JwtTokenService

class JwtTokenService(val generation: JwtTokenGenerationService, val verification: JwtTokenVerificationService, val dpopSigningAlgValuesSupportedStrings: Set<String>?, val supportsRefreshTokens: Boolean) : TokenService(source)

Combines sender-constrained JWT tokens from JwtTokenGenerationService and JwtTokenVerificationService.

Constructors

Link copied to clipboard
constructor(generation: JwtTokenGenerationService, verification: JwtTokenVerificationService, dpopSigningAlgValuesSupportedStrings: Set<String>?, supportsRefreshTokens: Boolean)

Properties

Link copied to clipboard
Link copied to clipboard
open override val supportsRefreshTokens: Boolean
Link copied to clipboard
open override val supportsTokenExchange: Boolean = true

Tokens are DPoP bound, and validateAccessToken rejects a subject token bound to another key.

Link copied to clipboard

Functions

Link copied to clipboard
open suspend fun dpopNonce(): String?
Link copied to clipboard
open suspend override fun readUserInfo(authorizationHeader: String, request: RequestInfo?): ValidatedAccessToken

Provides information about the access token from authorizationHeader, if it has been issued by generation.

Link copied to clipboard
open suspend fun tokenExchange(request: TokenRequestParameters, expectedResource: String, httpRequest: RequestInfo?, validatedClientKey: JsonWebKey?): KmmResult<TokenResponseParameters>

OAuth 2.0 Token Exchange: Validate the received token from TokenRequestParameters.subjectToken and issue a fresh access token. Callers need to make sure that the client has been authenticated before calling this method.

Link copied to clipboard
open suspend override fun validateAccessToken(authorizationHeader: String, httpRequest: RequestInfo?, validatedClientKey: JsonWebKey?): KmmResult<ValidatedAccessToken>

Validates the access token, and — since generation issued it — resolves the user info stored back then, so callers do not need a second lookup with readUserInfo.

Link copied to clipboard
open suspend override fun validateTokenForTokenExchange(subjectToken: String, httpRequest: RequestInfo?): KmmResult<ValidatedAccessToken>