Interface RefreshTokenProvider

All Superinterfaces:
Provider
All Known Implementing Classes:
AbstractRefreshTokenProvider, DefaultRefreshTokenProvider, OID4VCIRefreshTokenProvider

public interface RefreshTokenProvider extends Provider
Provider responsible for verification of refresh tokens and issuing of new refresh tokens
  • Method Details

    • supports

      boolean supports(InitialRefreshTokenContext initialRefreshTokenCtx)
      Method is triggered during initial issuance of refresh token - usually after successful user authentication.
      Parameters:
      initialRefreshTokenCtx - context information with the data useful to determine if this provider can be used to generate refresh token
      Returns:
      true if this provider can be used to generate refresh token. In this case method generateRefreshToken(InitialRefreshTokenContext) would be used for this provider to generate new refresh token. Keycloak iterates over available providers to determine which one can be used. Providers are sorted by their priority (based on the "order" of particular ProviderFactory)
    • generateRefreshToken

      RefreshToken generateRefreshToken(InitialRefreshTokenContext initialRefreshTokenCtx) throws RefreshTokenException
      Method is triggered during initial issuance of refresh token - usually after successful user authentication. Refresh token is generated by single provider, which was first available provider returned by method supports(InitialRefreshTokenContext)
      Parameters:
      initialRefreshTokenCtx - context information with the data useful to determine
      Returns:
      newly generated refresh token
      Throws:
      RefreshTokenException - in case of some issues during refresh token generation
    • supports

      boolean supports(RefreshTokenContext ctx)
      Invoked during refresh-token request.
      Parameters:
      ctx - Context, which contains old refresh token and some other data
      Returns:
      True if this provider supports verification of the refresh token from the context
    • refreshAccessToken

      Invoked during refresh-token request. Implements verifications related to old refresh token and creates token-response if all the verifications are successful
      Parameters:
      ctx - Context, which contains old refresh token and some other data
      Returns:
      successful token-response with new tokens and data, which would be returned in the successful token response
      Throws:
      OAuthErrorException - In case that validation failed or some other issue happened during token refresh
    • close

      default void close()
      Specified by:
      close in interface Provider