A single-use OAuth2 authorisation code issued to a RestApiApp after a profile has approved its access request. The code is generated as a random UUID when the profile authorises the app, handed back to the app on the redirect URI, and exchanged by the app for an access token. It is short lived and one shot: valid() treats it as expired ten minutes after it was created, and as spent once usedDate is set. Note this is the authorisation code itself, not the resulting token or the standing grant.

Group: Database Entities

Implements: Serializable


Properties

PropertyReturnsDescription
codeStringThe authorisation code itself, a random UUID given to the app on the redirect and exchanged for a token. Treat it as a secret; it is valid for ten minutes and for one exchange only.
createdDateDateWhen the code was issued. The ten minute expiry in valid() is measured from this.
idlongThe database-assigned unique identifier for this authorisation.
profileProfileThe profile who approved the app's access request. Any token exchanged for this code acts on their behalf.
redirectUriStringThe URI the profile was redirected back to with the code, as supplied by the app when the authorisation was requested. The token exchange is expected to present the same value.
restApiAppRestApiAppThe registered API app the code was issued to. Always set.
usedDateDateWhen the code was exchanged for a token. Null while the code is still unspent; once set the code can never be used again.

Methods

getId()

Returns: long

The database-assigned unique identifier for this authorisation.

getRestApiApp()

Returns: RestApiApp

The registered API app the code was issued to. Always set.

getProfile()

Returns: Profile

The profile who approved the app's access request. Any token exchanged for this code acts on their behalf.

getCode()

Returns: String

The authorisation code itself, a random UUID given to the app on the redirect and exchanged for a token. Treat it as a secret; it is valid for ten minutes and for one exchange only.

getRedirectUri()

Returns: String

The URI the profile was redirected back to with the code, as supplied by the app when the authorisation was requested. The token exchange is expected to present the same value.

getCreatedDate()

Returns: Date

When the code was issued. The ten minute expiry in valid() is measured from this.

getUsedDate()

Returns: Date

When the code was exchanged for a token. Null while the code is still unspent; once set the code can never be used again.

valid(Date now)

Returns: boolean

Checks the code is still usable, ie it was created less than ten minutes before the given time and has not already been exchanged. Call this before honouring a token exchange.

ParameterDescription
nowthe current date and time to test the expiry against
To get full access to the Kademi Hub existing customers can login here, or new customers can register here.