Object
se.curity.identityserver.sdk.data.authorization.ScopeValue

public final class ScopeValue extends Object
A ScopeValue is a resolved scope, i.e. a scope that got matched against an existing ScopeConfig from a profile or client.

Usually, an OAuth request will include a list of scopes in the form a whitespace-separated String. Those scopes need to be checked against those allowed by the OAuth profile and the current client making the request... this is done via a ScopeMap (code in the OAuth module), which knows how to check whether the requested scopes exist in the configuration.

Each configuration scope is represented by a ScopeConfig instance. Because every instance of ScopeValue is normally obtained by matching against a ScopeValue, all ScopeValues keep a reference to the actual ScopeConfig that it matched against, which can be used later to find more information about the configured scope (e.g. to display scope description in the consent page).

Since:
4.0.0
  • Constructor Details

  • Method Details

    • getTimeToLive

      public Optional<Duration> getTimeToLive()
      Returns:
      the scope time-to-live, or empty if the scope should never expire within a token.
    • exposeInMetadata

      public boolean exposeInMetadata()
      Returns:
      whether the scope may be exposed in the server's metadata
    • getName

      public String getName()
      Returns:
      the name of the scope.
    • getScopeConfig

      public ScopeConfig getScopeConfig()
    • getDescription

      public String getDescription()
      Returns:
      the description of the scope.
    • getProperties

      public Map<String,String> getProperties()
      Returns:
      the properties of this scope.
    • getClaimNames

      public Set<String> getClaimNames()
      Returns:
      the names of the claims associated with this scope.
    • isRequired

      public boolean isRequired()
      Returns:
      whether this scope is a required scope.
    • isConsentable

      public boolean isConsentable()
      Returns:
      true if this is a consentable scope.
      Since:
      4.1.0
      See Also:
    • isExpired

      public @io.curity.java_to_ts_docs.annotations.TypescriptDocs("@returns `true` if this scope has a TTL and has expired.") boolean isExpired(Instant createdAt, Instant now)
      Parameters:
      createdAt -
      now -
      Returns:
      true if this scope has a TTL and has expired
      Since:
      4.1.0
    • isPrefix

      public boolean isPrefix()
      Check if this scope is a prefix scope.
      Returns:
      whether this scope is a prefix scope
      Since:
      6.3.0
    • getSuffix

      @Nullable public @Nullable String getSuffix()
      Gets the suffix of this scope.
      Returns:
      the scope suffix, or null if this scope isn't a prefix scope
      Since:
      6.3.0
    • equals

      public boolean equals(Object other)
      Overrides:
      equals in class Object
    • hashCode

      public int hashCode()
      Overrides:
      hashCode in class Object
    • toString

      public String toString()
      Overrides:
      toString in class Object