Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public final class HttpSecurity

  1. Object
  2. HttpSecurity

Builds one SecurityFilterChain. A @Bean method that returns a chain declares a parameter of this type and is handed a new one:

@Bean
SecurityFilterChain web(HttpSecurity http) {
    http.authorizeHttpRequests(auth -> auth
            .requestMatchers("/public/**").permitAll()
            .anyRequest().authenticated())
        .formLogin(Customizer.withDefaults())
        .httpBasic(Customizer.withDefaults());
    return http.build();
}

Out of the box a chain guards every request, writes the security headers, keeps who is signed in in the HTTP session, protects that session against CSRF and gives a request nobody signed in for an anonymous authentication. It has no way of signing in and no authorization rules until it is given them.

Everything else is there only when the chain asks for it, and a server carries the code of only what its chains ask for: formLogin – which brings sign-out and the memory of where a request was going with it – httpBasic, oauth2Login, oauth2ResourceServer, authorizationServer, apiKey, rateLimit, rememberMe, mfa, webAuthn, logout and requestCache. A server that only verifies tokens has no login page, no password hashing and no user store in it. This makes two departures from Spring Security. The first: a chain without formLogin has no POST /logout until it calls logout.

The second: a chain whose session policy is SessionCreationPolicy.STATELESS keeps nothing a forged request could ride on, and has no CSRF filter unless csrf asks for one. One that takes HTTP Basic credentials from browsers should ask.

Users come from the application’s beans: a UserDetailsService and, if there is one, a PasswordEncoder and a UserDetailsPasswordService – or AuthenticationProvider beans, or an AuthenticationManager bean. A chain can also be told directly, with userDetailsService, authenticationProvider or authenticationManager.

Fields

public static final String USER_NAME = "cn1.security.user.name"The name of the one user a server with no user store has, when USER_PASSWORD is set; user unless set.
public static final String USER_PASSWORD = "cn1.security.user.password"That user’s password, as it would be stored; one written without an {id} is taken as {noop}, which verifies on a development profile only.
public static final String USER_ROLES = "cn1.security.user.roles"That user’s roles, separated by commas.
public static final String PASSWORD_MAX_CONCURRENT = "cn1.security.password.maxConcurrent"The most passwords checked at one time; a sign-in beyond that is answered 503 at once.

