Class DefaultClientScopeApiKeyGrantAuthenticationConverter

java.lang.Object
com.broadleafcommerce.auth.authorization.security.apikey.DefaultClientScopeApiKeyGrantAuthenticationConverter
All Implemented Interfaces:
org.springframework.security.web.authentication.AuthenticationConverter

public class DefaultClientScopeApiKeyGrantAuthenticationConverter extends Object implements org.springframework.security.web.authentication.AuthenticationConverter
Converts an HTTP request for the custom API Key grant type into an ApiKeyGrantAuthenticationToken during Phase 2 of the flow (Grant Authentication & Token Issuance). This is very similar to what DefaultClientScopeClientCredentialsRequestConverter does for the client credentials flow.
See Also:
  • Constructor Summary

    Constructors
  • Method Summary

    Modifier and Type
    Method
    Description
    protected org.springframework.security.oauth2.core.OAuth2AuthenticationException
    Prepare an OAuth2AuthenticationException to report an invalid client.
    org.springframework.security.core.Authentication
    convert(jakarta.servlet.http.HttpServletRequest request)
    Extracts the scope and grant_type from the request, constructing an ApiKeyGrantAuthenticationToken encapsulating the requested scopes and the authenticated client principal from Phase 1.
    protected org.springframework.security.oauth2.core.OAuth2AuthenticationException
    Prepare an OAuth2AuthenticationException to report an invalid scope.

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • DefaultClientScopeApiKeyGrantAuthenticationConverter

      public DefaultClientScopeApiKeyGrantAuthenticationConverter()
  • Method Details

    • convert

      public org.springframework.security.core.Authentication convert(jakarta.servlet.http.HttpServletRequest request)
      Extracts the scope and grant_type from the request, constructing an ApiKeyGrantAuthenticationToken encapsulating the requested scopes and the authenticated client principal from Phase 1.
      Specified by:
      convert in interface org.springframework.security.web.authentication.AuthenticationConverter
      Parameters:
      request - the HTTP servlet request
      Returns:
      the authentication token for the grant, or null if the grant_type does not match
    • clientException

      protected org.springframework.security.oauth2.core.OAuth2AuthenticationException clientException()
      Prepare an OAuth2AuthenticationException to report an invalid client.
      Returns:
      An OAuth2AuthenticationException describing the error.
    • scopeException

      protected org.springframework.security.oauth2.core.OAuth2AuthenticationException scopeException()
      Prepare an OAuth2AuthenticationException to report an invalid scope.
      Returns:
      An OAuth2AuthenticationException describing the error.