Class ApiKeyClientAuthenticationProvider
java.lang.Object
com.broadleafcommerce.auth.authorization.security.apikey.ApiKeyClientAuthenticationProvider
- All Implemented Interfaces:
org.springframework.security.authentication.AuthenticationProvider
public class ApiKeyClientAuthenticationProvider
extends Object
implements org.springframework.security.authentication.AuthenticationProvider
Authenticates the
ApiKeyClientAuthenticationToken generated by the
ApiKeyClientAuthenticationConverter during Phase 1 of the OAuth2 flow.
This provider hashes the provided key, finds the corresponding ApiKey and its parent
AuthorizedClient, and validates that the client is permitted to use the API key
authentication method.
-
Constructor Summary
ConstructorsConstructorDescriptionApiKeyClientAuthenticationProvider(ApiKeyHasher apiKeyHasher, ApiKeyService<ApiKey> apiKeyService, org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository registeredClientRepository) -
Method Summary
Modifier and TypeMethodDescriptionorg.springframework.security.core.Authenticationauthenticate(org.springframework.security.core.Authentication authentication) Authenticates the provided token.protected ApiKeyHasherprotected ApiKeyService<ApiKey>protected org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepositoryboolean
-
Constructor Details
-
ApiKeyClientAuthenticationProvider
public ApiKeyClientAuthenticationProvider(ApiKeyHasher apiKeyHasher, ApiKeyService<ApiKey> apiKeyService, org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository registeredClientRepository)
-
-
Method Details
-
authenticate
public org.springframework.security.core.Authentication authenticate(org.springframework.security.core.Authentication authentication) throws org.springframework.security.core.AuthenticationException Authenticates the provided token. If successful, returns a fully authenticatedApiKeyClientAuthenticationTokencontaining theRegisteredClientand whitelisted domains.- Specified by:
authenticatein interfaceorg.springframework.security.authentication.AuthenticationProvider- Parameters:
authentication- the authentication request object- Returns:
- a fully authenticated object including credentials
- Throws:
org.springframework.security.core.AuthenticationException- if authentication fails
-
supports
- Specified by:
supportsin interfaceorg.springframework.security.authentication.AuthenticationProvider
-
getApiKeyHasher
-
getApiKeyService
-
getRegisteredClientRepository
protected org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository getRegisteredClientRepository()
-