Class ApiKeyClientAuthenticationProvider

java.lang.Object
com.broadleafcommerce.auth.authorization.security.apikey.ApiKeyClientAuthenticationProvider
All Implemented Interfaces:
org.springframework.security.authentication.AuthenticationProvider

public class ApiKeyClientAuthenticationProvider extends Object implements org.springframework.security.authentication.AuthenticationProvider
Authenticates the ApiKeyClientAuthenticationToken generated by the ApiKeyClientAuthenticationConverter during Phase 1 of the OAuth2 flow.

This provider hashes the provided key, finds the corresponding ApiKey and its parent AuthorizedClient, and validates that the client is permitted to use the API key authentication method.

See Also:
  • Constructor Details

    • ApiKeyClientAuthenticationProvider

      public ApiKeyClientAuthenticationProvider(ApiKeyHasher apiKeyHasher, ApiKeyService<ApiKey> apiKeyService, org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository registeredClientRepository)
  • Method Details

    • authenticate

      public org.springframework.security.core.Authentication authenticate(org.springframework.security.core.Authentication authentication) throws org.springframework.security.core.AuthenticationException
      Authenticates the provided token. If successful, returns a fully authenticated ApiKeyClientAuthenticationToken containing the RegisteredClient and whitelisted domains.
      Specified by:
      authenticate in interface org.springframework.security.authentication.AuthenticationProvider
      Parameters:
      authentication - the authentication request object
      Returns:
      a fully authenticated object including credentials
      Throws:
      org.springframework.security.core.AuthenticationException - if authentication fails
    • supports

      public boolean supports(Class<?> authentication)
      Specified by:
      supports in interface org.springframework.security.authentication.AuthenticationProvider
    • getApiKeyHasher

      protected ApiKeyHasher getApiKeyHasher()
    • getApiKeyService

      protected ApiKeyService<ApiKey> getApiKeyService()
    • getRegisteredClientRepository

      protected org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository getRegisteredClientRepository()