Class ClientCredentialsProvider
- All Implemented Interfaces:
SmartAuthProvider
SmartAuthProvider strategy for the OAuth2 client_credentials grant used by
SMART Backend Services clients - a confidential, system-to-system client authenticating with
its own client_id/client_secret rather than a user login, the one strategy
this package's design explicitly left unbuilt until frog-runner needed to write to a real
write-capable FHIR tenant (see fhirfrog/sparked-fhir-server-configuration#95).
Authenticates via HTTP Basic (client_secret_basic, RFC 6749's default method every
compliant authorization server must support) rather than posting the secret in the form body -
Smile CDR's SMART discovery document doesn't advertise
token_endpoint_auth_methods_supported, so this is the safest default rather than a
guess specific to one server.
The obtained token is cached and reused across calls, refreshed automatically once it's
within EXPIRY_SAFETY_MARGIN of the server-declared expires_in - unlike FormLoginPkceProvider's cache-forever-per-instance approach, since a client-credentials token
is meant to be reused for a whole run's worth of requests (potentially minutes) rather than
one-shot login flow, and letting it silently expire mid-run would fail every request after
that point with a 401.
-
Constructor Summary
ConstructorsConstructorDescriptionClientCredentialsProvider(String tokenUrl, String clientId, String clientSecret, String scope) -
Method Summary
Modifier and TypeMethodDescriptionObtain an access token, running whatever flow this strategy implements.Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.fhirfrog.frog.smart.SmartAuthProvider
asRequestInterceptor, launchContext
-
Constructor Details
-
ClientCredentialsProvider
public ClientCredentialsProvider(String tokenUrl, String clientId, String clientSecret, String scope) - Parameters:
tokenUrl- the OAuth2 token endpoint, e.g.https://smile.sparked-fhir.com/aucore/smartauth/oauth/tokenclientId- the confidential client's idclientSecret- the confidential client's secretscope- space-separated scope string, e.g.system/*.*
-
-
Method Details
-
obtainAccessToken
Description copied from interface:SmartAuthProviderObtain an access token, running whatever flow this strategy implements.- Specified by:
obtainAccessTokenin interfaceSmartAuthProvider- Returns:
- the raw access token string (e.g. a JWT), suitable for use as
Authorization: Bearer <token>
-