Class PublicClientTokenRevocationAuthenticationConverter
java.lang.Object
com.broadleafcommerce.auth.authorization.security.tokenrevocation.PublicClientTokenRevocationAuthenticationConverter
- All Implemented Interfaces:
org.springframework.security.web.authentication.AuthenticationConverter
public class PublicClientTokenRevocationAuthenticationConverter
extends Object
implements org.springframework.security.web.authentication.AuthenticationConverter
The token revocation endpoint in
OAuth2TokenRevocationEndpointFilter relies on standard
client authentication converters/providers before it allows a token revocation request to
proceed. However, Broadleaf has replaced the default public client authentication converter with
PublicRefreshPublicClientAuthenticationConverter and it only matches on specific
requests. Rather than complicate those flows, this is a separate AuthenticationConverter
that specifically engages on the token revocation endpoint path and only engages for clients that
are known to be public clients. Then, PublicRefreshPublicClientAuthenticationProvider is
expected to handle the actual authorization of this token.- Since:
- AuthenticationServices 2.1.7, Release Train 2.1.7, AuthenticationServices 2.2.3, Release Train 2.2.3, AuthenticationServices 2.3.1, Release Train 2.3.1
-
Constructor Summary
ConstructorsConstructorDescriptionPublicClientTokenRevocationAuthenticationConverter(org.springframework.security.oauth2.server.authorization.settings.AuthorizationServerSettings authorizationServerSettings, AuthorizedClientService<AuthorizedClient> authorizedClientService) -
Method Summary
Modifier and TypeMethodDescriptionprotected org.springframework.security.web.util.matcher.RequestMatcherbuildTokenRevocationRequestMatcher(org.springframework.security.oauth2.server.authorization.settings.AuthorizationServerSettings authorizationServerSettings) org.springframework.security.core.Authenticationconvert(jakarta.servlet.http.HttpServletRequest request) protected AuthorizedClientService<AuthorizedClient>protected org.springframework.security.web.util.matcher.RequestMatcher
-
Constructor Details
-
PublicClientTokenRevocationAuthenticationConverter
public PublicClientTokenRevocationAuthenticationConverter(org.springframework.security.oauth2.server.authorization.settings.AuthorizationServerSettings authorizationServerSettings, AuthorizedClientService<AuthorizedClient> authorizedClientService)
-
-
Method Details
-
buildTokenRevocationRequestMatcher
protected org.springframework.security.web.util.matcher.RequestMatcher buildTokenRevocationRequestMatcher(org.springframework.security.oauth2.server.authorization.settings.AuthorizationServerSettings authorizationServerSettings) -
convert
@Nullable public org.springframework.security.core.Authentication convert(jakarta.servlet.http.HttpServletRequest request) - Specified by:
convertin interfaceorg.springframework.security.web.authentication.AuthenticationConverter
-
getTokenRevocationRequestMatcher
protected org.springframework.security.web.util.matcher.RequestMatcher getTokenRevocationRequestMatcher() -
getAuthorizedClientService
-