JwtTokenService
class JwtTokenService(val generation: JwtTokenGenerationService, val verification: JwtTokenVerificationService, val dpopSigningAlgValuesSupportedStrings: Set<String>?, val supportsRefreshTokens: Boolean) : TokenService(source)
Combines sender-constrained JWT tokens from JwtTokenGenerationService and JwtTokenVerificationService.
Constructors
Link copied to clipboard
constructor(generation: JwtTokenGenerationService, verification: JwtTokenVerificationService, dpopSigningAlgValuesSupportedStrings: Set<String>?, supportsRefreshTokens: Boolean)
Properties
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Tokens are DPoP bound, and validateAccessToken rejects a subject token bound to another key.
Link copied to clipboard
Functions
Link copied to clipboard
open suspend override fun readUserInfo(authorizationHeader: String, request: RequestInfo?): ValidatedAccessToken
Provides information about the access token from authorizationHeader, if it has been issued by generation.
Link copied to clipboard
open suspend fun tokenExchange(request: TokenRequestParameters, expectedResource: String, httpRequest: RequestInfo?, validatedClientKey: JsonWebKey?): KmmResult<TokenResponseParameters>
OAuth 2.0 Token Exchange: Validate the received token from TokenRequestParameters.subjectToken and issue a fresh access token. Callers need to make sure that the client has been authenticated before calling this method.
Link copied to clipboard
open suspend override fun validateAccessToken(authorizationHeader: String, httpRequest: RequestInfo?, validatedClientKey: JsonWebKey?): KmmResult<ValidatedAccessToken>
Validates the access token, and — since generation issued it — resolves the user info stored back then, so callers do not need a second lookup with readUserInfo.
Link copied to clipboard
open suspend override fun validateTokenForTokenExchange(subjectToken: String, httpRequest: RequestInfo?): KmmResult<ValidatedAccessToken>