60 lines
1.8 KiB
Java
60 lines
1.8 KiB
Java
package org.gcube.common.authorization.utils.clientid;
|
|
|
|
import org.gcube.common.authorization.utils.secret.JWTSecret;
|
|
import org.gcube.common.authorization.utils.secret.Secret;
|
|
import org.gcube.common.keycloak.KeycloakClientException;
|
|
import org.gcube.common.keycloak.KeycloakClientFactory;
|
|
import org.gcube.common.keycloak.model.TokenResponse;
|
|
|
|
/**
|
|
* @author Luca Frosini (ISTI - CNR)
|
|
*/
|
|
public class ClienIDManager implements RenewalProvider {
|
|
|
|
protected final String clientID;
|
|
protected final String clientSecret;
|
|
|
|
public ClienIDManager(String clientID, String clientSecret) {
|
|
this.clientID = clientID;
|
|
this.clientSecret = clientSecret;
|
|
}
|
|
|
|
public Secret getSecret() throws Exception {
|
|
TokenResponse tokenResponse = KeycloakClientFactory.newInstance().queryUMAToken(clientID, clientSecret, null);
|
|
|
|
JWTSecret jwtSecret = new JWTSecret(tokenResponse.getAccessToken());
|
|
jwtSecret.setRenewalProvider(this);
|
|
|
|
jwtSecret.setTokenResponse(tokenResponse);
|
|
|
|
return jwtSecret;
|
|
}
|
|
|
|
public Secret getSecret(String context) throws Exception {
|
|
TokenResponse tokenResponse = KeycloakClientFactory.newInstance().queryUMAToken(clientID, clientSecret, context, null);
|
|
|
|
JWTSecret jwtSecret = new JWTSecret(tokenResponse.getAccessToken());
|
|
jwtSecret.setRenewalProvider(this);
|
|
|
|
jwtSecret.setTokenResponse(tokenResponse);
|
|
|
|
return jwtSecret;
|
|
}
|
|
|
|
public Secret getOIDCSecret() throws KeycloakClientException {
|
|
TokenResponse tokenResponse = KeycloakClientFactory.newInstance().queryOIDCToken(clientID, clientSecret);
|
|
|
|
JWTSecret jwtSecret = new JWTSecret(tokenResponse.getAccessToken());
|
|
jwtSecret.setRenewalProvider(this);
|
|
|
|
jwtSecret.setTokenResponse(tokenResponse);
|
|
|
|
return jwtSecret;
|
|
}
|
|
|
|
@Override
|
|
public Secret renew() throws Exception {
|
|
return getSecret();
|
|
}
|
|
}
|