Interface AuthorizePageHandler

Functional Interface:
This is a functional interface and can therefore be used as the assignment target for a lambda expression or method reference.

@FunctionalInterface public interface AuthorizePageHandler
Pluggable strategy for turning an interactive SMART authorization_endpoint response into the next request that continues EhrLaunchProvider's fullWalk authorization-code flow.

Deliberately narrow: this is not a generic "solve any OAuth login/consent page" abstraction. It only helps for sandboxes already known to be a plain HTML form/auto-approve shape - i.e. it generalizes FormLoginPkceProvider's exact CSRF-scrape-and-POST trick to a second target - not for JS-heavy SPAs or MFA-bearing production IdPs. If a handler can't turn the interactive page into a next request, throw (e.g. SmartAuthException) rather than guessing; fullWalk bounds the number of hops it will follow (EhrLaunchProvider.MAX_AUTHORIZE_REDIRECT_HOPS) so a misbehaving handler can't loop forever.

If fullWalk is called with no handler (null) and the authorize response turns out to be interactive rather than an auto-approve redirect, it fails fast with a SmartAuthException pointing at EhrLaunchProvider.preAuthorizedCode / EhrLaunchProvider.preAuthorizedToken(java.lang.String) instead of hanging or mis-parsing.

  • Method Details

    • handle

      HttpResponse<String> handle(HttpClient client, HttpResponse<String> authorizePageResponse)
      Parameters:
      client - the same cookie-jar-enabled, no-redirect-follow HttpClient the flow is using for every other request in this launch - reuse it so cookies set by the authorize page (e.g. a session cookie) carry through.
      authorizePageResponse - the interactive (typically 200 HTML) response received from GET authorization_endpoint
      Returns:
      the next response to continue following - typically the result of sending a POST request that submits this target's login/consent form