Class AuthorizationServerSettings

java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.AuthorizationServerSettings

public final class AuthorizationServerSettings extends Object

Who the authorization server is and where its endpoints are.

http.authorizationServer(as -> as.settings(AuthorizationServerSettings.builder()
        .issuer("https://id.example.com").build()));

The issuer is the address clients reach this server at, with no trailing slash; it is the iss of every token and the base of every address in the metadata. It can also be given as cn1.security.authorizationserver.issuer. Outside a development profile it must be given one way or the other: an issuer read off a request is whatever the request's Host header said. On a development profile, with neither, it is taken from the request.

  • Field Details

    • ISSUER

      public static final String ISSUER
      The setting that holds the issuer.
      See Also:
    • AUDIENCE

      public static final String AUDIENCE
      The setting that holds the default audience; see AuthorizationServerSettings.Builder.defaultAudience.
      See Also:
  • Method Details

    • builder

      public static AuthorizationServerSettings.Builder builder()
    • getIssuer

      public String getIssuer()
      The issuer, or null to read it from the configuration.
    • getDefaultAudience

      public String getDefaultAudience()
      The aud of an access token whose request named no resource, or null for the configured one, and the issuer when there is none.
    • getAuthorizationEndpoint

      public String getAuthorizationEndpoint()
      /oauth2/authorize unless set.
    • getTokenEndpoint

      public String getTokenEndpoint()
      /oauth2/token unless set.
    • getJwkSetEndpoint

      public String getJwkSetEndpoint()
      /oauth2/jwks unless set.
    • getTokenRevocationEndpoint

      public String getTokenRevocationEndpoint()
      /oauth2/revoke unless set.
    • getDeviceAuthorizationEndpoint

      public String getDeviceAuthorizationEndpoint()
      /oauth2/device_authorization unless set.
    • getDeviceVerificationEndpoint

      public String getDeviceVerificationEndpoint()
      /oauth2/device_verification unless set.
    • getOidcUserInfoEndpoint

      public String getOidcUserInfoEndpoint()
      /userinfo unless set.
    • validIssuer

      public static String validIssuer(String issuer)
      issuer, required to be an http or https address with no query, no fragment and no trailing slash, as RFC 8414 asks of one.