Class OAuthHttpSecuritySupport

java.lang.Object
org.apache.camel.http.base.OAuthHttpSecuritySupport

public final class OAuthHttpSecuritySupport extends Object
Shared support for HTTP consumers that validate incoming OAuth 2.0 Bearer tokens with a Camel OAuth profile.
Since:
4.21
  • Field Details

  • Constructor Details

    • OAuthHttpSecuritySupport

      public OAuthHttpSecuritySupport(String oauthProfile)
      Creates support that resolves the validation factory lazily through OAuthHelper.
      Parameters:
      oauthProfile - the OAuth profile name
    • OAuthHttpSecuritySupport

      public OAuthHttpSecuritySupport(String oauthProfile, org.apache.camel.spi.OAuthTokenValidationFactory validationFactory)
      Creates support with a pre-resolved validation factory.
      Parameters:
      oauthProfile - the OAuth profile name
      validationFactory - the validation factory, or null to resolve through OAuthHelper
  • Method Details

    • create

      public static OAuthHttpSecuritySupport create(org.apache.camel.CamelContext camelContext, String oauthProfile)
      Creates support for the given profile and validates static profile configuration eagerly.
      Parameters:
      camelContext - the Camel context used to resolve the validation factory
      oauthProfile - the OAuth profile name; null or empty disables OAuth support
      Returns:
      a support instance, or null when no profile is configured
      Throws:
      RuntimeException - if the validation factory cannot be resolved or profile configuration is invalid
    • getOauthProfile

      public String getOauthProfile()
      Gets the OAuth profile name.
      Returns:
      the configured OAuth profile name
    • authenticate

      public boolean authenticate(org.apache.camel.Exchange exchange)
      Validates the current exchange message as an HTTP request and applies the authentication result or rejection response to the exchange.
      Parameters:
      exchange - the exchange to authenticate
      Returns:
      true when the request is authenticated, false when the request was rejected
    • validate

      public OAuthHttpSecuritySupport.Validation validate(org.apache.camel.CamelContext camelContext, String authorization)
      Validates an HTTP Authorization header value.
      Parameters:
      camelContext - the Camel context
      authorization - the raw Authorization header value, or null
      Returns:
      validation state containing either a token validation result or an HTTP rejection status
    • validate

      public OAuthHttpSecuritySupport.Validation validate(org.apache.camel.CamelContext camelContext, Collection<String> authorizations)
      Validates one or more HTTP Authorization header values.
      Parameters:
      camelContext - the Camel context
      authorizations - the raw Authorization header values
      Returns:
      validation state containing either a token validation result or an HTTP rejection status
    • applyAuthenticatedResult

      public static void applyAuthenticatedResult(org.apache.camel.Exchange exchange, org.apache.camel.spi.OAuthTokenValidationResult result)
      Stores an authenticated token validation result on the exchange.
      Parameters:
      exchange - the exchange to update
      result - the authenticated token validation result
    • removeAuthorizationHeader

      public static void removeAuthorizationHeader(org.apache.camel.Message message)
      Removes all Camel message headers named Authorization, ignoring case.
      Parameters:
      message - the message to update
    • reject

      public static void reject(org.apache.camel.Exchange exchange, OAuthHttpSecuritySupport.Validation validation)
      Applies a rejection response and stops route processing.
      Parameters:
      exchange - the exchange to reject
      validation - the failed validation state