Class CustomJWTAuthorizerConfiguration
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<CustomJWTAuthorizerConfiguration.Builder,CustomJWTAuthorizerConfiguration>
Configuration for a custom JWT authorizer that validates inbound bearer tokens against an OpenID Connect identity provider.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionThe audience values accepted during JWT validation.The client identifiers accepted during JWT validation.The scopes accepted during JWT validation.builder()final List<CustomClaimValidationType> Additional custom claim validations applied to the inbound JWT.final StringThe OpenID Connect discovery URL used to retrieve the identity provider's metadata and signing keys.final booleanfinal booleanequalsBySdkFields(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz) final booleanFor responses, this returns true if the service returned a value for the AllowedAudience property.final booleanFor responses, this returns true if the service returned a value for the AllowedClients property.final booleanFor responses, this returns true if the service returned a value for the AllowedScopes property.final booleanFor responses, this returns true if the service returned a value for the CustomClaims property.final inthashCode()final booleanFor responses, this returns true if the service returned a value for the PrivateEndpointOverrides property.final PrivateEndpointThe private endpoint used to reach the identity provider's discovery URL over a private network path.final List<PrivateEndpointOverride> Per-domain private endpoint overrides that route specific identity provider domains through distinct private endpoints.static Class<? extends CustomJWTAuthorizerConfiguration.Builder> Take this object and create a builder that contains all of the current property values of this object.final StringtoString()Returns a string representation of this object.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
discoveryUrl
The OpenID Connect discovery URL used to retrieve the identity provider's metadata and signing keys.
- Returns:
- The OpenID Connect discovery URL used to retrieve the identity provider's metadata and signing keys.
-
hasAllowedAudience
public final boolean hasAllowedAudience()For responses, this returns true if the service returned a value for the AllowedAudience property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
allowedAudience
The audience values accepted during JWT validation. A token is rejected if none of its audience claims match.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasAllowedAudience()method.- Returns:
- The audience values accepted during JWT validation. A token is rejected if none of its audience claims match.
-
hasAllowedClients
public final boolean hasAllowedClients()For responses, this returns true if the service returned a value for the AllowedClients property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
allowedClients
The client identifiers accepted during JWT validation. A token is rejected if it was not issued to one of these clients.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasAllowedClients()method.- Returns:
- The client identifiers accepted during JWT validation. A token is rejected if it was not issued to one of these clients.
-
hasAllowedScopes
public final boolean hasAllowedScopes()For responses, this returns true if the service returned a value for the AllowedScopes property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
allowedScopes
The scopes accepted during JWT validation. A token is rejected if it does not carry one of these scopes.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasAllowedScopes()method.- Returns:
- The scopes accepted during JWT validation. A token is rejected if it does not carry one of these scopes.
-
hasCustomClaims
public final boolean hasCustomClaims()For responses, this returns true if the service returned a value for the CustomClaims property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
customClaims
Additional custom claim validations applied to the inbound JWT.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasCustomClaims()method.- Returns:
- Additional custom claim validations applied to the inbound JWT.
-
privateEndpoint
The private endpoint used to reach the identity provider's discovery URL over a private network path.
- Returns:
- The private endpoint used to reach the identity provider's discovery URL over a private network path.
-
hasPrivateEndpointOverrides
public final boolean hasPrivateEndpointOverrides()For responses, this returns true if the service returned a value for the PrivateEndpointOverrides property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
privateEndpointOverrides
Per-domain private endpoint overrides that route specific identity provider domains through distinct private endpoints.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasPrivateEndpointOverrides()method.- Returns:
- Per-domain private endpoint overrides that route specific identity provider domains through distinct private endpoints.
-
toBuilder
Description copied from interface:ToCopyableBuilderTake this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilderin interfaceToCopyableBuilder<CustomJWTAuthorizerConfiguration.Builder,CustomJWTAuthorizerConfiguration> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojoIndicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojoclass, and is generated based on a service model.If an
SdkPojoclass does not have any inherited fields,equalsBySdkFieldsandequalsare essentially the same.- Specified by:
equalsBySdkFieldsin interfaceSdkPojo- Parameters:
obj- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-
sdkFieldNameToField
- Specified by:
sdkFieldNameToFieldin interfaceSdkPojo- Returns:
- The mapping between the field name and its corresponding field.
-