BearerTokenService

class BearerTokenService(val generation: BearerTokenGenerationService, val verification: BearerTokenVerificationService, val dpopSigningAlgValuesSupportedStrings: Set<String>?, val supportsRefreshTokens: Boolean) : TokenService(source)

Combines simple bearer tokens from BearerTokenGenerationService and BearerTokenVerificationService.

Constructors

Link copied to clipboard
constructor(generation: BearerTokenGenerationService, verification: BearerTokenVerificationService, dpopSigningAlgValuesSupportedStrings: Set<String>?, supportsRefreshTokens: Boolean)

Properties

Link copied to clipboard
Link copied to clipboard
open override val supportsRefreshTokens: Boolean
Link copied to clipboard

Whether this service can bind a token presented as TokenRequestParameters.subjectToken to the client presenting it, i.e. whether validateAccessToken proves possession of the key that token is bound to.

Link copied to clipboard

Functions

Link copied to clipboard
open suspend fun dpopNonce(): String?
Link copied to clipboard
open suspend override fun readUserInfo(authorizationHeader: String, request: RequestInfo?): ValidatedAccessToken

Provides information about the access token from authorizationHeader, if it has been issued by generation.

Link copied to clipboard
open suspend fun tokenExchange(request: TokenRequestParameters, expectedResource: String, httpRequest: RequestInfo?, validatedClientKey: JsonWebKey?): KmmResult<TokenResponseParameters>

OAuth 2.0 Token Exchange: Validate the received token from TokenRequestParameters.subjectToken and issue a fresh access token. Callers need to make sure that the client has been authenticated before calling this method.

Link copied to clipboard
open suspend fun validateAccessToken(authorizationHeader: String, httpRequest: RequestInfo?, validatedClientKey: JsonWebKey?): KmmResult<ValidatedAccessToken>

Validates the access token from authorizationHeader and returns what it authorizes. Implementations that issued the token themselves also fill ValidatedAccessToken.userInfoExtended, so callers do not need a second lookup with readUserInfo.

Link copied to clipboard
open suspend override fun validateTokenForTokenExchange(subjectToken: String, httpRequest: RequestInfo?): KmmResult<ValidatedAccessToken>