Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
public final class OAuth2ResourceServerConfigurer
- Object
- SecurityConfigurer
- OAuth2ResourceServerConfigurer
Sign-in with a bearer token on each request: the routes under the chain are an OAuth 2.0 resource server, and the token is a JWT.
@Bean
SecurityFilterChain api(HttpSecurity http) {
http.securityMatcher("/api/**")
.authorizeHttpRequests(auth -> auth
.requestMatchers("/api/orders/**").hasAuthority("SCOPE_orders:read")
.anyRequest().authenticated())
.oauth2ResourceServer(oauth2 -> oauth2.jwt(Customizer.withDefaults()));
return http.build();
}
With nothing more said, the tokens are verified by the application’s
JwtDecoder bean, or else as these properties describe:
| Property | Meaning |
|---|---|
cn1.security.oauth2.resourceserver.jwt.issuer-uri | The issuer. Its metadata names the keys, and every token’s iss must be it. |
cn1.security.oauth2.resourceserver.jwt.jwk-set-uri | Where the keys are, when the issuer publishes no metadata. |
cn1.security.oauth2.resourceserver.jwt.public-key-location | A PEM file holding the one public key. |
cn1.security.oauth2.resourceserver.jwt.jws-algorithms | The algorithms accepted, separated by commas; RS256 unless set. |
cn1.security.oauth2.resourceserver.jwt.audiences | What this server is called in a token’s aud, separated by commas. Set it: without it a token the issuer made for another application is accepted here. |
A request authenticated by its token is not asked for a CSRF token: a
browser does not attach an Authorization header to a request another site
made it send, which is the whole of what CSRF protection is against. No
session is started for it either.
A token is refused with 401 and the reason in WWW-Authenticate; a good
token that does not grant enough, with 403 and insufficient_scope. See
BearerTokenAuthenticationEntryPoint and BearerTokenAccessDeniedHandler.
Nested types
class OAuth2ResourceServerConfigurer.JwtConfigurer | How the JWTs of a resource server are verified and read. |
Fields
public static final String ISSUER_URI = "cn1.security.oauth2.resourceserver.jwt.issuer-uri" | The issuer whose tokens are accepted. |
public static final String JWK_SET_URI = "cn1.security.oauth2.resourceserver.jwt.jwk-set-uri" | The address of the issuer’s JSON Web Key Set. |
public static final String PUBLIC_KEY_LOCATION = "cn1.security.oauth2.resourceserver.jwt.public-key-location" | A PEM file holding the public key tokens are verified with. |
public static final String JWS_ALGORITHMS = "cn1.security.oauth2.resourceserver.jwt.jws-algorithms" | The signature algorithms accepted, separated by commas. |
public static final String AUDIENCES = "cn1.security.oauth2.resourceserver.jwt.audiences" | The audiences a token must name one of, separated by commas. |
Methods
Inherited methods
Field details
ISSUER_URI
public static final String ISSUER_URI = "cn1.security.oauth2.resourceserver.jwt.issuer-uri"JWK_SET_URI
public static final String JWK_SET_URI = "cn1.security.oauth2.resourceserver.jwt.jwk-set-uri"PUBLIC_KEY_LOCATION
public static final String PUBLIC_KEY_LOCATION = "cn1.security.oauth2.resourceserver.jwt.public-key-location"JWS_ALGORITHMS
public static final String JWS_ALGORITHMS = "cn1.security.oauth2.resourceserver.jwt.jws-algorithms"AUDIENCES
public static final String AUDIENCES = "cn1.security.oauth2.resourceserver.jwt.audiences"Method details
jwt
public OAuth2ResourceServerConfigurer jwt(Customizer<OAuth2ResourceServerConfigurer.JwtConfigurer> customizer)JwtConfigurer.bearerTokenResolver
public OAuth2ResourceServerConfigurer bearerTokenResolver(BearerTokenResolver resolver)Authorization header
unless set. See DefaultBearerTokenResolver.realmName
public OAuth2ResourceServerConfigurer realmName(String realmName)WWW-Authenticate: Bearer realm="...".
None unless set. It applies to the entry point and the access-denied
handler this configurer brings, not to ones given in their place.authenticationEntryPoint
public OAuth2ResourceServerConfigurer authenticationEntryPoint(AuthenticationEntryPoint entryPoint)accessDeniedHandler
public OAuth2ResourceServerConfigurer accessDeniedHandler(AccessDeniedHandler handler)authenticationManagerResolver
public OAuth2ResourceServerConfigurer authenticationManagerResolver(AuthenticationManagerResolver resolver)jwt: a
JwtIssuerAuthenticationManagerResolver
for a server that trusts several issuers.init
public void init(HttpSecurity http)configure
public void configure(HttpSecurity http)