Class ScopeNarrowingApiKeyGrantAuthenticationProvider
java.lang.Object
com.broadleafcommerce.auth.authorization.security.apikey.ScopeNarrowingApiKeyGrantAuthenticationProvider
- All Implemented Interfaces:
org.springframework.security.authentication.AuthenticationProvider
public class ScopeNarrowingApiKeyGrantAuthenticationProvider
extends Object
implements org.springframework.security.authentication.AuthenticationProvider
Processes the ApiKeyGrantAuthenticationToken to issue an OAuth2 access token.
This provider runs in Phase 2 of the flow. It validates the requested scopes against the client's allowed scopes and constructs the final token response, ensuring that any domain claims (like whitelisted domains) are included in the token envelope.
This is very similar to what ScopeNarrowingOAuth2ClientCredentialsAuthenticationProvider
does for the client credentials flow:
- If there are no scopes on the request, the default scopes from the client are added to the
request. Handled in
DefaultClientScopeApiKeyGrantAuthenticationConverter. - The requested scopes are compared to all the scopes that the client is able to access. Any invalid scopes are removed from the request.
- After the previous steps, if there are no scopes on the request, then throw an
INVALID_SCOPEexception.
Notably, this flow does not handle refresh tokens, since API Keys are themselves long-lived and directly exchangeable for access tokens. It also does not handle OAuth2 DPoP in this initial implementation.
-
Constructor Summary
ConstructorsConstructorDescriptionScopeNarrowingApiKeyGrantAuthenticationProvider(org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService authorizationService, org.springframework.security.oauth2.server.authorization.token.OAuth2TokenGenerator<? extends org.springframework.security.oauth2.core.OAuth2Token> tokenGenerator, SecurityService securityService, AuthorizedClientService<AuthorizedClient> clientService) -
Method Summary
Modifier and TypeMethodDescriptionorg.springframework.security.core.Authenticationauthenticate(org.springframework.security.core.Authentication authentication) Authenticates the grant request, generates the access token, and returns anOAuth2AccessTokenAuthenticationTokencontaining the access token and any additional parameters.Builds the value passed toOAuth2AccessTokenAuthenticationToken.getAdditionalParameters().protected org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationServicegetClientAccessibleScopes(ApiKeyGrantAuthenticationToken requestToken, org.springframework.security.oauth2.server.authorization.client.RegisteredClient registeredClient) Validate and filter the requested scopes to the scopes that the authenticated client is able to access.protected AuthorizedClientService<AuthorizedClient>protected SecurityServiceprotected org.springframework.security.oauth2.server.authorization.token.OAuth2TokenGenerator<? extends org.springframework.security.oauth2.core.OAuth2Token>boolean
-
Constructor Details
-
ScopeNarrowingApiKeyGrantAuthenticationProvider
public ScopeNarrowingApiKeyGrantAuthenticationProvider(org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService authorizationService, org.springframework.security.oauth2.server.authorization.token.OAuth2TokenGenerator<? extends org.springframework.security.oauth2.core.OAuth2Token> tokenGenerator, SecurityService securityService, AuthorizedClientService<AuthorizedClient> clientService)
-
-
Method Details
-
authenticate
public org.springframework.security.core.Authentication authenticate(org.springframework.security.core.Authentication authentication) throws org.springframework.security.core.AuthenticationException Authenticates the grant request, generates the access token, and returns anOAuth2AccessTokenAuthenticationTokencontaining the access token and any additional parameters.- Specified by:
authenticatein interfaceorg.springframework.security.authentication.AuthenticationProvider- Parameters:
authentication- the authentication request object- Returns:
- a fully authenticated object containing the issued access token
- Throws:
org.springframework.security.core.AuthenticationException- if authentication fails
-
getClientAccessibleScopes
protected Set<String> getClientAccessibleScopes(ApiKeyGrantAuthenticationToken requestToken, org.springframework.security.oauth2.server.authorization.client.RegisteredClient registeredClient) Validate and filter the requested scopes to the scopes that the authenticated client is able to access. If the client is not authorized for any scopes, throw anOAuth2AuthenticationException.- Parameters:
requestToken- The token representing the api key grant web request and its parameters.registeredClient- TheRegisteredClientthat is requesting authorization.- Returns:
- The sub-set of requested scopes that the authenticated client is able to access.
-
buildAdditionalParameters
Builds the value passed toOAuth2AccessTokenAuthenticationToken.getAdditionalParameters(). Useful, since these values are automatically included in the envelope response created byTokenEndpointFilterPostProcessor.- Parameters:
clientAuth- the client authentication- Returns:
- the additional parameters
-
supports
- Specified by:
supportsin interfaceorg.springframework.security.authentication.AuthenticationProvider
-
getAuthorizationService
protected org.springframework.security.oauth2.server.authorization.OAuth2AuthorizationService getAuthorizationService() -
getTokenGenerator
protected org.springframework.security.oauth2.server.authorization.token.OAuth2TokenGenerator<? extends org.springframework.security.oauth2.core.OAuth2Token> getTokenGenerator() -
getSecurityService
-
getClientService
-