Class JwtCredentials
- All Implemented Interfaces:
JwtProvider, Serializable
Uses a JSON Web Token (JWT) directly in the request metadata to provide authorization.
JwtClaims claims = JwtClaims.newBuilder()
.setAudience("https://example.com/some-audience")
.setIssuer("some-issuer@example.com")
.setSubject("some-subject@example.com")
.build();
Credentials = JwtCredentials.newBuilder()
.setPrivateKey(privateKey)
.setPrivateKeyId("private-key-id")
.setJwtClaims(claims)
.build();
- See Also:
-
Nested Class Summary
Nested Classes -
Field Summary
FieldsModifier and TypeFieldDescription(package private) com.google.api.client.util.Clockprivate static final longprivate Longprivate Stringprivate static final Stringprivate static final Stringprivate final JwtClaimsprivate final Longprivate final Objectprivate final PrivateKeyprivate final StringFields inherited from class Credentials
GOOGLE_DEFAULT_UNIVERSE -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbooleanA constant string name describing the authentication technology.(package private) com.google.api.client.util.ClockgetClock()getRequestMetadata(URI uri) Get the current request metadata in a blocking manner, refreshing tokens if required.inthashCode()booleanWhether the credentials have metadata entries that should be added to each request.booleanIndicates whether or not the Auth mechanism works purely by including request metadata.jwtWithClaims(JwtClaims newClaims) Returns a copy of these credentials with modified claims.static JwtCredentials.Buildervoidrefresh()Refresh the token by discarding the cached token and metadata and rebuilding a new one.private booleanMethods inherited from class Credentials
blockingGetToCallback, getMetricsCredentialType, getRequestMetadata, getRequestMetadata, getUniverseDomain
-
Field Details
-
JWT_ACCESS_PREFIX
- See Also:
-
JWT_INCOMPLETE_ERROR_MESSAGE
- See Also:
-
CLOCK_SKEW
private static final long CLOCK_SKEW -
lock
-
privateKey
-
privateKeyId
-
jwtClaims
-
lifeSpanSeconds
-
clock
transient com.google.api.client.util.Clock clock -
jwt
-
expiryInSeconds
-
-
Constructor Details
-
JwtCredentials
-
-
Method Details
-
newBuilder
-
refresh
Refresh the token by discarding the cached token and metadata and rebuilding a new one.- Specified by:
refreshin classCredentials- Throws:
IOException- if there was an error getting up-to-date access.
-
shouldRefresh
private boolean shouldRefresh() -
jwtWithClaims
Returns a copy of these credentials with modified claims.- Specified by:
jwtWithClaimsin interfaceJwtProvider- Parameters:
newClaims- new claims. Any unspecified claim fields default to the the current values.- Returns:
- new credentials
-
getAuthenticationType
Description copied from class:CredentialsA constant string name describing the authentication technology.E.g. “OAuth2”, “SSL”. For use by the transport layer to determine whether it supports the type of authentication in the case where
Credentials.hasRequestMetadataOnly()is false. Also serves as a debugging helper.- Specified by:
getAuthenticationTypein classCredentials- Returns:
- The type of authentication used.
-
getRequestMetadata
Description copied from class:CredentialsGet the current request metadata in a blocking manner, refreshing tokens if required.This should be called by the transport layer on each request, and the data should be populated in headers or other context. The operation can block and fail to complete and may do things such as refreshing access tokens.
The convention for handling binary data is for the key in the returned map to end with
"-bin"and for the corresponding values to be base64 encoded.- Specified by:
getRequestMetadatain classCredentials- Parameters:
uri- URI of the entry point for the request.- Returns:
- The request metadata used for populating headers or other context.
- Throws:
IOException- if there was an error getting up-to-date access. The exception should implementRetryableandisRetryable()will return true if the operation may be retried.
-
hasRequestMetadata
public boolean hasRequestMetadata()Description copied from class:CredentialsWhether the credentials have metadata entries that should be added to each request.This should be called by the transport layer to see if
Credentials.getRequestMetadata()should be used for each request.- Specified by:
hasRequestMetadatain classCredentials- Returns:
- Whether or not the transport layer should call
Credentials.getRequestMetadata()
-
hasRequestMetadataOnly
public boolean hasRequestMetadataOnly()Description copied from class:CredentialsIndicates whether or not the Auth mechanism works purely by including request metadata.This is meant for the transport layer. If this is true a transport does not need to take actions other than including the request metadata. If this is false, a transport must specifically know about the authentication technology to support it, and should fail to accept the credentials otherwise.
- Specified by:
hasRequestMetadataOnlyin classCredentials- Returns:
- Whether or not the Auth mechanism works purely by including request metadata.
-
equals
-
hashCode
-
getClock
com.google.api.client.util.Clock getClock()
-