Record Class OidcPrincipal

java.lang.Object
java.lang.Record
dev.relism.flash.ext.security.oidc.OidcPrincipal
Record Components:
provider - the OidcProvider.id()
claims - verified: the access token's for a bearer caller, the ID token's for a session
refreshToken - null for a bearer caller
All Implemented Interfaces:
dev.relism.flash.ext.security.Principal

public record OidcPrincipal(String provider, String name, Map<String,Object> claims, String accessToken, String refreshToken, String logoutUrl) extends Record implements dev.relism.flash.ext.security.Principal
A caller an OpenID Provider vouched for: through a bearer access token, or by signing in. Its name() is the sub claim — unique per issuer(), never across issuers.
  • Constructor Details

    • OidcPrincipal

      public OidcPrincipal(String provider, String name, Map<String,Object> claims, String accessToken, String refreshToken, String logoutUrl)
      Creates an instance of a OidcPrincipal record class.
      Parameters:
      provider - the value for the provider record component
      name - the value for the name record component
      claims - the value for the claims record component
      accessToken - the value for the accessToken record component
      refreshToken - the value for the refreshToken record component
      logoutUrl - the value for the logoutUrl record component
  • Method Details

    • issuer

      public String issuer()
    • email

      public String email()
    • claim

      public Object claim(String name)
    • hasScope

      public boolean hasScope(String scope)
      From scope (space-delimited) or scp; a token that grants none grants none.
      Specified by:
      hasScope in interface dev.relism.flash.ext.security.Principal
    • hasAudience

      public boolean hasAudience(String audience)
      Specified by:
      hasAudience in interface dev.relism.flash.ext.security.Principal
    • toString

      public final String toString()
      Returns a string representation of this record class. The representation contains the name of the class, followed by the name and value of each of the record components.
      Specified by:
      toString in class Record
      Returns:
      a string representation of this object
    • hashCode

      public final int hashCode()
      Returns a hash code value for this object. The value is derived from the hash code of each of the record components.
      Specified by:
      hashCode in class Record
      Returns:
      a hash code value for this object
    • equals

      public final boolean equals(Object o)
      Indicates whether some other object is "equal to" this one. The objects are equal if the other object is of the same class and if all the record components are equal. All components in this record class are compared with Objects::equals(Object,Object).
      Specified by:
      equals in class Record
      Parameters:
      o - the object with which to compare
      Returns:
      true if this object is the same as the o argument; false otherwise.
    • provider

      public String provider()
      Returns the value of the provider record component.
      Returns:
      the value of the provider record component
    • name

      public String name()
      Returns the value of the name record component.
      Specified by:
      name in interface dev.relism.flash.ext.security.Principal
      Returns:
      the value of the name record component
    • claims

      public Map<String,Object> claims()
      Returns the value of the claims record component.
      Returns:
      the value of the claims record component
    • accessToken

      public String accessToken()
      Returns the value of the accessToken record component.
      Returns:
      the value of the accessToken record component
    • refreshToken

      public String refreshToken()
      Returns the value of the refreshToken record component.
      Returns:
      the value of the refreshToken record component
    • logoutUrl

      public String logoutUrl()
      Returns the value of the logoutUrl record component.
      Specified by:
      logoutUrl in interface dev.relism.flash.ext.security.Principal
      Returns:
      the value of the logoutUrl record component