Author: buildbot
Date: Thu May 26 13:47:42 2016
New Revision: 989187

Log:
Production update by buildbot for cxf

Modified:
    websites/production/cxf/content/cache/docs.pageCache
    websites/production/cxf/content/docs/jax-rs-oauth2.html

Modified: websites/production/cxf/content/cache/docs.pageCache
==============================================================================
Binary files - no diff available.

Modified: websites/production/cxf/content/docs/jax-rs-oauth2.html
==============================================================================
--- websites/production/cxf/content/docs/jax-rs-oauth2.html (original)
+++ websites/production/cxf/content/docs/jax-rs-oauth2.html Thu May 26 13:47:42 
2016
@@ -118,11 +118,11 @@ Apache CXF -- JAX-RS OAuth2
            <!-- Content -->
            <div class="wiki-content">
 <div id="ConfluenceContent"><h1 id="JAX-RSOAuth2-JAX-RS:OAuth2">JAX-RS: 
OAuth2</h1><p><style type="text/css">/*<![CDATA[*/
-div.rbtoc1464266818744 {padding: 0px;}
-div.rbtoc1464266818744 ul {list-style: disc;margin-left: 0px;}
-div.rbtoc1464266818744 li {margin-left: 0px;padding-left: 0px;}
+div.rbtoc1464270417246 {padding: 0px;}
+div.rbtoc1464270417246 ul {list-style: disc;margin-left: 0px;}
+div.rbtoc1464270417246 li {margin-left: 0px;padding-left: 0px;}
 
-/*]]>*/</style></p><div class="toc-macro rbtoc1464266818744">
+/*]]>*/</style></p><div class="toc-macro rbtoc1464270417246">
 <ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-JAX-RS:OAuth2">JAX-RS: OAuth2</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-Introduction">Introduction</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-Mavendependencies">Maven dependencies</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-ClientRegistration">Client 
Registration</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-DevelopingOAuth2Servers">Developing OAuth2 Servers</a>
 <ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-AuthorizationService">Authorization Service</a>
 <ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-HowtocreateAuthorizationView">How to create Authorization 
View</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-EndUserNameinAuthorizationForm">EndUser Name in 
Authorization Form</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-PublicClients(Devices)">Public Clients (Devices)</a>
@@ -130,14 +130,12 @@ div.rbtoc1464266818744 li {margin-left:
 </li></ul>
 </li><li><a shape="rect" 
href="#JAX-RSOAuth2-AccessTokenService">AccessTokenService</a>
 <ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-AccessTokenTypes">Access Token Types</a>
-<ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-Bearer">Bearer</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-HAWK">HAWK</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-MAC">MAC</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-EncryptedandSignedTokens">Encrypted and Signed Tokens</a>
-<ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-EncryptedandSignedJWTTokens">Encrypted and Signed JWT 
Tokens</a></li></ul>
-</li><li><a shape="rect" href="#JAX-RSOAuth2-Customtokens">Custom 
tokens</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-SimpleTokensandAudience">Simple Tokens and 
Audience</a></li></ul>
+<ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-Bearer">Bearer</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-HAWK">HAWK</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-MAC">MAC</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-EncryptedTokens">Encrypted Tokens</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-JWTTokens">JWT Tokens</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-Customtokens">Custom tokens</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-SimpleTokensandAudience">Simple Tokens and 
Audience</a></li></ul>
 </li><li><a shape="rect" 
href="#JAX-RSOAuth2-OAuthJSONProvider">OAuthJSONProvider</a></li></ul>
 </li><li><a shape="rect" 
href="#JAX-RSOAuth2-AccessTokenValidationService">Access Token Validation 
Service</a>
 <ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-AccessTokenValidatorService">AccessTokenValidatorService</a></li><li><a
 shape="rect" 
href="#JAX-RSOAuth2-TokenIntrospectionService">TokenIntrospectionService</a></li></ul>
 </li><li><a shape="rect" 
href="#JAX-RSOAuth2-TokenRevocationService">TokenRevocationService</a></li><li><a
 shape="rect" href="#JAX-RSOAuth2-SupportedGrants">Supported Grants</a>
-<ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-AuthorizationCode">Authorization Code</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-Implicit">Implicit</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-ClientCredentials">Client Credentials</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-ResourceOwnerPasswordCredentials">Resource 
Owner Password Credentials</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-RefreshToken">Refresh Token</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-Assertions">Assertions</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-CustomGrants">Custom Grants</a></li></ul>
+<ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-AuthorizationCode">Authorization Code</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-Implicit">Implicit</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-ClientCredentials">Client Credentials</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-ResourceOwnerPasswordCredentials">Resource 
Owner Password Credentials</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-RefreshToken">Refresh Token</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-SAMLandJWTAssertions">SAML and JWT 
Assertions</a></li><li><a shape="rect" href="#JAX-RSOAuth2-CustomGrants">Custom 
Grants</a></li></ul>
 </li><li><a shape="rect" 
href="#JAX-RSOAuth2-RedirectionFlowFilters">Redirection Flow 
Filters</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-AccessTokenResponseFilters">AccessTokenResponse 
Filters</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-PreAuthorizedaccesstokens">PreAuthorized access 
tokens</a></li><li><a shape="rect" 
href="#JAX-RSOAuth2-Pre-registeredscopes">Pre-registered scopes</a></li><li><a 
shape="rect" href="#JAX-RSOAuth2-WritingOAuthDataProvider">Writing 
OAuthDataProvider</a>
 <ul class="toc-indentation"><li><a shape="rect" 
href="#JAX-RSOAuth2-DefaultProviders">Default Providers</a></li></ul>
 </li><li><a shape="rect" href="#JAX-RSOAuth2-OAuthServerJAX-RSendpoints">OAuth 
Server JAX-RS endpoints</a></li></ul>
@@ -348,7 +346,7 @@ Authorization: MAC id="5b5c8e677413277c4
                    mac="W7bdMZbv9UWOTadASIQHagZyirA="
                    ts="12345678" 
 </pre>
-</div></div><p>where 'ts' attribute is used to pass a timestamp value.</p><h4 
id="JAX-RSOAuth2-EncryptedandSignedTokens">Encrypted and Signed 
Tokens</h4><p>Typically, the tokens are persisted in the storage. The 
alternative approach is to completely encrypt the token state and return the 
encrypted representation back to a client: the processing time to do with the 
encryption and decryption might increase but the server wins on avoiding the DB 
/ storage lookups.&#160;&#160; &#160;</p><p>CXF 3.0.0-milestone2 introduces the 
utility support for encrypting the state of BearerAccessToken and 
RefreshToken.</p><p>The tokens can be encrypted and decrypted with symmetric 
(secret) keys or certificates (public and private keys) and the combination of 
certificates and secret keys.</p><p><a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/utils/crypto/ModelEncryptionSupport.java";
 r
 el="nofollow">ModelEncryptionSupport</a> can be used to encrypt the tokens 
using the custom serialization format.</p><p>Note that ServerAuthorizationGrant 
and Client can also be encrypted.</p><p>&#160;</p><p>The simplest strategy is 
to encrypt and decrypt the tokens with the symmetric/secret keys. Every new 
token can be encrypted with a unique secret key or all of them can be encrypted 
with a single secret key. The utilities provide few methods for creating secret 
keys with the default and advanced properties, in addition there are many 
examples around on how to create the keys with the specific 
properties.</p><p>For example, see 
org.apache.cxf.rs.security.oauth2.grants.code.DefaultEncryptingCodeDataProvider 
and&#160;org.apache.cxf.rs.security.oauth2.provider.DefaultEncryptingOAuthDataProvider
 which are shipped starting from CXF 3.0.2.</p><p>Here is a typical code 
demonstrating how the encryption/decryption works:</p><p>&#160;</p><div 
class="code panel pdl" style="border-width: 1px;
 "><div class="codeContent panelContent pdl">
+</div></div><p>where 'ts' attribute is used to pass a timestamp value.</p><h4 
id="JAX-RSOAuth2-EncryptedTokens">Encrypted Tokens</h4><p>Typically, the tokens 
are persisted in the storage. The alternative approach is to completely encrypt 
the token state and return the encrypted representation back to a client: the 
processing time to do with the encryption and decryption might increase but the 
server wins on avoiding the DB / storage lookups.&#160;&#160; &#160;</p><p>CXF 
3.0.0-milestone2 introduces the utility support for encrypting the state of 
BearerAccessToken and RefreshToken.</p><p>The tokens can be encrypted and 
decrypted with symmetric (secret) keys or certificates (public and private 
keys) and the combination of certificates and secret keys.</p><p><a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/utils/crypto/ModelEncryptionSupport.java";
 rel="nofollow">ModelE
 ncryptionSupport</a> can be used to encrypt the tokens using the custom 
serialization format.</p><p>Note that ServerAuthorizationGrant and Client can 
also be encrypted.</p><p>&#160;</p><p>The simplest strategy is to encrypt and 
decrypt the tokens with the symmetric/secret keys. Every new token can be 
encrypted with a unique secret key or all of them can be encrypted with a 
single secret key. The utilities provide few methods for creating secret keys 
with the default and advanced properties, in addition there are many examples 
around on how to create the keys with the specific properties.</p><p>For 
example, see 
org.apache.cxf.rs.security.oauth2.grants.code.DefaultEncryptingCodeDataProvider 
and&#160;org.apache.cxf.rs.security.oauth2.provider.DefaultEncryptingOAuthDataProvider
 which are shipped starting from CXF 3.0.2.</p><p>Here is a typical code 
demonstrating how the encryption/decryption works:</p><p>&#160;</p><div 
class="code panel pdl" style="border-width: 1px;"><div class="codeCo
 ntent panelContent pdl">
 <pre class="brush: java; gutter: false; theme: Default" 
style="font-size:12px;">SecretKey key = CryptoUtils.getSecretKey();
 
