Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public final class OidcIdTokenDecoderFactory

  1. Object
  2. OidcIdTokenDecoderFactory

Makes, and keeps, the decoder that verifies the ID tokens of one registration.

A token is accepted when its signature verifies under a key the provider publishes at its jwks_uri, with a public key algorithm the registration allows – never one the token merely names – and when

  • iss is the registration’s issuer, or for a provider with one issuer per tenant, the template with the token’s own tid in it;
  • aud contains the client id, and when it names more than one audience, azp is the client id;
  • exp has not passed, and iat and sub are there.

The nonce is checked by the sign-in, which is what knows the value that was sent.

Constructors

public OidcIdTokenDecoderFactory()
public OidcIdTokenDecoderFactory(RemoteJwkSet.Fetcher fetcher)

Methods

public synchronized JwtDecoder createDecoder(ClientRegistration registration)The decoder of registration: one for as long as the server runs, so the provider’s keys are fetched once and kept.

Inherited methods

Constructor details

OidcIdTokenDecoderFactory

public OidcIdTokenDecoderFactory()

OidcIdTokenDecoderFactory

public OidcIdTokenDecoderFactory(RemoteJwkSet.Fetcher fetcher)

Parameters

fetcher RemoteJwkSet.Fetcher
what reads the provider’s keys

Method details

createDecoder

public synchronized JwtDecoder createDecoder(ClientRegistration registration)
The decoder of registration: one for as long as the server runs, so the provider’s keys are fetched once and kept.