Interface AuthorizePageHandler
- Functional Interface:
- This is a functional interface and can therefore be used as the assignment target for a lambda expression or method reference.
authorization_endpoint
response into the next request that continues EhrLaunchProvider's
fullWalk authorization-code flow.
Deliberately narrow: this is not a generic "solve any OAuth login/consent
page" abstraction. It only helps for sandboxes already known to be a plain HTML
form/auto-approve shape - i.e. it generalizes FormLoginPkceProvider's exact
CSRF-scrape-and-POST trick to a second target - not for JS-heavy SPAs or MFA-bearing
production IdPs. If a handler can't turn the interactive page into a next request, throw
(e.g. SmartAuthException) rather than guessing; fullWalk bounds the
number of hops it will follow (EhrLaunchProvider.MAX_AUTHORIZE_REDIRECT_HOPS) so
a misbehaving handler can't loop forever.
If fullWalk is called with no handler (null) and the authorize response
turns out to be interactive rather than an auto-approve redirect, it fails fast with a
SmartAuthException pointing at EhrLaunchProvider.preAuthorizedCode /
EhrLaunchProvider.preAuthorizedToken(java.lang.String) instead of hanging or mis-parsing.
-
Method Summary
Modifier and TypeMethodDescriptionhandle(HttpClient client, HttpResponse<String> authorizePageResponse)
-
Method Details
-
handle
- Parameters:
client- the same cookie-jar-enabled, no-redirect-followHttpClientthe flow is using for every other request in this launch - reuse it so cookies set by the authorize page (e.g. a session cookie) carry through.authorizePageResponse- the interactive (typically200HTML) response received fromGET authorization_endpoint- Returns:
- the next response to continue following - typically the result of sending a POST request that submits this target's login/consent form
-