 // create a new token, encrypt its state and return
@@ -364,15 +362,7 @@ return token;
 // decrypt a token given a token key
 
 ModelEncryptionSupport.decryptAccessToken(this, encryptedToken, key);</pre>
-</div></div><pre>&#160;</pre><h5 
id="JAX-RSOAuth2-EncryptedandSignedJWTTokens">Encrypted and Signed JWT 
Tokens</h5><p>JWT Token can be JWE-encrypted and the encrypted string passed to 
ServerAccessToken as access token id parameter.</p><p>See <a shape="rect" 
href="http://cxf.apache.org/docs/jax-rs-jose.html";>JAX-RS JOSE</a> wiki page 
for more information on how to sign and encrypt JSON Web Tokens.</p><p><a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/tokens/jwt/JwtAccessTokenUtils.java";
 rel="nofollow">JwtAccessTokenUtils </a>provides utility method for encrypting 
and decrypting an access token represented as JWT.</p><p>Note more support for 
JWT access tokens is on the way.</p><h4 id="JAX-RSOAuth2-Customtokens">Custom 
tokens</h4><p>If needed, users can use their own custom token types, with the 
only restriction that the custom token type implementations have to exte
 nd org.apache.cxf.rs.security.oauth2.common.ServerAccessToken.</p><h4 
id="JAX-RSOAuth2-SimpleTokensandAudience">Simple Tokens and 
Audience</h4><p>Starting from CXF 2.7.7 an <a shape="rect" 
class="external-link" 
href="http://tools.ietf.org/html/draft-tschofenig-oauth-audience-00"; 
rel="nofollow">audience</a> parameter is supported during the client token 
requests.</p><h3 
id="JAX-RSOAuth2-OAuthJSONProvider">OAuthJSONProvider</h3><p>org.apache.cxf.rs.security.oauth2.provider.OAuthJSONProvider
 is a JAX-RS MessageBodyWriter which supports returning ClientAccessToken and 
OAuthError representations to the client in a JSON format required by OAuth2 
spec. It is also a JAX-RS MessageBodyReader that is used by client 
OAuthClientUtils (see below) to read the responses from 
AccessTokenService.</p><p>Register it as a provider with a JAXRS 
AccessTokenService endpoint.</p><p>Alternatively, if you prefer, a custom 
MessageBodyWriter implementation can be registered instead.</p><h2 
id="JAX-RSOAuth2-Acc
 essTokenValidationService">Access Token Validation Service</h2><h3 
id="JAX-RSOAuth2-AccessTokenValidatorService">AccessTokenValidatorService</h3><p>The
 <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/AccessTokenValidatorService.java";
 rel="nofollow">AccessTokenValidatorService</a> is a CXF specific OAuth2 
service for accepting the remote access token validation requests. 
OAuthRequestFilter needs to be injected with <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/AccessTokenValidatorClient.java";
 rel="nofollow">AccessTokenValidatorClient</a> which will ask 
AccessTokenValidatorService to return the information relevant to the current 
access token, before setting up a security context.</p><h3 
id="JAX-RSOAuth2-TokenIntrospectionServic
 e">TokenIntrospectionService</h3><p>The <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/TokenIntrospectionService.java";
 rel="nofollow">TokenIntrospectionService</a> is a standard OAuth2 service for 
accepting the remote access token introspection requests. See <a shape="rect" 
class="external-link" href="https://tools.ietf.org/html/rfc7662"; 
rel="nofollow">RFC 7662</a>. OAuthRequestFilter needs to be injected with <a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/AccessTokenIntrospectionClient.java";
 rel="nofollow">AccessTokenIntrospectionClient.</a></p><h2 
id="JAX-RSOAuth2-TokenRevocationService">TokenRevocationService</h2><p><a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-pa
 
rent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/TokenRevocationService.java"
 rel="nofollow">TokenRevocationService</a> is a simple OAuth2 service 
supporting the clients wishing to revoke the access or refresh tokens they own 
themselves, please see <a shape="rect" class="external-link" 
href="http://tools.ietf.org/html/draft-ietf-oauth-revocation-09"; 
rel="nofollow">OAuth2 Token Revocation Draft</a> for more 
information.</p><p>TokenRevocationService and AccessTokenService share the same 
code which enforces that the clients have been correctly 
authenticated.</p><p>Note, OAuthDataProvider implementations processing a 
revocation request should simply ignore the invalid tokens as recommended by 
the specification which will let TokenRevocationService return HTTP 200 which 
is done to minimize a possible attack surface (specifically for bad clients not 
to see if their requests failed or succeeded) and throw the exceptions only if 
the token revocation feature is not curren
 tly supported.</p><h2 id="JAX-RSOAuth2-SupportedGrants">Supported 
Grants</h2><p>The following subsections briefly describe how the well-known 
grant types can be supported on the server side. Please also check the "Client 
Side Support" section on how to use the related <a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/AccessTokenGrant.java";>AccessTokenGrant</a>
 implementations to request the access tokens.</p><h3 
id="JAX-RSOAuth2-AuthorizationCode">Authorization Code</h3><p>As described 
above, <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/AuthorizationCodeGrantService.java";>AuthorizationCodeGrantService</a>
 service and <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent
 
/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AuthorizationCodeDataProvider.java">AuthorizationCodeDataProvider</a>
 data provider can support a redirection-based Authorization Code 
flow.</p><p>The code that the client receives in the end of the redirection 
process will need to be exchanged for a new access token with 
AccessTokenService. CXF-based clients can use a helper <a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AuthorizationCodeGrant.java";>AuthorizationCodeGrant</a>
 bean to request a new access token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-Implicit">Implicit</h3><p>Implicit grant is supported the same 
way Authorization Code grant is except that the response to the client running 
within a web browser is formatted differently, using URI fragments.</p><p><a 
shape="rect" class="external-link" href="http://svn.apache.org/
 
repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/ImplicitGrantService.java">ImplicitGrantService</a>
 service and <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AuthorizationCodeDataProvider.java";>AuthorizationCodeDataProvider</a>
 data provider can support a redirection-based Implicit flow.</p><p>Note the 
only difference is the use of ImplicitGrantService instead of 
AuthorizationCodeGrantService.</p><p>Also note that when an Implicit grant 
client (running within a browser) replaces the code grant for a new access 
token and tries to access the end user's resource, Cross Origin Resource 
Sharing (CORS) support will most likely need to be enabled on the end user's 
resource server.<br clear="none"> The simplest approach is to register a CXF <a 
shape="rect" href="http://cxf.apache.org/docs/jax-rs
 -cors.html">CORS filter</a>, right before OAuth2 filter (see on it 
below).</p><p>Starting from CXF 2.7.5 it is possible to request 
ImplicitGrantService to return a registered Client id to the browser-hosted 
client. This is recommended so that the client can verify that the token is 
meant to be delivered to this client.</p><h3 
id="JAX-RSOAuth2-ClientCredentials">Client Credentials</h3><p>Register <a 
shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/clientcred/ClientCredentialsGrantHandler.java";>ClientCredentialsGrantHandler</a>
 handler with AccessTokenService for this grant be supported.</p><p>CXF-based 
clients can use a helper <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/clientcred/ClientCredentialsGrant.java";>ClientCredentialsGrant<
 /a> bean to request a new access token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-ResourceOwnerPasswordCredentials">Resource Owner Password 
Credentials</h3><p>Register <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/owner/ResourceOwnerGrantHandler.java";>ResourceOwnerGrantHandler</a>
 handler with AccessTokenService for this grant be supported.</p><p>CXF-based 
clients can use a helper <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/owner/ResourceOwnerGrant.java";>ResourceOwnerGrant</a>
 bean to request a new access token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-RefreshToken">Refresh Token</h3><p>The client can issue a 
refresh token grant if the current access token it owns has expired or been 
revoked and the refresh token was
  issued alongside with the access token which is now invalid and get the new, 
'refreshed' access token. This can allow the client to avoid seeking a new 
authorization approval from the end user.</p><p>Register <a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/refresh/RefreshTokenGrantHandler.java";>RefreshTokenGrantHandler</a>
 handler with AccessTokenService for this grant be supported. Note this grant 
handler is only useful for refreshing the existing access token, so one or more 
of the other grant handlers (Authorization Code, Implicit, etc) will also have 
to be registered with AccessTokenService.</p><p>CXF-based clients can use a 
helper <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/refresh/RefreshTokenGrant.java";>RefreshTokenGran
 t</a> bean to request a new access token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-Assertions">Assertions</h3><p>SAML2 Bearer and JWT assertions 
can be used as token grants.</p><p>Please see <a shape="rect" 
href="jaxrs-oauth2-assertions.html">JAXRS OAuth2 Assertions</a> section for 
more information.</p><h3 id="JAX-RSOAuth2-CustomGrants">Custom Grants</h3><p>If 
you need to customize the way the well-known grant requests are handled then 
consider extending one of the grant handlers listed in the previous 
sub-sections.</p><p>Alternatively create a custom <a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AccessTokenGrantHandler.java";>AccessTokenGrantHandler</a>
 and register it with AccessTokenService. Additionally, consider providing a 
related <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/
 
oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/AccessTokenGrant.java">AccessTokenGrant</a>
 implementation for making it easy for the client code to request a new access 
token with this custom grant.</p><h2 
id="JAX-RSOAuth2-RedirectionFlowFilters">Redirection Flow Filters</h2><p><a 
shape="rect" class="external-link" 
href="https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=blob;f=rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AuthorizationCodeRequestFilter.java;h=646861c1ea3f9effad74bd234c0576f638009932;hb=HEAD";>AuthorizationCodeRequestFilter</a>
 implementations can be registered with AuthorizationCodeService in order to 
pre-process code requests. For example, <a shape="rect" class="external-link" 
href="https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=blob;f=rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/JwtRequestCodeFilter.java;h=a318c2c405c813e9c07f1b22c4b2afbfccd6101e;hb
 =HEAD">JwtRequestCodeFilter</a> can be used to process JWS-signed or 
JWE-encrypted code requests.</p><p><a shape="rect" class="external-link" 
href="https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=blob;f=rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AuthorizationCodeResponseFilter.java;h=f363a461ed21be5a2b87584271bcce2933402ab6;hb=HEAD";>AuthorizationCodeResponseFilter</a>
 implementations can be registered with AuthorizationCodeService in order to 
post-process code responses.</p><h2 
id="JAX-RSOAuth2-AccessTokenResponseFilters">AccessTokenResponse 
Filters</h2><p><a shape="rect" class="external-link" 
href="https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=blob;f=rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AccessTokenResponseFilter.java;h=f6058e6d2d2aa54543514cbfe2d0d9951a30db68;hb=HEAD";>AccessTokenResponseFilter</a>
 implementations can be registered with AccessTokenService in order to pos
 t-process access token responses. For example,&#160; OIDC id_token can be 
added to a response with a <a shape="rect" class="external-link" 
href="https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=blob;f=rt/rs/security/sso/oidc/src/main/java/org/apache/cxf/rs/security/oidc/idp/UserInfoCodeResponseFilter.java;h=42bf9ff41004a32903e6839495d9edde5963c2e3;hb=HEAD";>filter</a>.
 Filters can also calculate an access token response signature, etc.</p><h2 
id="JAX-RSOAuth2-PreAuthorizedaccesstokens">PreAuthorized access 
tokens</h2><p>When working with the flows which require the end users/resource 
owners explicitly authorizing clients (for example, as in the case of 
redirection-based flows), using pre-authorized access tokens is one option to 
minimize the need for the end-user intervention. <br clear="none"> 
OAuthDataProvider is always checked first if the pre-authorized access token 
for a given Client exists and if yes then it will be returned immediately, 
without starting the authorization pr
 ocess involving the end user (as required by some flows).</p><p>Consider 
providing a user interface which will let the end users/resource owners to 
pre-authorize specific clients early. Note, a CXF service for supporting the 
users pre-authorizing the clients or revoking the tokens for some of the 
clients may be introduced in the future.</p><p>Also note that using a refresh 
token grant may further help with minimizing the end user involvement, in cases 
when the current access token has expired.</p><h2 
id="JAX-RSOAuth2-Pre-registeredscopes">Pre-registered scopes</h2><p>Clients can 
register custom scopes they will be expected to use and then avoid specifying 
the scopes when requesting the code grants or access tokens.<br clear="none"> 
Alternatively it makes it easier to support so called wild-card scopes. For 
example, a client pre-registers a scope "update" and actually uses an 
"update-7" scope: Redirection-based services and access token grants can be 
configured to do a partial scope 
 match, in this case, validate that "update-7" starts from "update"</p><h2 
id="JAX-RSOAuth2-WritingOAuthDataProvider">Writing 
OAuthDataProvider</h2><p>Using CXF OAuth service implementations will help a 
lot with setting up an OAuth server. As you can see from the above sections, 
these services rely on a custom <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/OAuthDataProvider.java";>OAuthDataProvider</a>
 implementation.</p><p>The main task of OAuthDataProvider is to persist and 
generate access tokens. Additionally, as noted above, 
AuthorizationCodeDataProvider needs to persist and remove the code grant 
registrations. The way it's done is really application-specific. Consider 
starting with a basic memory based implementation and then move on to keeping 
the data in some DB.</p><p>Note that OAuthDataProvider supports retrieving <a 
shape="rect" class="external-l
 ink" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/Client.java";>Client</a>
 instances but it has no methods for creating or removing Clients. The reason 
for it is that the process of registering third-party clients is very specific 
to a particular OAuth2 application, so CXF does not offer a registration 
support service and hence OAuthDataProvider has no Client create/update 
methods. You will likely need to do something like this:</p><div class="code 
panel pdl" style="border-width: 1px;"><div class="codeContent panelContent pdl">
-<pre class="brush: java; gutter: false; theme: Default" 
style="font-size:12px;">public class CustomOAuthProvider implements 
OAuthDataProvider {
-   public Client registerClient(String applicationName, String applicationURI, 
...) {}
-   public void removeClient(String cliendId) {}
-   // etc
-   // OAuthDataProvider methods
-}
-</pre>
-</div></div><p>CustomOAuthProvider will also remove all tokens associated with 
a given Client in removeClient(String cliendId).</p><p>Finally 
OAuthDataProvider may need to convert opaque scope values such as 
"readCalendar" into a list of <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/OAuthPermission.java";>OAuthPermission</a>s.
 AuthorizationCodeGrantService and OAuth2 security filters will depend on it 
(assuming scopes are used in the first place). In the former case 
AuthorizationCodeGrantService will use this list to populate <a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/OAuthAuthorizationData.java";>OAuthAuthorizationData</a>
 - the reason this bean only sees <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos
 