Methods

public HttpSecurity securityMatcher(String... patterns)Limits the chain to the requests whose path matches any of these Ant patterns; see AntPathRequestMatcher.
public HttpSecurity securityMatcher(RequestMatcher requestMatcher)Limits the chain to the requests requestMatcher matches.
public HttpSecurity authorizeHttpRequests(Customizer<AuthorizeHttpRequestsConfigurer.AuthorizationManagerRequestMatcherRegistry> customizer)The authorization rules; see AuthorizeHttpRequestsConfigurer.
public HttpSecurity formLogin(Customizer<FormLoginConfigurer> customizer)Sign-in through an HTML form; see FormLoginConfigurer.
public HttpSecurity httpBasic(Customizer<HttpBasicConfigurer> customizer)Sign-in with HTTP Basic credentials; see HttpBasicConfigurer.
public HttpSecurity oauth2ResourceServer(Customizer<OAuth2ResourceServerConfigurer> customizer)Sign-in with a bearer token that is a JWT; see OAuth2ResourceServerConfigurer.
public HttpSecurity oauth2Login(Customizer<OAuth2LoginConfigurer> customizer)Sign-in through another identity provider, with OAuth2 or OpenID Connect; see OAuth2LoginConfigurer.
public HttpSecurity authorizationServer(Customizer<AuthorizationServerConfigurer> customizer)Makes this server an OAuth2 authorization server and OpenID Connect provider: the one that issues tokens; see AuthorizationServerConfigurer.
public HttpSecurity rememberMe(Customizer<RememberMeConfigurer> customizer)A cookie that signs a returning user in; see RememberMeConfigurer.
public HttpSecurity mfa(Customizer<MfaConfigurer> customizer)A second factor at sign-in; see MfaConfigurer.
public HttpSecurity webAuthn(Customizer<WebAuthnConfigurer> customizer)Passkeys: registering one for a user who is signed in, and signing in with one; see WebAuthnConfigurer.
public HttpSecurity apiKey(Customizer<ApiKeyConfigurer> customizer)Sign-in with an API key; see ApiKeyConfigurer.
public HttpSecurity rateLimit(RequestMatcher matcher, RateLimitKeyResolver keyResolver, RateLimiter limiter)Limits how often the requests matcher matches may be made under one key, and answers 429 with Retry-After beyond that.
public HttpSecurity rateLimit(String pattern, RateLimitKeyResolver keyResolver, RateLimiter limiter)rateLimit(RequestMatcher, RateLimitKeyResolver, RateLimiter) for the requests whose path matches an Ant pattern.
public HttpSecurity logout(Customizer<LogoutConfigurer> customizer)Sign-out; see LogoutConfigurer.
public HttpSecurity csrf(Customizer<CsrfConfigurer> customizer)CSRF protection; see CsrfConfigurer.
public HttpSecurity sessionManagement(Customizer<SessionManagementConfigurer> customizer)The use of the HTTP session; see SessionManagementConfigurer.
public HttpSecurity headers(Customizer<HeadersConfigurer> customizer)The security headers; see HeadersConfigurer.
public HttpSecurity requestCache(Customizer<RequestCacheConfigurer> customizer)Where an anonymous request’s address is remembered; see RequestCacheConfigurer.
public HttpSecurity exceptionHandling(Customizer<ExceptionHandlingConfigurer> customizer)The answers to a request that must sign in or is denied; see ExceptionHandlingConfigurer.
public HttpSecurity securityContext(Customizer<SecurityContextConfigurer> customizer)Where who is signed in is kept; see SecurityContextConfigurer.
public HttpSecurity anonymous(Customizer<AnonymousConfigurer> customizer)The authentication of a request nobody signed in for; see AnonymousConfigurer.
public <C extends SecurityConfigurer> HttpSecurity with(C configurer, Customizer<C> customizer)Applies a configurer of the application’s or a library’s own, and lets customizer set it up.
public <C extends SecurityConfigurer> C getConfigurer(Class<C> type)The configurer of this class applied to the chain, or null.
public HttpSecurity authenticationManager(AuthenticationManager authenticationManager)The AuthenticationManager the chain’s sign-in filters use, in place of what the application’s beans would give.
public HttpSecurity authenticationProvider(AuthenticationProvider authenticationProvider)One more provider for this chain, asked before those found among the application’s beans.
public HttpSecurity userDetailsService(UserDetailsService userDetailsService)The users of this chain, in place of the application’s UserDetailsService bean.
public HttpSecurity addFilterBefore(SecurityFilter filter, Class<? extends SecurityFilter> beforeFilter)Adds filter just before the filter of class beforeFilter.
public HttpSecurity addFilterAfter(SecurityFilter filter, Class<? extends SecurityFilter> afterFilter)Adds filter just after the filter of class afterFilter.
public HttpSecurity addFilterAt(SecurityFilter filter, Class<? extends SecurityFilter> atFilter)Adds filter at the place of the filter of class atFilter, beside it rather than instead of it: which of the two runs first is not defined.
public <C> C getSharedObject(Class<C> sharedType)Something the parts of a chain share, by its class: one set with setSharedObject, or else the one bean of the application that is an instance of sharedType.
public <C> void setSharedObject(Class<C> sharedType, C object)Shares object with the parts of this chain under sharedType.
public Config getConfig()The configuration of the server the chain is built for.
public DefaultSecurityFilterChain build()The chain.
public HttpSecurity authenticationCodec(AuthenticationCodec codec)Keeps one more kind of Authentication in the session as itself; see AuthenticationCodec.

Inherited methods

Field details

USER_NAME

public static final String USER_NAME = "cn1.security.user.name"
The name of the one user a server with no user store has, when USER_PASSWORD is set; user unless set.

USER_PASSWORD

public static final String USER_PASSWORD = "cn1.security.user.password"
That user’s password, as it would be stored; one written without an {id} is taken as {noop}, which verifies on a development profile only.

USER_ROLES

public static final String USER_ROLES = "cn1.security.user.roles"
That user’s roles, separated by commas.

