Class ApiKeyClientAuthenticationToken
java.lang.Object
org.springframework.security.authentication.AbstractAuthenticationToken
org.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken
com.broadleafcommerce.auth.authorization.security.apikey.ApiKeyClientAuthenticationToken
- All Implemented Interfaces:
Serializable,Principal,org.springframework.security.core.Authentication,org.springframework.security.core.CredentialsContainer
public class ApiKeyClientAuthenticationToken
extends org.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken
Represents the authentication state of an API key client during Phase 1 (Client Authentication).
It starts unauthenticated with just the raw key, and upon successful validation by the
ApiKeyClientAuthenticationProvider, it becomes authenticated, carrying the
RegisteredClient and any whitelisted domains associated with the key.
-
Nested Class Summary
Nested classes/interfaces inherited from class org.springframework.security.authentication.AbstractAuthenticationToken
org.springframework.security.authentication.AbstractAuthenticationToken.AbstractAuthenticationBuilder<B extends org.springframework.security.authentication.AbstractAuthenticationToken.AbstractAuthenticationBuilder<B>>Nested classes/interfaces inherited from interface org.springframework.security.core.Authentication
org.springframework.security.core.Authentication.Builder<B extends org.springframework.security.core.Authentication.Builder<B>> -
Constructor Summary
ConstructorsConstructorDescriptionApiKeyClientAuthenticationToken(String rawApiKey) Creates an unauthenticated token containing only the raw API key.ApiKeyClientAuthenticationToken(org.springframework.security.oauth2.server.authorization.client.RegisteredClient registeredClient, String rawApiKey, List<String> whitelistedDomains) Creates an authenticated token containing the fully resolvedRegisteredClientand the key's whitelisted domains. -
Method Summary
Modifier and TypeMethodDescriptionvoidThe raw, plaintext API key that was provided by the caller.The value ofApiKey.getWhitelistedDomains(), only set for authenticated tokens.toString()Methods inherited from class org.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken
getAdditionalParameters, getClientAuthenticationMethod, getPrincipal, getRegisteredClientMethods inherited from class org.springframework.security.authentication.AbstractAuthenticationToken
equals, getAuthorities, getDetails, getName, hashCode, isAuthenticated, setAuthenticated, setDetailsMethods inherited from class java.lang.Object
clone, finalize, getClass, notify, notifyAll, wait, wait, waitMethods inherited from interface org.springframework.security.core.Authentication
toBuilder
-
Constructor Details
-
ApiKeyClientAuthenticationToken
Creates an unauthenticated token containing only the raw API key.- Parameters:
rawApiKey- the unhashed API key provided by the request
-
ApiKeyClientAuthenticationToken
public ApiKeyClientAuthenticationToken(org.springframework.security.oauth2.server.authorization.client.RegisteredClient registeredClient, @Nullable String rawApiKey, List<String> whitelistedDomains) Creates an authenticated token containing the fully resolvedRegisteredClientand the key's whitelisted domains.- Parameters:
registeredClient- the authenticated clientrawApiKey- the raw API key (optional)whitelistedDomains- the domains authorized to use this key, if applicable
-
-
Method Details
-
getCredentials
- Specified by:
getCredentialsin interfaceorg.springframework.security.core.Authentication- Overrides:
getCredentialsin classorg.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken
-
eraseCredentials
public void eraseCredentials()- Specified by:
eraseCredentialsin interfaceorg.springframework.security.core.CredentialsContainer- Overrides:
eraseCredentialsin classorg.springframework.security.authentication.AbstractAuthenticationToken
-
toString
-
getRawApiKey
The raw, plaintext API key that was provided by the caller. -
getWhitelistedDomains
The value ofApiKey.getWhitelistedDomains(), only set for authenticated tokens.
-