/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/Permission.java">Permission</a>s
 is that some of the properties OAuthPermission keeps are of no interest to 
OAuthAuthorizationData handlers.</p><h3 
id="JAX-RSOAuth2-DefaultProviders">Default Providers</h3><p>CXF 3.1.7 ships 
JPA2 (<a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/JPAOAuthDataProvider.java";
 rel="nofollow">JPAOAuthDataProvider</a> and <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/JPACodeDataProvider.java";
 rel="nofollow">JPACodeDataProvider</a>), Ehcache (<a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/sec
 urity/oauth2/provider/DefaultEHCacheOAuthDataProvider.java" 
rel="nofollow">DefaultEHCacheOAuthDataProvider</a> and <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/DefaultEHCacheCodeDataProvider.java";
 rel="nofollow">DefaultEHCacheCodeDataProvider</a>) and JCache (<a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/JCacheOAuthDataProvider.java";
 rel="nofollow">JCacheOAuthDataProvider</a> and <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/JCacheCodeDataProvider.java";
 rel="nofollow">JCacheCodeDataProvider</a>) provider implementations which take 
care of all the persistence tasks: saving or removing reg
 istered clients, tokens and code grants. These providers can be easily 
customized.</p><p>Custom implementations can also extend&#160; <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AbstractOAuthDataProvider.java";
 rel="nofollow">AbstractOAuthDataProvider</a> or <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AbstractCodeDataProvider.java";
 rel="nofollow">AbstractCodeDataProvider</a>&#160; and only implement their 
abstract persistence related methods or further customize some of their 
code.</p><h2 id="JAX-RSOAuth2-OAuthServerJAX-RSendpoints">OAuth Server JAX-RS 
endpoints</h2><p>With CXF offering OAuth service implementations and a custom 
OAuthDataProvider provider in place, it is time to deploy the OAuth2 server. 
<br clear="no
 ne"> Most likely, you'd want to deploy AccessTokenService as an independent 
JAX-RS endpoint, for example:</p><div class="code panel pdl" 
style="border-width: 1px;"><div class="codeContent panelContent pdl">
+</div></div><pre>&#160;</pre><h4 id="JAX-RSOAuth2-JWTTokens">JWT 
Tokens</h4><p>JWT Token can be JWE-encrypted and the encrypted string passed to 
ServerAccessToken as access token id parameter.</p><p>See <a shape="rect" 
href="http://cxf.apache.org/docs/jax-rs-jose.html";>JAX-RS JOSE</a> wiki page 
for more information on how to sign and encrypt JSON Web Tokens.</p><p><a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/tokens/jwt/JwtAccessTokenUtils.java";
 rel="nofollow">JwtAccessTokenUtils </a>provides utility method for encrypting 
and decrypting an access token represented as JWT.</p><p>Note more support for 
JWT access tokens is on the way.</p><h4 id="JAX-RSOAuth2-Customtokens">Custom 
tokens</h4><p>If needed, users can use their own custom token types, with the 
only restriction that the custom token type implementations have to extend 
org.apache.cxf.rs.security.oauth2.co
 mmon.ServerAccessToken.</p><h4 
id="JAX-RSOAuth2-SimpleTokensandAudience">Simple Tokens and 
Audience</h4><p>Starting from CXF 2.7.7 an <a shape="rect" 
class="external-link" 
href="http://tools.ietf.org/html/draft-tschofenig-oauth-audience-00"; 
rel="nofollow">audience</a> parameter is supported during the client token 
requests.</p><h3 
id="JAX-RSOAuth2-OAuthJSONProvider">OAuthJSONProvider</h3><p>org.apache.cxf.rs.security.oauth2.provider.OAuthJSONProvider
 is a JAX-RS MessageBodyWriter which supports returning ClientAccessToken and 
OAuthError representations to the client in a JSON format required by OAuth2 
spec. It is also a JAX-RS MessageBodyReader that is used by client 
OAuthClientUtils (see below) to read the responses from 
AccessTokenService.</p><p>Register it as a provider with a JAXRS 
AccessTokenService endpoint.</p><p>Alternatively, if you prefer, a custom 
MessageBodyWriter implementation can be registered instead.</p><h2 
id="JAX-RSOAuth2-AccessTokenValidationService">Access Token
  Validation Service</h2><h3 
id="JAX-RSOAuth2-AccessTokenValidatorService">AccessTokenValidatorService</h3><p>The
 <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/AccessTokenValidatorService.java";
 rel="nofollow">AccessTokenValidatorService</a> is a CXF specific OAuth2 
service for accepting the remote access token validation requests. 
OAuthRequestFilter needs to be injected with <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/AccessTokenValidatorClient.java";
 rel="nofollow">AccessTokenValidatorClient</a> which will ask 
AccessTokenValidatorService to return the information relevant to the current 
access token, before setting up a security context.</p><h3 
id="JAX-RSOAuth2-TokenIntrospectionService">TokenIntrospectionService</h3><p>The
  <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/TokenIntrospectionService.java";
 rel="nofollow">TokenIntrospectionService</a> is a standard OAuth2 service for 
accepting the remote access token introspection requests. See <a shape="rect" 
class="external-link" href="https://tools.ietf.org/html/rfc7662"; 
rel="nofollow">RFC 7662</a>. OAuthRequestFilter needs to be injected with <a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/AccessTokenIntrospectionClient.java";
 rel="nofollow">AccessTokenIntrospectionClient.</a></p><h2 
id="JAX-RSOAuth2-TokenRevocationService">TokenRevocationService</h2><p><a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cx
 f/rs/security/oauth2/services/TokenRevocationService.java" 
rel="nofollow">TokenRevocationService</a> is a simple OAuth2 service supporting 
the clients wishing to revoke the access or refresh tokens they own themselves, 
please see <a shape="rect" class="external-link" 
href="http://tools.ietf.org/html/draft-ietf-oauth-revocation-09"; 
rel="nofollow">OAuth2 Token Revocation Draft</a> for more 
information.</p><p>TokenRevocationService and AccessTokenService share the same 
code which enforces that the clients have been correctly 
authenticated.</p><p>Note, OAuthDataProvider implementations processing a 
revocation request should simply ignore the invalid tokens as recommended by 
the specification which will let TokenRevocationService return HTTP 200 which 
is done to minimize a possible attack surface (specifically for bad clients not 
to see if their requests failed or succeeded) and throw the exceptions only if 
the token revocation feature is not currently supported.</p><h2 
id="JAX-RSOAuth2-
 SupportedGrants">Supported Grants</h2><p>The following subsections briefly 
describe how the well-known grant types can be supported on the server side. 
Please also check the "Client Side Support" section on how to use the related 
<a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/AccessTokenGrant.java";
 rel="nofollow">AccessTokenGrant</a> implementations to request the access 
tokens.</p><h3 id="JAX-RSOAuth2-AuthorizationCode">Authorization Code</h3><p>As 
described above, <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/AuthorizationCodeGrantService.java";
 rel="nofollow">AuthorizationCodeGrantService</a> service and <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/s
 
rc/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AuthorizationCodeDataProvider.java"
 rel="nofollow">AuthorizationCodeDataProvider</a> data provider can support a 
redirection-based Authorization Code flow.</p><p>The code that the client 
receives in the end of the redirection process will need to be exchanged for a 
new access token with AccessTokenService. CXF-based clients can use a helper <a 
shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AuthorizationCodeGrant.java";>AuthorizationCodeGrant</a>
 bean to request a new access token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-Implicit">Implicit</h3><p>Implicit grant is supported the same 
way Authorization Code grant is except that no code is created, a token is 
issued immediately and returned to the client running within a web 
browser.</p><p><a shape="rect" class="external-link" href="https://gith
 