PASSWORD_MAX_CONCURRENT

public static final String PASSWORD_MAX_CONCURRENT = "cn1.security.password.maxConcurrent"
The most passwords checked at one time; a sign-in beyond that is answered 503 at once. No bound unless set. See DaoAuthenticationProvider.setMaxConcurrentPasswordChecks.

Method details

securityMatcher

public HttpSecurity securityMatcher(String... patterns)
Limits the chain to the requests whose path matches any of these Ant patterns; see AntPathRequestMatcher. A chain without one guards every request, and must then be the last in @Order.

securityMatcher

public HttpSecurity securityMatcher(RequestMatcher requestMatcher)
Limits the chain to the requests requestMatcher matches.

authorizeHttpRequests

public HttpSecurity authorizeHttpRequests(Customizer<AuthorizeHttpRequestsConfigurer.AuthorizationManagerRequestMatcherRegistry> customizer)
The authorization rules; see AuthorizeHttpRequestsConfigurer.

formLogin

public HttpSecurity formLogin(Customizer<FormLoginConfigurer> customizer)
Sign-in through an HTML form; see FormLoginConfigurer. Brings sign-out (logout) and the memory of where a request was going (requestCache) with it, unless the chain has turned those off.

httpBasic

public HttpSecurity httpBasic(Customizer<HttpBasicConfigurer> customizer)
Sign-in with HTTP Basic credentials; see HttpBasicConfigurer.

oauth2ResourceServer

public HttpSecurity oauth2ResourceServer(Customizer<OAuth2ResourceServerConfigurer> customizer)
Sign-in with a bearer token that is a JWT; see OAuth2ResourceServerConfigurer.

oauth2Login

public HttpSecurity oauth2Login(Customizer<OAuth2LoginConfigurer> customizer)
Sign-in through another identity provider, with OAuth2 or OpenID Connect; see OAuth2LoginConfigurer. Brings sign-out and the memory of where a request was going with it, as formLogin does.

authorizationServer

public HttpSecurity authorizationServer(Customizer<AuthorizationServerConfigurer> customizer)
Makes this server an OAuth2 authorization server and OpenID Connect provider: the one that issues tokens; see AuthorizationServerConfigurer. How a user signs in to it is whatever else the chain declares.

rememberMe

public HttpSecurity rememberMe(Customizer<RememberMeConfigurer> customizer)
A cookie that signs a returning user in; see RememberMeConfigurer. Brings sign-out with it, as formLogin does.

mfa

public HttpSecurity mfa(Customizer<MfaConfigurer> customizer)
A second factor at sign-in; see MfaConfigurer. Brings sign-out with it, as formLogin does.

webAuthn

public HttpSecurity webAuthn(Customizer<WebAuthnConfigurer> customizer)
Passkeys: registering one for a user who is signed in, and signing in with one; see WebAuthnConfigurer. Brings sign-out with it, as formLogin does.

apiKey

public HttpSecurity apiKey(Customizer<ApiKeyConfigurer> customizer)
Sign-in with an API key; see ApiKeyConfigurer.

rateLimit

public HttpSecurity rateLimit(RequestMatcher matcher, RateLimitKeyResolver keyResolver, RateLimiter limiter)

Limits how often the requests matcher matches may be made under one key, and answers 429 with Retry-After beyond that.

http.rateLimit(AntPathRequestMatcher.antMatcher("/login"),
        RateLimitKeys.clientAddress(), new InMemoryRateLimiter(5, 60));
http.rateLimit("/api/**", RateLimitKeys.firstOf(RateLimitKeys.apiKeyId(),
        RateLimitKeys.principal()), new InMemoryRateLimiter(600, 60));

A limit keyed by something the request has from the start – its client’s address, its session – is applied before anything else in the chain. One keyed by who signed in is applied once that is known, and does not apply to a request nobody signed in for. Rules are consulted in the order given, and a request counts against every rule that matches it up to the one that refuses it.

Two rules given the same limiter share its counts for any key they have in common; give each its own unless that is what is meant.

