Class JwtGrantedAuthoritiesConverter

java.lang.Object
com.codename1.backend.security.oauth2.server.resource.JwtGrantedAuthoritiesConverter
All Implemented Interfaces:
Converter<Jwt, Collection<GrantedAuthority>>

public final class JwtGrantedAuthoritiesConverter extends Object implements Converter<Jwt, Collection<GrantedAuthority>>

Reads a token's authorities out of one claim: each value, with a prefix in front.

Unless told otherwise the claim is scope -- one text, the scopes separated by spaces, as RFC 8693 and most issuers write it -- or else scp, and the prefix is SCOPE_. A token with "scope": "orders:read orders:write" is granted SCOPE_orders:read and SCOPE_orders:write, which is what hasAuthority("SCOPE_orders:read") asks for.

JwtGrantedAuthoritiesConverter roles = new JwtGrantedAuthoritiesConverter();
roles.setAuthoritiesClaimName("roles");     // ["ADMIN", "USER"]
roles.setAuthorityPrefix("ROLE_");          // so hasRole("ADMIN") matches
  • Constructor Details

    • JwtGrantedAuthoritiesConverter

      public JwtGrantedAuthoritiesConverter()
  • Method Details

    • setAuthorityPrefix

      public void setAuthorityPrefix(String authorityPrefix)
      What goes in front of every value; SCOPE_ unless set, and empty for none.
    • setAuthoritiesClaimName

      public void setAuthoritiesClaimName(String authoritiesClaimName)
      The claim to read, in place of scope and scp.
    • convert

      public Collection<GrantedAuthority> convert(Jwt jwt)
      Description copied from interface: Converter
      What source becomes; null when it becomes nothing.
      Specified by:
      convert in interface Converter<Jwt, Collection<GrantedAuthority>>