ub.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/services/ImplicitGrantService.java"
 rel="nofollow">ImplicitGrantService</a> service asks <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/OAuthDataProvider.java";
 rel="nofollow">OAuthDataProvider</a> data provider to issue a new token after 
a user has approved it.</p><p>Note the only difference is the use of 
ImplicitGrantService instead of AuthorizationCodeGrantService.</p><p>Also note 
that when an Implicit grant client (running within a browser) replaces the code 
grant for a new access token and tries to access the end user's resource, Cross 
Origin Resource Sharing (CORS) support will most likely need to be enabled on 
the end user's resource server.<br clear="none"> The simplest approach is to 
register a CXF <a shape="rect" href="http://cxf.apac
 he.org/docs/jax-rs-cors.html">CORS filter</a>, right before OAuth2 filter (see 
on it below).</p><p>Starting from CXF 2.7.5 it is possible to request 
ImplicitGrantService to return a registered Client id to the browser-hosted 
client. This is recommended so that the client can verify that the token is 
meant to be delivered to this client.</p><h3 
id="JAX-RSOAuth2-ClientCredentials">Client Credentials</h3><p>Register <a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/clientcred/ClientCredentialsGrant.java";
 rel="nofollow">ClientCredentialsGrantHandler</a> handler with 
AccessTokenService for this grant be supported.</p><p>CXF-based clients can use 
a helper <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/clientcred/ClientCredentialsGrant.jav
 a" rel="nofollow">ClientCredentialsGrant</a> bean to request a new access 
token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-ResourceOwnerPasswordCredentials">Resource Owner Password 
Credentials</h3><p>Register <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/owner/ResourceOwnerGrantHandler.java";
 rel="nofollow">ResourceOwnerGrantHandler</a> handler with AccessTokenService 
for this grant be supported.</p><p>CXF-based clients can use a helper <a 
shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/owner/ResourceOwnerGrant.java";>ResourceOwnerGrant</a>
 bean to request a new access token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-RefreshToken">Refresh Token</h3><p>The client can issue a 
refresh token grant if the current access token it ow
 ns has expired or been revoked and the refresh token was issued alongside with 
the access token which is now invalid and get the new, 'refreshed' access 
token. This can allow the client to avoid seeking a new authorization approval 
from the end user.</p><p>Register <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/refresh/RefreshTokenGrantHandler.java";>RefreshTokenGrantHandler</a>
 handler with AccessTokenService for this grant be supported. Note this grant 
handler is only useful for refreshing the existing access token, so one or more 
of the other grant handlers (Authorization Code, Implicit, etc) will also have 
to be registered with AccessTokenService.</p><p>CXF-based clients can use a 
helper <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2
 /grants/owner/ResourceOwnerGrant.java" rel="nofollow">RefreshTokenGrant</a> 
bean to request a new access token with OAuthClientUtils.</p><h3 
id="JAX-RSOAuth2-SAMLandJWTAssertions">SAML and JWT Assertions</h3><p>SAML2 
Bearer and JWT assertions can be used as token grants.</p><p>Please see <a 
shape="rect" href="jaxrs-oauth2-assertions.html">JAXRS OAuth2 Assertions</a> 
section for more information.</p><p>&#160;</p><h3 
id="JAX-RSOAuth2-CustomGrants">Custom Grants</h3><p>If you need to customize 
the way the well-known grant requests are handled then consider extending one 
of the grant handlers listed in the previous sub-sections.</p><p>Alternatively 
create a custom <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AccessTokenGrantHandler.java";
 rel="nofollow">AccessTokenGrantHandler</a> and register it with 
AccessTokenService. Additionally, consider providing a r
 elated&#160;<a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/AccessTokenGrant.java";
 rel="nofollow">AccessTokenGrant</a> implementation for making it easy for the 
client code to request a new access token with this custom grant.</p><h2 
id="JAX-RSOAuth2-RedirectionFlowFilters">Redirection Flow Filters</h2><p><a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AuthorizationRequestFilter.java";
 rel="nofollow">AuthorizationRequestFilter</a> implementations can be 
registered with AuthorizationCodeGrantService or ImplicitGrantService in order 
to pre-process code requests. For example, <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/securit
 y/oauth2/grants/code/JwtRequestCodeFilter.java" 
rel="nofollow">JwtRequestCodeFilter</a> can be used to process JWS-signed or 
JWE-encrypted code requests.</p><p><a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AuthorizationCodeResponseFilter.java";
 rel="nofollow">AuthorizationCodeResponseFilter</a> implementations can be 
registered with AuthorizationCodeService in order to post-process code 
responses.</p><h2 
id="JAX-RSOAuth2-AccessTokenResponseFilters">AccessTokenResponse 
Filters</h2><p><a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AccessTokenResponseFilter.java";
 rel="nofollow">AccessTokenResponseFilter</a> implementations can be registered 
with AccessTokenService in order to post-process access token responses. For 
example,&#16
 0; OIDC IdToken can be added to a response with a <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/sso/oidc/src/main/java/org/apache/cxf/rs/security/oidc/idp/IdTokenResponseFilter.java";
 rel="nofollow">IdTokenResponseFilter</a>.</p><h2 
id="JAX-RSOAuth2-PreAuthorizedaccesstokens">PreAuthorized access 
tokens</h2><p>When working with the flows which require the end users/resource 
owners explicitly authorizing clients (for example, as in the case of 
redirection-based flows), using pre-authorized access tokens is one option to 
minimize the need for the end-user intervention. <br clear="none"> 
OAuthDataProvider is always checked first if the pre-authorized access token 
for a given Client exists and if yes then it will be returned immediately, 
without starting the authorization process involving the end user (as required 
by some flows).</p><p>Consider providing a user interface which will let the 
end users/resource owners to pre-authorize 
 specific clients early. Note, a CXF service for supporting the users 
pre-authorizing the clients or revoking the tokens for some of the clients may 
be introduced in the future.</p><p>Also note that using a refresh token grant 
may further help with minimizing the end user involvement, in cases when the 
current access token has expired.</p><h2 
id="JAX-RSOAuth2-Pre-registeredscopes">Pre-registered scopes</h2><p>Clients can 
register custom scopes they will be expected to use and then avoid specifying 
the scopes when requesting the code grants or access tokens.<br clear="none"> 
Alternatively it makes it easier to support so called wild-card scopes. For 
example, a client pre-registers a scope "update" and actually uses an 
"update-7" scope: Redirection-based services and access token grants can be 
configured to do a partial scope match, in this case, validate that "update-7" 
starts from "update"</p><h2 id="JAX-RSOAuth2-WritingOAuthDataProvider">Writing 
OAuthDataProvider</h2><p>Using CXF OA
 uth service implementations will help a lot with setting up an OAuth server. 
As you can see from the above sections, these services rely on a custom 
OAuthDataProvider implementation.</p><p>The main task of OAuthDataProvider is 
to persist and generate access tokens. Additionally, as noted above, 
AuthorizationCodeDataProvider needs to persist and remove the code grant 
registrations. The way it's done is really application-specific. Consider 
starting with a basic memory based implementation and then move on to keeping 
the data in some DB.</p><p>Finally OAuthDataProvider may need to convert opaque 
scope values such as "readCalendar" into a list of <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/OAuthPermission.java";
 rel="nofollow">OAuthPermission</a>s. AuthorizationCodeGrantService and OAuth2 
security filters will depend on it (assuming scopes are used in the f
 irst place).&#160;</p><h3 id="JAX-RSOAuth2-DefaultProviders">Default 
Providers</h3><p>CXF 3.1.7 ships JPA2 (<a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/JPAOAuthDataProvider.java";
 rel="nofollow">JPAOAuthDataProvider</a> and <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/JPACodeDataProvider.java";
 rel="nofollow">JPACodeDataProvider</a>), Ehcache (<a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/DefaultEHCacheOAuthDataProvider.java";
 rel="nofollow">DefaultEHCacheOAuthDataProvider</a> and <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-paren
 
t/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/DefaultEHCacheCodeDataProvider.java"
 rel="nofollow">DefaultEHCacheCodeDataProvider</a>) and JCache (<a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/JCacheOAuthDataProvider.java";
 rel="nofollow">JCacheOAuthDataProvider</a> and <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/JCacheCodeDataProvider.java";
 rel="nofollow">JCacheCodeDataProvider</a>) provider implementations which take 
care of all the persistence tasks: saving or removing registered clients, 
tokens and code grants. These providers can be easily customized.</p><p>Custom 
implementations can also extend&#160; <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/s
 
ecurity/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AbstractOAuthDataProvider.java"
 rel="nofollow">AbstractOAuthDataProvider</a> or <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AbstractCodeDataProvider.java";
 rel="nofollow">AbstractCodeDataProvider</a>&#160; and only implement their 
abstract persistence related methods or further customize some of their 
code.</p><h2 id="JAX-RSOAuth2-OAuthServerJAX-RSendpoints">OAuth Server JAX-RS 
endpoints</h2><p>With CXF offering OAuth service implementations and a custom 
OAuthDataProvider provider in place, it is time to deploy the OAuth2 server. 
<br clear="none"> Most likely, you'd want to deploy AccessTokenService as an 
independent JAX-RS endpoint, for example:</p><div class="code panel pdl" 
style="border-width: 1px;"><div class="codeContent panelContent pdl">
 <pre class="brush: xml; gutter: false; theme: Default" 
style="font-size:12px;">&lt;!-- implements OAuthDataProvider --&gt;
 &lt;bean id="oauthProvider" class="oauth.manager.OAuthManager"/&gt;
      
@@ -418,7 +408,7 @@ ModelEncryptionSupport.decryptAccessToke
   &lt;/jaxrs:serviceBeans&gt;
 &lt;/jaxrs:server&gt;
 </pre>
-</div></div><p>AuthorizationCodeGrantService listens on a relative 
"/authorize" path so in this case its absolute address will be something like 
"http://localhost:8080/services/myapp/authorize";. This address and that of 
AccessTokenService will be used by third-party clients.</p><h1 
id="JAX-RSOAuth2-ThirdPartyClientAuthentication">Third Party Client 
Authentication</h1><p>When a client requests a token from Access Token Service, 
it needs to get authenticated. Providing its client_id and client secret as 
part of Basic Authorization scheme or posting them directly as form parameters 
are typical options, however other authentication schemes can easily be 
supported if required.</p><p>For example, using client certificates or 
assertions like SAML2 Bearer or JWT is all acceptable - the only additional 
requirement in this case is that a given security filter processing a specific 
authentication scheme maps the client credentials to an actual client_id - CXF 
Access Token Service will check a 
 "client_id" property on the current message context as the last resort. Note 
that org.apache.cxf.rs.security.oauth2.provider.ClientIdProvider can be 
registered with AccessTokenService to facilitate the mapping between an 
authenticated client and its id expected by the data provider if the container 
or filter based authentication can not set a "client_id" contextual 
property.</p><p>If a Basic authentication scheme is used and neither the 
container or filter has authenticated the client AccessTokenService will 
request a Client from the data provider and compare the Client's secret against 
the password found in the Basic scheme data. 
org.apache.cxf.rs.security.oauth2.provider.ClientSecretVerifier is available 
starting from CXF 3.0.3 to support Clients saving only password hashes. Its 
org.apache.cxf.rs.security.oauth2.provider.ClientSecretHashVerifier (calculates 
a SHA-256 password hash and compares it with the Client's secret) or custom 
implementations can be registered with AccessToke
 nService.</p><p>If a 2-way TLS is sued to authenticate a client and Client has 
a Base64 encoded representations of its X509Certificates available in its 
"applicationCertificates" property then AccessTokenService will do the 
additional comparison of these certificates against the ones available in the 
current TLS session.</p><p>Please see <a shape="rect" 
href="jaxrs-oauth2-assertions.html">JAXRS OAuth2 Assertions</a> section for 
more information on how it may work.</p><h1 
id="JAX-RSOAuth2-UserSessionAuthenticity">User Session 
Authenticity</h1><p>Redirection-based Authorization Code and Implicit flows 
depend on end users signing in if needed during the initial redirection, 
challenged with the client authorization form and returning their decision. By 
default, CXF will enforce the user session authenticity by keeping the session 
state in a servlet container's HTTPSession. If the alternative storage is 
preferred then you can register a new <a shape="rect" class="external-link" 
href="htt
 
