Class AuthorizationEndpointBase

java.lang.Object
org.keycloak.protocol.AuthorizationEndpointBase
Direct Known Subclasses:
AuthorizationEndpoint, DeviceEndpoint, DockerEndpoint, SamlService

public abstract class AuthorizationEndpointBase extends Object
Common base class for Authorization REST endpoints implementation, which have to be implemented by each protocol.
Author:
Vlastimil Elias (velias at redhat dot com)
  • Field Details

    • APP_INITIATED_FLOW

      public static final String APP_INITIATED_FLOW
      See Also:
    • realm

      protected final org.keycloak.models.RealmModel realm
    • event

      protected final org.keycloak.events.EventBuilder event
    • authManager

      protected AuthenticationManager authManager
    • headers

      protected final jakarta.ws.rs.core.HttpHeaders headers
    • httpRequest

      protected final org.keycloak.http.HttpRequest httpRequest
    • session

      protected final org.keycloak.models.KeycloakSession session
    • clientConnection

      protected final org.keycloak.common.ClientConnection clientConnection
  • Constructor Details

    • AuthorizationEndpointBase

      public AuthorizationEndpointBase(org.keycloak.models.KeycloakSession session, org.keycloak.events.EventBuilder event)
  • Method Details

    • createProcessor

      protected AuthenticationProcessor createProcessor(org.keycloak.sessions.AuthenticationSessionModel authSession, String flowId, String flowPath)
    • handleBrowserAuthenticationRequest

      protected jakarta.ws.rs.core.Response handleBrowserAuthenticationRequest(org.keycloak.sessions.AuthenticationSessionModel authSession, org.keycloak.protocol.LoginProtocol protocol, boolean isPassive, boolean redirectToAuthentication)
      Common method to handle browser authentication request in protocols unified way.
      Parameters:
      authSession - for current request
      protocol - handler for protocol used to initiate login
      isPassive - set to true if login should be passive (without login screen shown)
      redirectToAuthentication - if true redirect to flow url. If initial call to protocol is a POST, you probably want to do this. This is so we can disable the back button on browser
      Returns:
      response to be returned to the browser
    • getAuthenticationFlow

      protected org.keycloak.models.AuthenticationFlowModel getAuthenticationFlow(org.keycloak.sessions.AuthenticationSessionModel authSession)
    • checkSsl

      protected void checkSsl()
    • checkRealm

      protected void checkRealm()
    • createAuthenticationSession

      protected org.keycloak.sessions.AuthenticationSessionModel createAuthenticationSession(org.keycloak.models.ClientModel client, String requestState)