Class ScopeNarrowingApiKeyGrantAuthenticationProvider

java.lang.Object
com.broadleafcommerce.auth.authorization.security.apikey.ScopeNarrowingApiKeyGrantAuthenticationProvider
All Implemented Interfaces:
org.springframework.security.authentication.AuthenticationProvider

public class ScopeNarrowingApiKeyGrantAuthenticationProvider extends Object implements org.springframework.security.authentication.AuthenticationProvider

Processes the ApiKeyGrantAuthenticationToken to issue an OAuth2 access token.

This provider runs in Phase 2 of the flow. It validates the requested scopes against the client's allowed scopes and constructs the final token response, ensuring that any domain claims (like whitelisted domains) are included in the token envelope.

This is very similar to what ScopeNarrowingOAuth2ClientCredentialsAuthenticationProvider does for the client credentials flow:

  • If there are no scopes on the request, the default scopes from the client are added to the request. Handled in DefaultClientScopeApiKeyGrantAuthenticationConverter.
  • The requested scopes are compared to all the scopes that the client is able to access. Any invalid scopes are removed from the request.
  • After the previous steps, if there are no scopes on the request, then throw an INVALID_SCOPE exception.

Notably, this flow does not handle refresh tokens, since API Keys are themselves long-lived and directly exchangeable for access tokens. It also does not handle OAuth2 DPoP in this initial implementation.

See Also:
  • Constructor Details

    • ScopeNarrowingApiKeyGrantAuthenticationProvider

      public ScopeNarrowingApiKeyGrantAuthenticationProvider(org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService authorizationService, org.springframework.security.oauth2.server.authorization.token.OAuth2TokenGenerator<? extends org.springframework.security.oauth2.core.OAuth2Token> tokenGenerator, SecurityService securityService, AuthorizedClientService<AuthorizedClient> clientService)
  • Method Details

    • authenticate

      public org.springframework.security.core.Authentication authenticate(org.springframework.security.core.Authentication authentication) throws org.springframework.security.core.AuthenticationException
      Authenticates the grant request, generates the access token, and returns an OAuth2AccessTokenAuthenticationToken containing the access token and any additional parameters.
      Specified by:
      authenticate in interface org.springframework.security.authentication.AuthenticationProvider
      Parameters:
      authentication - the authentication request object
      Returns:
      a fully authenticated object containing the issued access token
      Throws:
      org.springframework.security.core.AuthenticationException - if authentication fails
    • getClientAccessibleScopes

      protected Set<String> getClientAccessibleScopes(ApiKeyGrantAuthenticationToken requestToken, org.springframework.security.oauth2.server.authorization.client.RegisteredClient registeredClient)
      Validate and filter the requested scopes to the scopes that the authenticated client is able to access. If the client is not authorized for any scopes, throw an OAuth2AuthenticationException.
      Parameters:
      requestToken - The token representing the api key grant web request and its parameters.
      registeredClient - The RegisteredClient that is requesting authorization.
      Returns:
      The sub-set of requested scopes that the authenticated client is able to access.
    • buildAdditionalParameters

      protected Map<String,Object> buildAdditionalParameters(ApiKeyClientAuthenticationToken clientAuth)
      Builds the value passed to OAuth2AccessTokenAuthenticationToken.getAdditionalParameters(). Useful, since these values are automatically included in the envelope response created by TokenEndpointFilterPostProcessor.
      Parameters:
      clientAuth - the client authentication
      Returns:
      the additional parameters
    • supports

      public boolean supports(Class<?> authentication)
      Specified by:
      supports in interface org.springframework.security.authentication.AuthenticationProvider
    • getAuthorizationService

      protected org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService getAuthorizationService()
    • getTokenGenerator

      protected org.springframework.security.oauth2.server.authorization.token.OAuth2TokenGenerator<? extends org.springframework.security.oauth2.core.OAuth2Token> getTokenGenerator()
    • getSecurityService

      protected SecurityService getSecurityService()
    • getClientService

      protected AuthorizedClientService<AuthorizedClient> getClientService()