ps://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/SessionAuthenticityTokenProvider.java"
 rel="nofollow">SessionAuthenticityTokenProvider</a> with either 
AuthorizationCodeGrantService or ImplicitGrantService beans.</p><p>CXF ships <a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/JoseSessionTokenProvider.java";
 rel="nofollow">JoseSessionTokenProvider </a>which uses <a shape="rect" 
href="http://cxf.apache.org/docs/jax-rs-jose.html";>CXF JOSE</a> to create a 
compact JWS and/or JWE sequence capturing all the data which need to be 
available when the user returns an authorization form decision and this secure 
sequence becomes a session token.</p><h3 
id="JAX-RSOAuth2-Keepingthestateinthesession">Keeping the state in the 
session</h3><p>Note that <a shape="rect" class="external-link" href
 
="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/SessionAuthenticityTokenProvider.java";>SessionAuthenticityTokenProvider</a>
 has been further updated in CXF 3.1.0 to support signing and/or encrypting 
some of the redirection properties that would otherwise have to be kept as HTML 
form hidden fields (see "Authorization Service" section).</p><p>CXF&#160; ships 
org.apache.cxf.rs.security.oauth2.provider.JoseSessionTokenProvider that can be 
used as a <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/SessionAuthenticityTokenProvider.java";>SessionAuthenticityTokenProvider</a>
 which JWS-signs and/or JWE-encrypts the properties and saves the result in the 
session. The HTML authorization forms will only have to have an 
"authenticityToken" property which the provider will use to mat
 ch the session signed/encryped data and decrypt and/or validate the session 
data.</p><h3 id="JAX-RSOAuth2-MultipleFactorVerification">Multiple Factor 
Verification</h3><p>Note that <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/SessionAuthenticityTokenProvider.java";>SessionAuthenticityTokenProvider</a>
 has been updated in CXF 3.0.2 to accept request parameters and a reference to 
the authenticated user. This allows for introducing a multiple factor session 
verification: when the provider created a session property it can for example 
sent a message to a user's mobile phone expect the authorization consent form 
return the sent value.</p><p>The other minor enhancement is that 
RedirectionBasedGrantService will check the authorization content form for the 
name of the form property that contains a session authentication property, 
using a "session_authenticity_to
 ken_param_name" property name. This allows for the 'rotation' of hidden form 
properties containing the actual session authenticity values.</p><h1 
id="JAX-RSOAuth2-CustomizingEndUserSubjectinitialization">Customizing End User 
Subject initialization</h1><p>By default, redirection based authorization 
services will the the current CXF SecurityContext to initialize a subject 
representing the authenticated resource owner/end user. If the customization if 
needed: custom CXF filter can be used to create UserSubject and set it on the 
message or org.apache.cxf.rs.security.oauth2.provider.SubjectCreator interface 
implementation can be registered with either AuthorizationCodeGrantService or 
ImplicitGrantService.</p><h1 
id="JAX-RSOAuth2-ProtectingresourceswithOAuthfilters">Protecting resources with 
OAuth filters</h1><p><a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OA
 uthRequestFilter.java">OAuthRequestFilter</a> request handler can be used to 
protect the resource server when processing the requests from the third-party 
clients. Add it as a jaxrs:provider to the endpoint which deals with the 
clients requesting the resources.</p><p>When checking a request like 
this:</p><div class="code panel pdl" style="border-width: 1px;"><div 
class="codeContent panelContent pdl">
+</div></div><p>AuthorizationCodeGrantService listens on a relative 
"/authorize" path so in this case its absolute address will be something like 
"http://localhost:8080/services/myapp/authorize";. This address and that of 
AccessTokenService will be used by third-party clients.</p><h1 
id="JAX-RSOAuth2-ThirdPartyClientAuthentication">Third Party Client 
Authentication</h1><p>When a client requests a token from Access Token Service, 
it needs to get authenticated. Providing its client_id and client secret as 
part of Basic Authorization scheme or posting them directly as form parameters 
are typical options, however other authentication schemes can easily be 
supported if required.</p><p>For example, using client certificates or 
assertions like SAML2 Bearer or JWT is all acceptable - the only additional 
requirement in this case is that a given security filter processing a specific 
authentication scheme maps the client credentials to an actual client_id - CXF 
Access Token Service will check a 
 "client_id" property on the current message context as the last resort. Note 
that org.apache.cxf.rs.security.oauth2.provider.ClientIdProvider can be 
registered with AccessTokenService to facilitate the mapping between an 
authenticated client and its id expected by the data provider if the container 
or filter based authentication can not set a "client_id" contextual 
property.</p><p>If a Basic authentication scheme is used and neither the 
container or filter has authenticated the client AccessTokenService will 
request a Client from the data provider and compare the Client's secret against 
the password found in the Basic scheme data. 
org.apache.cxf.rs.security.oauth2.provider.ClientSecretVerifier is available 
starting from CXF 3.0.3 to support Clients saving only password hashes. Its 
org.apache.cxf.rs.security.oauth2.provider.ClientSecretHashVerifier (calculates 
a SHA-256 password hash and compares it with the Client's secret) or custom 
implementations can be registered with AccessToke
 nService.</p><p>If a 2-way TLS is sued to authenticate a client and Client has 
a Base64 encoded representations of its X509Certificates available in its 
"applicationCertificates" property then AccessTokenService will do the 
additional comparison of these certificates against the ones available in the 
current TLS session.</p><p>Please see <a shape="rect" 
href="jaxrs-oauth2-assertions.html">JAXRS OAuth2 Assertions</a> section for 
more information on how it may work.</p><h1 
id="JAX-RSOAuth2-UserSessionAuthenticity">User Session 
Authenticity</h1><p>Redirection-based Authorization Code and Implicit flows 
depend on end users signing in if needed during the initial redirection, 
challenged with the client authorization form and returning their decision. By 
default, CXF will enforce the user session authenticity by keeping the session 
state in a servlet container's HTTPSession. If the alternative storage is 
preferred then you can register a new <a shape="rect" class="external-link" 
href="htt
 
ps://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/SessionAuthenticityTokenProvider.java"
 rel="nofollow">SessionAuthenticityTokenProvider</a> with either 
AuthorizationCodeGrantService or ImplicitGrantService beans.</p><p>CXF ships <a 
shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/JoseSessionTokenProvider.java";
 rel="nofollow">JoseSessionTokenProvider </a>which uses <a shape="rect" 
href="http://cxf.apache.org/docs/jax-rs-jose.html";>CXF JOSE</a> to create a 
compact JWS and/or JWE sequence capturing all the data which need to be 
available when the user returns an authorization form decision and this secure 
sequence becomes a session token.</p><h3 
id="JAX-RSOAuth2-Keepingthestateinthesession">Keeping the state in the 
session</h3><p>Note that&#160;<a shape="rect" class="external-link"
  
