Class BearerTokenAccessDeniedHandler

java.lang.Object
com.codename1.backend.security.oauth2.server.resource.BearerTokenAccessDeniedHandler
All Implemented Interfaces:
AccessDeniedHandler

public final class BearerTokenAccessDeniedHandler extends Object implements AccessDeniedHandler

Answers a request whose token is good and does not grant what the request needs, as RFC 6750 3.1 says to:

403   WWW-Authenticate: Bearer error="insufficient_scope",
          error_description="The request requires higher privileges than provided by the
          access token.", error_uri="https://tools.ietf.org/html/rfc6750#section-3.1",
          scope="orders:write"

The scope is there when the rule that refused the request asks for one.