Class ClientCredentialsProvider

java.lang.Object
org.fhirfrog.frog.smart.ClientCredentialsProvider
All Implemented Interfaces:
SmartAuthProvider

public final class ClientCredentialsProvider extends Object implements SmartAuthProvider
SmartAuthProvider strategy for the OAuth2 client_credentials grant used by SMART Backend Services clients - a confidential, system-to-system client authenticating with its own client_id/client_secret rather than a user login, the one strategy this package's design explicitly left unbuilt until frog-runner needed to write to a real write-capable FHIR tenant (see fhirfrog/sparked-fhir-server-configuration#95).

Authenticates via HTTP Basic (client_secret_basic, RFC 6749's default method every compliant authorization server must support) rather than posting the secret in the form body - Smile CDR's SMART discovery document doesn't advertise token_endpoint_auth_methods_supported, so this is the safest default rather than a guess specific to one server.

The obtained token is cached and reused across calls, refreshed automatically once it's within EXPIRY_SAFETY_MARGIN of the server-declared expires_in - unlike FormLoginPkceProvider's cache-forever-per-instance approach, since a client-credentials token is meant to be reused for a whole run's worth of requests (potentially minutes) rather than one-shot login flow, and letting it silently expire mid-run would fail every request after that point with a 401.

  • Constructor Details

    • ClientCredentialsProvider

      public ClientCredentialsProvider(String tokenUrl, String clientId, String clientSecret, String scope)
      Parameters:
      tokenUrl - the OAuth2 token endpoint, e.g. https://smile.sparked-fhir.com/aucore/smartauth/oauth/token
      clientId - the confidential client's id
      clientSecret - the confidential client's secret
      scope - space-separated scope string, e.g. system/*.*
  • Method Details

    • obtainAccessToken

      public String obtainAccessToken()
      Description copied from interface: SmartAuthProvider
      Obtain an access token, running whatever flow this strategy implements.
      Specified by:
      obtainAccessToken in interface SmartAuthProvider
      Returns:
      the raw access token string (e.g. a JWT), suitable for use as Authorization: Bearer <token>