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/SessionAuthenticityTokenProvider.java";
 rel="nofollow">SessionAuthenticityTokenProvider</a> has been further updated 
in CXF 3.1.0 to support signing and/or encrypting some of the redirection 
properties that would otherwise have to be kept as HTML form hidden fields (see 
"Authorization Service" section).</p><p>CXF&#160; ships&#160;<a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/JoseSessionTokenProvider.java";
 rel="nofollow">JoseSessionTokenProvider </a>which uses <a shape="rect" 
href="http://cxf.apache.org/docs/jax-rs-jose.html";>CXF JOSE</a> that can be 
used as a SessionAuthenticityTokenProvider which JWS-signs and/or JWE-encrypts 
the properties and saves the result in the session. The HTML authorization 
forms will only
  have to have an "authenticityToken" property which the provider will use to 
match the session signed/encryped data and decrypt and/or validate the session 
data.</p><h3 id="JAX-RSOAuth2-MultipleFactorVerification">Multiple Factor 
Verification</h3><p>Note that&#160;<a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/SessionAuthenticityTokenProvider.java";
 rel="nofollow">SessionAuthenticityTokenProvider</a> has been updated in CXF 
3.0.2 to accept request parameters and a reference to the authenticated user. 
This allows for introducing a multiple factor session verification: when the 
provider created a session property it can for example sent a message to a 
user's mobile phone expect the authorization consent form return the sent 
value.</p><p>The other minor enhancement is that RedirectionBasedGrantService 
will check the authorization content form for the name of
  the form property that contains a session authentication property, using a 
"session_authenticity_token_param_name" property name. This allows for the 
'rotation' of hidden form properties containing the actual session authenticity 
values.</p><h1 
id="JAX-RSOAuth2-CustomizingEndUserSubjectinitialization">Customizing End User 
Subject initialization</h1><p>By default, redirection based authorization 
services will the the current CXF SecurityContext to initialize a subject 
representing the authenticated resource owner/end user. If the customization if 
needed: custom CXF filter can be used to create UserSubject and set it on the 
message or org.apache.cxf.rs.security.oauth2.provider.SubjectCreator interface 
implementation can be registered with either AuthorizationCodeGrantService or 
ImplicitGrantService.</p><h1 
id="JAX-RSOAuth2-ProtectingresourceswithOAuthfilters">Protecting resources with 
OAuth filters</h1><p><a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/
 
master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestFilter.java"
 rel="nofollow">OAuthRequestFilter</a> request handler can be used to protect 
the resource server when processing the requests from the third-party clients. 
Add it as a jaxrs:provider to the endpoint which deals with the clients 
requesting the resources.</p><p>When checking a request like this:</p><div 
class="code panel pdl" style="border-width: 1px;"><div class="codeContent 
panelContent pdl">
 <pre class="brush: xml; gutter: false; theme: Default" 
style="font-size:12px;">Address: 
http://localhost:8080/services/thirdPartyAccess/calendar
 Http-Method: GET
 Headers: 
@@ -427,7 +417,7 @@ Headers:
   Accept=[application/xml]
 }
 </pre>
-</div></div><p>the filter will do the following:</p><p>1. Retrieve a 
ServerAccessToken by delegating to a matching registered <a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AccessTokenValidator.java";>AccessTokenValidator</a>.
 AccessTokenValidator is expected to check the validity of the incoming token 
parameters and possibly delegate to OAuthDataProvider to find the token 
representation - this is what the filter will default to if no matching 
AccessTokenValidator is found and the Authorization scheme is 
'Bearer'.</p><p>2. Check the token has not expired</p><p>3. AccessToken may 
have a list of <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security2/oauth/data/OAuthPermission.java";>OAuthPermissions</a>.
 For every permission it will:</p><ul class="alte
 rnate"><li>If it has a uri property set then the current request URI will be 
checked against it</li><li>If it has an httpVerb property set then the current 
HTTP verb will be checked against it</li></ul><p>If an allPermissionsMatch 
property is set then the filter will check that all the token permissions have 
been met.</p><p>If a requestScopes property is set then the filter will check 
that all of the scopes are 'covered' by one or more token permissions.</p><p>4. 
Finally, it will create a CXF <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/api/src/main/java/org/apache/cxf/security/SecurityContext.java";>SecurityContext</a>
 using this list of <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/data/OAuthPermission.java";>OAuthPermissions</a>,
 the <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt
 
/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/UserSubject.java">UserSubject</a>
 representing the client or the end user who authorized the grant used to 
obtain this token.</p><p>This SecurityContext will not necessarily be important 
for some of OAuth2 applications. Most of the security checks will be done by 
OAuth2 filters and security filters protecting the main application path the 
end users themselves use. Only if you would like to share the same JAX-RS 
resource code and access URIs between end users and clients then it can become 
handy. More on it below.</p><p>Here is one example of how OAuthRequestFilter 
can be configured:</p><div class="code panel pdl" style="border-width: 
1px;"><div class="codeContent panelContent pdl">
+</div></div><p>the filter will do the following:</p><p>1. Retrieve a 
ServerAccessToken by delegating to a matching registered <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/provider/AccessTokenValidator.java";
 rel="nofollow">AccessTokenValidator</a>. AccessTokenValidator is expected to 
check the validity of the incoming token parameters and possibly delegate to 
OAuthDataProvider to find the token representation - this is what the filter 
will default to if no matching AccessTokenValidator is found and the 
Authorization scheme is 'Bearer'.</p><p>2. Check the token has not 
expired</p><p>3. AccessToken may have a list of <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/OAuthPermission.java";
 rel="nofollow">OAuthPermission</a>. For every permiss
 ion it will:</p><ul class="alternate"><li>If it has a uri property set then 
the current request URI will be checked against it</li><li>If it has an 
httpVerb property set then the current HTTP verb will be checked against 
it</li></ul><p>If an allPermissionsMatch property is set then the filter will 
check that all the token permissions have been met.</p><p>If a requestScopes 
property is set then the filter will check that all of the scopes are 'covered' 
by one or more token permissions.</p><p>4. Finally, it will create a CXF 
SecurityContext using this list of <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/OAuthPermission.java";
 rel="nofollow">OAuthPermissions</a>, the <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/UserSubject.java";
 
 rel="nofollow">UserSubject</a> representing the client or the end user who 
authorized the grant used to obtain this token.</p><p>This SecurityContext will 
not necessarily be important for some of OAuth2 applications. Most of the 
security checks will be done by OAuth2 filters and security filters protecting 
the main application path the end users themselves use. Only if you would like 
to share the same JAX-RS resource code and access URIs between end users and 
clients then it can become handy. More on it below.</p><p>Here is one example 
of how OAuthRequestFilter can be configured:</p><div class="code panel pdl" 
style="border-width: 1px;"><div class="codeContent panelContent pdl">
 <pre class="brush: xml; gutter: false; theme: Default" 
style="font-size:12px;">&lt;bean id="oauthProvider" 
class="oauth.manager.OAuthManager"/&gt;
 &lt;bean id="oauthFiler" 
class="org.apache.cxf.rs.security.oauth2.filters.OAuthRequestFilter"&gt;
   &lt;property name="dataProvider" ref="oauthProvider"/&gt;
@@ -477,7 +467,7 @@ Headers:
   &lt;/jaxrs:providers&gt;
 &lt;/jaxrs:server&gt;
 </pre>
-</div></div><h2 id="JAX-RSOAuth2-OAuth2tokensandSOAPendpoints">OAuth2 tokens 
and SOAP endpoints</h2><p>If you use HTTP Authorization header or WS-Security 
Binary token to pass OAuth2 tokens to SOAP endpoints then <a shape="rect" 
class="external-link" 
href="https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=blob;f=rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestInterceptor.java;h=173fed36fc78db69c0d4afaee5d5f482dd4e05fd;hb=HEAD";>OAuthRequestInterceptor</a>
 can be used to validate such tokens. It is OAuthRequestFilter running as CXF 
interceptor which will work OOB for tokens passed with Authorization header and 
it can be easily extended to support WS-Security binary tokens</p><h1 
id="JAX-RSOAuth2-Scope-basedaccesscontrol">Scope-based access 
control</h1><p>OAuthRequestFilter can be configured to do a lot of security 
checks as described above.&#160;</p><p>Additionally, starting from CXF 3.1.5 it 
is also possible to control which se
 rvice methods can be invoked</p><p>with a new <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/Scopes.java";
 rel="nofollow">Scopes</a> annotation and <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthScopesFilter.java";
 rel="nofollow">OAuthScopesFilter</a> (it needs to be registered alongside 
OAuthRequestFilter).</p><p>For example:</p><pre>@Path("calendar")
+</div></div><h2 id="JAX-RSOAuth2-OAuth2tokensandSOAPendpoints">OAuth2 tokens 
and SOAP endpoints</h2><p>If you use HTTP Authorization header or WS-Security 
Binary token to pass OAuth2 tokens to SOAP endpoints then <a shape="rect" 
class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestInterceptor.java";
 rel="nofollow">OAuthRequestInterceptor</a> can be used to validate such 
tokens. It is OAuthRequestFilter running as CXF interceptor which will work OOB 
for tokens passed with Authorization header and it can be easily extended to 
support WS-Security binary tokens</p><h1 
id="JAX-RSOAuth2-Scope-basedaccesscontrol">Scope-based access 
control</h1><p>OAuthRequestFilter can be configured to do a lot of security 
checks as described above.&#160;</p><p>Additionally, starting from CXF 3.1.5 it 
is also possible to control which service methods can be invoked</p><p>with a 
new <a shap
 e="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/Scopes.java";
 rel="nofollow">Scopes</a> annotation and <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthScopesFilter.java";
 rel="nofollow">OAuthScopesFilter</a> (it needs to be registered alongside 
OAuthRequestFilter).</p><p>For example:</p><pre>@Path("calendar")
 public class CalendarResource {
 
