Class DefaultClientScopeApiKeyGrantAuthenticationConverter
java.lang.Object
com.broadleafcommerce.auth.authorization.security.apikey.DefaultClientScopeApiKeyGrantAuthenticationConverter
- All Implemented Interfaces:
org.springframework.security.web.authentication.AuthenticationConverter
public class DefaultClientScopeApiKeyGrantAuthenticationConverter
extends Object
implements org.springframework.security.web.authentication.AuthenticationConverter
Converts an HTTP request for the custom API Key grant type into an
ApiKeyGrantAuthenticationToken during Phase 2 of the flow (Grant Authentication & Token
Issuance). This is very similar to what
DefaultClientScopeClientCredentialsRequestConverter does for the client credentials flow.-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected org.springframework.security.oauth2.core.OAuth2AuthenticationExceptionPrepare anOAuth2AuthenticationExceptionto report an invalid client.org.springframework.security.core.Authenticationconvert(jakarta.servlet.http.HttpServletRequest request) Extracts the scope and grant_type from the request, constructing anApiKeyGrantAuthenticationTokenencapsulating the requested scopes and the authenticated client principal from Phase 1.protected org.springframework.security.oauth2.core.OAuth2AuthenticationExceptionPrepare anOAuth2AuthenticationExceptionto report an invalid scope.
-
Constructor Details
-
DefaultClientScopeApiKeyGrantAuthenticationConverter
public DefaultClientScopeApiKeyGrantAuthenticationConverter()
-
-
Method Details
-
convert
public org.springframework.security.core.Authentication convert(jakarta.servlet.http.HttpServletRequest request) Extracts the scope and grant_type from the request, constructing anApiKeyGrantAuthenticationTokenencapsulating the requested scopes and the authenticated client principal from Phase 1.- Specified by:
convertin interfaceorg.springframework.security.web.authentication.AuthenticationConverter- Parameters:
request- the HTTP servlet request- Returns:
- the authentication token for the grant, or null if the grant_type does not match
-
clientException
protected org.springframework.security.oauth2.core.OAuth2AuthenticationException clientException()Prepare anOAuth2AuthenticationExceptionto report an invalid client.- Returns:
- An
OAuth2AuthenticationExceptiondescribing the error.
-
scopeException
protected org.springframework.security.oauth2.core.OAuth2AuthenticationException scopeException()Prepare anOAuth2AuthenticationExceptionto report an invalid scope.- Returns:
- An
OAuth2AuthenticationExceptiondescribing the error.
-