Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public final class OAuth2ResourceServerConfigurer

  1. Object
  2. SecurityConfigurer
  3. OAuth2ResourceServerConfigurer

Sign-in with a bearer token on each request: the routes under the chain are an OAuth 2.0 resource server, and the token is a JWT.

@Bean
SecurityFilterChain api(HttpSecurity http) {
    http.securityMatcher("/api/**")
        .authorizeHttpRequests(auth -> auth
                .requestMatchers("/api/orders/**").hasAuthority("SCOPE_orders:read")
                .anyRequest().authenticated())
        .oauth2ResourceServer(oauth2 -> oauth2.jwt(Customizer.withDefaults()));
    return http.build();
}

With nothing more said, the tokens are verified by the application’s JwtDecoder bean, or else as these properties describe:

PropertyMeaning
cn1.security.oauth2.resourceserver.jwt.issuer-uriThe issuer. Its metadata names the keys, and every token’s iss must be it.
cn1.security.oauth2.resourceserver.jwt.jwk-set-uriWhere the keys are, when the issuer publishes no metadata.
cn1.security.oauth2.resourceserver.jwt.public-key-locationA PEM file holding the one public key.
cn1.security.oauth2.resourceserver.jwt.jws-algorithmsThe algorithms accepted, separated by commas; RS256 unless set.
cn1.security.oauth2.resourceserver.jwt.audiencesWhat this server is called in a token’s aud, separated by commas. Set it: without it a token the issuer made for another application is accepted here.

A request authenticated by its token is not asked for a CSRF token: a browser does not attach an Authorization header to a request another site made it send, which is the whole of what CSRF protection is against. No session is started for it either.

A token is refused with 401 and the reason in WWW-Authenticate; a good token that does not grant enough, with 403 and insufficient_scope. See BearerTokenAuthenticationEntryPoint and BearerTokenAccessDeniedHandler.

Nested types

class OAuth2ResourceServerConfigurer.JwtConfigurerHow the JWTs of a resource server are verified and read.

Fields

public static final String ISSUER_URI = "cn1.security.oauth2.resourceserver.jwt.issuer-uri"The issuer whose tokens are accepted.
public static final String JWK_SET_URI = "cn1.security.oauth2.resourceserver.jwt.jwk-set-uri"The address of the issuer’s JSON Web Key Set.
public static final String PUBLIC_KEY_LOCATION = "cn1.security.oauth2.resourceserver.jwt.public-key-location"A PEM file holding the public key tokens are verified with.
public static final String JWS_ALGORITHMS = "cn1.security.oauth2.resourceserver.jwt.jws-algorithms"The signature algorithms accepted, separated by commas.
public static final String AUDIENCES = "cn1.security.oauth2.resourceserver.jwt.audiences"The audiences a token must name one of, separated by commas.

Methods

public OAuth2ResourceServerConfigurer jwt(Customizer<OAuth2ResourceServerConfigurer.JwtConfigurer> customizer)The tokens are JWTs, verified here; see JwtConfigurer.
public OAuth2ResourceServerConfigurer bearerTokenResolver(BearerTokenResolver resolver)Where the token is looked for in a request; the Authorization header unless set.
public OAuth2ResourceServerConfigurer realmName(String realmName)The realm the challenges name: WWW-Authenticate: Bearer realm="...".
public OAuth2ResourceServerConfigurer authenticationEntryPoint(AuthenticationEntryPoint entryPoint)What answers a request whose token is missing or refused.
public OAuth2ResourceServerConfigurer accessDeniedHandler(AccessDeniedHandler handler)What answers a request whose token does not grant enough.
public OAuth2ResourceServerConfigurer authenticationManagerResolver(AuthenticationManagerResolver resolver)Chooses what authenticates each request’s token, in place of jwt: a JwtIssuerAuthenticationManagerResolver for a server that trusts several issuers.
public void init(HttpSecurity http)Shares what other parts need to know; nothing by default.
public void configure(HttpSecurity http)Adds this part’s filters; nothing by default.

Inherited methods

Field details

ISSUER_URI

public static final String ISSUER_URI = "cn1.security.oauth2.resourceserver.jwt.issuer-uri"
The issuer whose tokens are accepted.

JWK_SET_URI

public static final String JWK_SET_URI = "cn1.security.oauth2.resourceserver.jwt.jwk-set-uri"
The address of the issuer’s JSON Web Key Set.

PUBLIC_KEY_LOCATION

public static final String PUBLIC_KEY_LOCATION = "cn1.security.oauth2.resourceserver.jwt.public-key-location"
A PEM file holding the public key tokens are verified with.

JWS_ALGORITHMS

public static final String JWS_ALGORITHMS = "cn1.security.oauth2.resourceserver.jwt.jws-algorithms"
The signature algorithms accepted, separated by commas.

AUDIENCES

public static final String AUDIENCES = "cn1.security.oauth2.resourceserver.jwt.audiences"
The audiences a token must name one of, separated by commas.

Method details

jwt

public OAuth2ResourceServerConfigurer jwt(Customizer<OAuth2ResourceServerConfigurer.JwtConfigurer> customizer)
The tokens are JWTs, verified here; see JwtConfigurer.

bearerTokenResolver

public OAuth2ResourceServerConfigurer bearerTokenResolver(BearerTokenResolver resolver)
Where the token is looked for in a request; the Authorization header unless set. See DefaultBearerTokenResolver.

realmName

public OAuth2ResourceServerConfigurer realmName(String realmName)
The realm the challenges name: WWW-Authenticate: Bearer realm="...". None unless set. It applies to the entry point and the access-denied handler this configurer brings, not to ones given in their place.

authenticationEntryPoint

public OAuth2ResourceServerConfigurer authenticationEntryPoint(AuthenticationEntryPoint entryPoint)
What answers a request whose token is missing or refused.

accessDeniedHandler

public OAuth2ResourceServerConfigurer accessDeniedHandler(AccessDeniedHandler handler)
What answers a request whose token does not grant enough.

authenticationManagerResolver

public OAuth2ResourceServerConfigurer authenticationManagerResolver(AuthenticationManagerResolver resolver)
Chooses what authenticates each request’s token, in place of jwt: a JwtIssuerAuthenticationManagerResolver for a server that trusts several issuers.

init

public void init(HttpSecurity http)
Shares what other parts need to know; nothing by default.

configure

public void configure(HttpSecurity http)
Adds this part’s filters; nothing by default.