    
@@ -509,7 +499,7 @@ public class ThirdPartyAccessService {
 }
 
 </pre>
-</div></div><p>The above shows a fragment of the JAX-RS service managing the 
access to user resources from authorized 3rd-party clients (see the Design 
Considerations section for more information).</p><p>The injected MessageContext 
provides an access to <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/OAuthContext.java";>OAuthContext</a>
 which has been set by OAuth2 filters described in the previous section. 
OAuthContext will act as a container of the information which can be useful to 
the custom application code which do not need to deal with the OAuth2 
internals. OAuthContextUtils provides a number of utility methods for 
retrieving and working with OAuthContext.</p><p>Note that starting from CXF 
2.7.6 it is also possible to inject OAuthContext as JAX-RS context:</p><div 
class="code panel pdl" style="border-width: 1px;"><div class="codeContent 
panelContent p
 dl">
+</div></div><p>The above shows a fragment of the JAX-RS service managing the 
access to user resources from authorized 3rd-party clients (see the Design 
Considerations section for more information).</p><p>The injected MessageContext 
provides an access to <a shape="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/common/OAuthContext.java";
 rel="nofollow">OAuthContext</a> which has been set by OAuth2 filters described 
in the previous section. OAuthContext will act as a container of the 
information which can be useful to the custom application code which do not 
need to deal with the OAuth2 internals. OAuthContextUtils provides a number of 
utility methods for retrieving and working with OAuthContext.</p><p>Note that 
starting from CXF 2.7.6 it is also possible to inject OAuthContext as JAX-RS 
context:</p><div class="code panel pdl" style="border-width: 1px;"><div 
class="codeContent
  panelContent pdl">
 <pre class="brush: java; gutter: false; theme: Default" 
style="font-size:12px;"> 
 import org.apache.cxf.rs.security.oauth2.common.OAuthContext;
 
@@ -525,7 +515,7 @@ public class ThirdPartyAccessService {
     }
 }
 </pre>
-</div></div><p>org.apache.cxf.rs.security.oauth2.provider.OAuthContextProvider 
will have to be registered as jaxrs:provider for it to work.</p><h1 
id="JAX-RSOAuth2-Client-sidesupport">Client-side support</h1><p>When developing 
a third party application which needs to participate in OAuth2 flows one has to 
deal with redirecting users to OAuth2 AuthorizationCodeGrantService, 
interacting with AccessTokenService in order to exchange code grants for access 
tokens as well as correctly building Authorization OAuth2 headers when 
accessing the end users' resources.</p><h2 
id="JAX-RSOAuth2-AdvancedOAuth2clientapplications">Advanced OAuth2 client 
applications</h2><p>In a number of cases an OAuth2 client application 
supporting the code flow needs to have an OAuth2-specific code written 
directly. Such clients qualify as advanced given that writing such a code 
requires thel understanding of OAuth2 specifics. That said,</p><p>JAX-RS makes 
it straightforward to support the redirection, while <a sha
 pe="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/client/OAuthClientUtils.java";>OAuthClientUtils</a>
 class makes it possible to encapsulate most of the complexity away from the 
client application code, so ultimately the code required to support is 
typically not that complex at all, while at the same it offers the most 
flexibility.</p><p>For example, the following custom code can be used by the 
third-party application:</p><div class="code panel pdl" style="border-width: 
1px;"><div class="codeContent panelContent pdl">
+</div></div><p>org.apache.cxf.rs.security.oauth2.provider.OAuthContextProvider 
will have to be registered as jaxrs:provider for it to work.</p><h1 
id="JAX-RSOAuth2-Client-sidesupport">Client-side support</h1><p>When developing 
a third party application which needs to participate in OAuth2 flows one has to 
deal with redirecting users to OAuth2 AuthorizationCodeGrantService, 
interacting with AccessTokenService in order to exchange code grants for access 
tokens as well as correctly building Authorization OAuth2 headers when 
accessing the end users' resources.</p><h2 
id="JAX-RSOAuth2-AdvancedOAuth2clientapplications">Advanced OAuth2 client 
applications</h2><p>In a number of cases an OAuth2 client application 
supporting the code flow needs to have an OAuth2-specific code written 
directly. Such clients qualify as advanced given that writing such a code 
requires thel understanding of OAuth2 specifics. That said,</p><p>JAX-RS makes 
it straightforward to support the redirection, while <a sha
 pe="rect" class="external-link" 
href="https://github.com/apache/cxf/blob/master/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/client/OAuthClientUtils.java";
 rel="nofollow">OAuthClientUtils</a> class makes it possible to encapsulate 
most of the complexity away from the client application code, so ultimately the 
code required to support is typically not that complex at all, while at the 
same it offers the most flexibility.</p><p>For example, the following custom 
code can be used by the third-party application:</p><div class="code panel pdl" 
style="border-width: 1px;"><div class="codeContent panelContent pdl">
 <pre class="brush: java; gutter: false; theme: Default" 
style="font-size:12px;">public class OAuthClientManager {
        
        private WebClient accessTokenService;
@@ -557,7 +547,7 @@ public class ThirdPartyAccessService {
        }
 }
 </pre>
-</div></div><p>The reason such a simple wrapper can be introduced is to 
minimize the exposure to OAuth2 of the main application code to the bare 
minimum, this is why in this example OAuthServiceExceptions are caught, 
presumably logged and null values are returned which will indicate to the main 
code that the request failed. Obviously, OAuthClientUtils can be used directly 
as well.</p><p>Note that in the above example, an instance of <a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AuthorizationCodeGrant.java";>AuthorizationCodeGrant</a>
 is passed as the last parameter to OAuthClientUtils.getAccessToken() method, 
alongside the references to the AccessTokenService client and 
OAuthClientUtils.Consumer bean keeping the client id and secret.</p><p>CXF 
provides the utility grant beans for all the grants it supports, <a 
shape="rect" class="external-link" href="
 
http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/code/AuthorizationCodeGrant.java";>AuthorizationCodeGrant</a>,
 <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/clientcred/ClientCredentialsGrant.java";>ClientCredentialsGrant</a>,
 <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/owner/ResourceOwnerGrant.java";>ResourceOwnerGrant</a>
 and <a shape="rect" class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/grants/refresh/RefreshTokenGrant.java";>RefreshTokenGrant</a>.
 Please use the appropriate grant bean relevant to your application when 
requesting an access t
 oken or create a custom AccessTokenGrant bean implementation.</p><p>For 
example, consider a case where a client who already owns an authorized access 
token and accessing the end user resource gets HTTP 401 error back and the 
client also owns a refresh token. Here is one possible way to handle 
it:</p><div class="code panel pdl" style="border-width: 1px;"><div 
class="codeContent panelContent pdl">
+</div></div><p>The reason such a simple wrapper can be introduced is to 
minimize the exposure to OAuth2 of the main application code to the bare 
minimum, this is why in this example OAuthServiceExceptions are caught, 
presumably logged and null values are returned which will indicate to the main 
code that the request failed. Obviously, OAuthClientUtils can be used directly 
as well.</p><p>Note that in the above example, an instance of 
AuthorizationCodeGrant is passed as the last parameter to 
OAuthClientUtils.getAccessToken() method, alongside the references to the 
AccessTokenService client and OAuthClientUtils.Consumer bean keeping the client 
id and secret.</p><p>CXF provides the utility grant beans for all the grants it 
supports, see the information on grants above. Please use the appropriate grant 
bean relevant to your application when requesting an access token or create a 
custom AccessTokenGrant bean implementation.</p><p>For example, consider a case 
where a client who already own
 s an authorized access token and accessing the end user resource gets HTTP 401 
error back and the client also owns a refresh token. Here is one possible way 
to handle it:</p><div class="code panel pdl" style="border-width: 1px;"><div 
class="codeContent panelContent pdl">
 <pre class="brush: java; gutter: false; theme: Default" 
style="font-size:12px;">import javax.ws.rs.NotAuthorizedException;
 import javax.ws.rs.core.HttpHeaders;
 
@@ -784,7 +774,7 @@ public class CustomClientTokenContextPro
   &lt;/authSupplier&gt;
 &lt;/conduit&gt;
 &lt;/beans&gt;</pre>

[... 24 lines stripped ...]

Reply via email to