A single-use OAuth2 authorisation code issued to a RestApiApp after a profile has approved its access request. The code is generated as a random UUID when the profile authorises the app, handed back to the app on the redirect URI, and exchanged by the app for an access token. It is short lived and one shot: valid() treats it as expired ten minutes after it was created, and as spent once usedDate is set. Note this is the authorisation code itself, not the resulting token or the standing grant.
Group: Database Entities
Implements: Serializable
Properties
| Property | Returns | Description |
|---|---|---|
| code | String | The authorisation code itself, a random UUID given to the app on the redirect and exchanged for a token. Treat it as a secret; it is valid for ten minutes and for one exchange only. |
| createdDate | Date | When the code was issued. The ten minute expiry in valid() is measured from this. |
| id | long | The database-assigned unique identifier for this authorisation. |
| profile | Profile | The profile who approved the app's access request. Any token exchanged for this code acts on their behalf. |
| redirectUri | String | The URI the profile was redirected back to with the code, as supplied by the app when the authorisation was requested. The token exchange is expected to present the same value. |
| restApiApp | RestApiApp | The registered API app the code was issued to. Always set. |
| usedDate | Date | When the code was exchanged for a token. Null while the code is still unspent; once set the code can never be used again. |
Methods
getId()
Returns: long
The database-assigned unique identifier for this authorisation.
getRestApiApp()
Returns: RestApiApp
The registered API app the code was issued to. Always set.
getProfile()
Returns: Profile
The profile who approved the app's access request. Any token exchanged for this code acts on their behalf.
getCode()
Returns: String
The authorisation code itself, a random UUID given to the app on the redirect and exchanged for a token. Treat it as a secret; it is valid for ten minutes and for one exchange only.
getRedirectUri()
Returns: String
The URI the profile was redirected back to with the code, as supplied by the app when the authorisation was requested. The token exchange is expected to present the same value.
getCreatedDate()
Returns: Date
When the code was issued. The ten minute expiry in valid() is measured from this.
getUsedDate()
Returns: Date
When the code was exchanged for a token. Null while the code is still unspent; once set the code can never be used again.
valid(Date now)
Returns: boolean
Checks the code is still usable, ie it was created less than ten minutes before the given time and has not already been exchanged. Call this before honouring a token exchange.
| Parameter | Description |
|---|---|
now | the current date and time to test the expiry against |