Interface OAuth2TokenCustomizer
public interface OAuth2TokenCustomizer
Changes the claims of the tokens an authorization server signs: adds the user's roles to an access token, a tenant to an ID token.
http.authorizationServer(as -> as.tokenCustomizer(context -> {
if (OAuth2TokenContext.ACCESS_TOKEN.equals(context.getTokenType())) {
context.getClaims().claim("tenant", tenants.of(context.getPrincipalName()));
}
}));
-
Method Summary
Modifier and TypeMethodDescriptionvoidcustomize(OAuth2TokenContext context) Called once for every token, before it is signed.
-
Method Details
-
customize
Called once for every token, before it is signed.
-