Class PublicClientTokenRevocationAuthenticationConverter

java.lang.Object
com.broadleafcommerce.auth.authorization.security.tokenrevocation.PublicClientTokenRevocationAuthenticationConverter
All Implemented Interfaces:
org.springframework.security.web.authentication.AuthenticationConverter

public class PublicClientTokenRevocationAuthenticationConverter extends Object implements org.springframework.security.web.authentication.AuthenticationConverter
The token revocation endpoint in OAuth2TokenRevocationEndpointFilter relies on standard client authentication converters/providers before it allows a token revocation request to proceed. However, Broadleaf has replaced the default public client authentication converter with PublicRefreshPublicClientAuthenticationConverter and it only matches on specific requests. Rather than complicate those flows, this is a separate AuthenticationConverter that specifically engages on the token revocation endpoint path and only engages for clients that are known to be public clients. Then, PublicRefreshPublicClientAuthenticationProvider is expected to handle the actual authorization of this token.
Since:
AuthenticationServices 2.1.7, Release Train 2.1.7, AuthenticationServices 2.2.3, Release Train 2.2.3, AuthenticationServices 2.3.1, Release Train 2.3.1
  • Constructor Details

    • PublicClientTokenRevocationAuthenticationConverter

      public PublicClientTokenRevocationAuthenticationConverter(org.springframework.security.oauth2.server.authorization.settings.AuthorizationServerSettings authorizationServerSettings, AuthorizedClientService<AuthorizedClient> authorizedClientService)
  • Method Details

    • buildTokenRevocationRequestMatcher

      protected org.springframework.security.web.util.matcher.RequestMatcher buildTokenRevocationRequestMatcher(org.springframework.security.oauth2.server.authorization.settings.AuthorizationServerSettings authorizationServerSettings)
    • convert

      @Nullable public org.springframework.security.core.Authentication convert(jakarta.servlet.http.HttpServletRequest request)
      Specified by:
      convert in interface org.springframework.security.web.authentication.AuthenticationConverter
    • getTokenRevocationRequestMatcher

      protected org.springframework.security.web.util.matcher.RequestMatcher getTokenRevocationRequestMatcher()
      See Also:
    • getAuthorizedClientService

      protected AuthorizedClientService<AuthorizedClient> getAuthorizedClientService()