keys did not answer.Refuses a token whoseissis not exactly the issuer this server trusts.Refuses a token past itsexpor ahead of itsnbf, with a minute's allowance either way for two machines whose clocks disagree.A token whose signature verified and whose claims did not pass: expired, not yet valid, from another issuer, meant for another audience.The validators a decoder is usually given.The keys another server publishes at itsjwks_uri, fetched when they are first needed and kept.Fetches the text at an address.A decoder that is made when the first token arrives, and then kept.