TokenService
Access token service that combines generation and verification, i.e., it is suitable to be used in an implementation of an OAuth 2.0 Authorization Server.
Also implements OAuth 2.0 Token Exchange.
Inheritors
Properties
Whether this service can bind a token presented as TokenRequestParameters.subjectToken to the client presenting it, i.e. whether validateAccessToken proves possession of the key that token is bound to.
Functions
Provides information about the access token from authorizationHeader, if it has been issued by generation.
OAuth 2.0 Token Exchange: Validate the received token from TokenRequestParameters.subjectToken and issue a fresh access token. Callers need to make sure that the client has been authenticated before calling this method.
Validates the access token from authorizationHeader and returns what it authorizes. Implementations that issued the token themselves also fill ValidatedAccessToken.userInfoExtended, so callers do not need a second lookup with readUserInfo.