Class ApiKeyClientAuthenticationToken

java.lang.Object
org.springframework.security.authentication.AbstractAuthenticationToken
org.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken
com.broadleafcommerce.auth.authorization.security.apikey.ApiKeyClientAuthenticationToken
All Implemented Interfaces:
Serializable, Principal, org.springframework.security.core.Authentication, org.springframework.security.core.CredentialsContainer

public class ApiKeyClientAuthenticationToken extends org.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken
Represents the authentication state of an API key client during Phase 1 (Client Authentication).

It starts unauthenticated with just the raw key, and upon successful validation by the ApiKeyClientAuthenticationProvider, it becomes authenticated, carrying the RegisteredClient and any whitelisted domains associated with the key.

See Also:
  • Nested Class Summary

    Nested classes/interfaces inherited from class org.springframework.security.authentication.AbstractAuthenticationToken

    org.springframework.security.authentication.AbstractAuthenticationToken.AbstractAuthenticationBuilder<B extends org.springframework.security.authentication.AbstractAuthenticationToken.AbstractAuthenticationBuilder<B>>

    Nested classes/interfaces inherited from interface org.springframework.security.core.Authentication

    org.springframework.security.core.Authentication.Builder<B extends org.springframework.security.core.Authentication.Builder<B>>
  • Constructor Summary

    Constructors
    Constructor
    Description
    Creates an unauthenticated token containing only the raw API key.
    ApiKeyClientAuthenticationToken(org.springframework.security.oauth2.server.authorization.client.RegisteredClient registeredClient, String rawApiKey, List<String> whitelistedDomains)
    Creates an authenticated token containing the fully resolved RegisteredClient and the key's whitelisted domains.
  • Method Summary

    Modifier and Type
    Method
    Description
    void
     
     
    The raw, plaintext API key that was provided by the caller.
    The value of ApiKey.getWhitelistedDomains(), only set for authenticated tokens.
     

    Methods inherited from class org.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken

    getAdditionalParameters, getClientAuthenticationMethod, getPrincipal, getRegisteredClient

    Methods inherited from class org.springframework.security.authentication.AbstractAuthenticationToken

    equals, getAuthorities, getDetails, getName, hashCode, isAuthenticated, setAuthenticated, setDetails

    Methods inherited from class java.lang.Object

    clone, finalize, getClass, notify, notifyAll, wait, wait, wait

    Methods inherited from interface org.springframework.security.core.Authentication

    toBuilder

    Methods inherited from interface java.security.Principal

    implies
  • Constructor Details

    • ApiKeyClientAuthenticationToken

      public ApiKeyClientAuthenticationToken(@Nullable String rawApiKey)
      Creates an unauthenticated token containing only the raw API key.
      Parameters:
      rawApiKey - the unhashed API key provided by the request
    • ApiKeyClientAuthenticationToken

      public ApiKeyClientAuthenticationToken(org.springframework.security.oauth2.server.authorization.client.RegisteredClient registeredClient, @Nullable String rawApiKey, List<String> whitelistedDomains)
      Creates an authenticated token containing the fully resolved RegisteredClient and the key's whitelisted domains.
      Parameters:
      registeredClient - the authenticated client
      rawApiKey - the raw API key (optional)
      whitelistedDomains - the domains authorized to use this key, if applicable
  • Method Details

    • getCredentials

      @Nullable public Object getCredentials()
      Specified by:
      getCredentials in interface org.springframework.security.core.Authentication
      Overrides:
      getCredentials in class org.springframework.security.oauth2.server.authorization.authentication.OAuth2ClientAuthenticationToken
    • eraseCredentials

      public void eraseCredentials()
      Specified by:
      eraseCredentials in interface org.springframework.security.core.CredentialsContainer
      Overrides:
      eraseCredentials in class org.springframework.security.authentication.AbstractAuthenticationToken
    • toString

      public String toString()
      Specified by:
      toString in interface Principal
      Overrides:
      toString in class org.springframework.security.authentication.AbstractAuthenticationToken
    • getRawApiKey

      @Nullable public String getRawApiKey()
      The raw, plaintext API key that was provided by the caller.
    • getWhitelistedDomains

      public List<String> getWhitelistedDomains()
      The value of ApiKey.getWhitelistedDomains(), only set for authenticated tokens.