Parameters

matcher RequestMatcher
Not documented.
keyResolver RateLimitKeyResolver
which key a request counts under; see RateLimitKeys
limiter RateLimiter
what counts; null for the application’s one RateLimiter bean. InMemoryRateLimiter counts in this process alone.

rateLimit

public HttpSecurity rateLimit(String pattern, RateLimitKeyResolver keyResolver, RateLimiter limiter)
rateLimit(RequestMatcher, RateLimitKeyResolver, RateLimiter) for the requests whose path matches an Ant pattern.

logout

public HttpSecurity logout(Customizer<LogoutConfigurer> customizer)
Sign-out; see LogoutConfigurer. A chain with formLogin has it already; any other chain has none until it calls this.

csrf

public HttpSecurity csrf(Customizer<CsrfConfigurer> customizer)
CSRF protection; see CsrfConfigurer. On for every chain that keeps a session; a SessionCreationPolicy.STATELESS chain has it only when it calls this.

sessionManagement

public HttpSecurity sessionManagement(Customizer<SessionManagementConfigurer> customizer)
The use of the HTTP session; see SessionManagementConfigurer.

headers

public HttpSecurity headers(Customizer<HeadersConfigurer> customizer)
The security headers; see HeadersConfigurer.

requestCache

public HttpSecurity requestCache(Customizer<RequestCacheConfigurer> customizer)
Where an anonymous request’s address is remembered; see RequestCacheConfigurer.

exceptionHandling

public HttpSecurity exceptionHandling(Customizer<ExceptionHandlingConfigurer> customizer)
The answers to a request that must sign in or is denied; see ExceptionHandlingConfigurer.

securityContext

public HttpSecurity securityContext(Customizer<SecurityContextConfigurer> customizer)
Where who is signed in is kept; see SecurityContextConfigurer.

anonymous

public HttpSecurity anonymous(Customizer<AnonymousConfigurer> customizer)
The authentication of a request nobody signed in for; see AnonymousConfigurer.

with

public <C extends SecurityConfigurer> HttpSecurity with(C configurer, Customizer<C> customizer)
Applies a configurer of the application’s or a library’s own, and lets customizer set it up.

getConfigurer

public <C extends SecurityConfigurer> C getConfigurer(Class<C> type)
The configurer of this class applied to the chain, or null.

authenticationManager

public HttpSecurity authenticationManager(AuthenticationManager authenticationManager)
The AuthenticationManager the chain’s sign-in filters use, in place of what the application’s beans would give.

authenticationProvider

public HttpSecurity authenticationProvider(AuthenticationProvider authenticationProvider)
One more provider for this chain, asked before those found among the application’s beans.

userDetailsService

public HttpSecurity userDetailsService(UserDetailsService userDetailsService)
The users of this chain, in place of the application’s UserDetailsService bean.

addFilterBefore

public HttpSecurity addFilterBefore(SecurityFilter filter, Class<? extends SecurityFilter> beforeFilter)
Adds filter just before the filter of class beforeFilter.

addFilterAfter

public HttpSecurity addFilterAfter(SecurityFilter filter, Class<? extends SecurityFilter> afterFilter)
Adds filter just after the filter of class afterFilter.

addFilterAt

public HttpSecurity addFilterAt(SecurityFilter filter, Class<? extends SecurityFilter> atFilter)
Adds filter at the place of the filter of class atFilter, beside it rather than instead of it: which of the two runs first is not defined.

getSharedObject

public <C> C getSharedObject(Class<C> sharedType)
Something the parts of a chain share, by its class: one set with setSharedObject, or else the one bean of the application that is an instance of sharedType. Null when there is none, or more than one bean.

setSharedObject

public <C> void setSharedObject(Class<C> sharedType, C object)
Shares object with the parts of this chain under sharedType.

getConfig

public Config getConfig()
The configuration of the server the chain is built for.

build

public DefaultSecurityFilterChain build()
The chain. An HttpSecurity builds one chain, once.

authenticationCodec

public HttpSecurity authenticationCodec(AuthenticationCodec codec)
Keeps one more kind of Authentication in the session as itself; see AuthenticationCodec. Called before the chain is built, or from a configurer’s init: the ways of signing in that have a kind of their own – oauth2Login, webAuthn – each call it for theirs.