2 * ========================LICENSE_START=================================
5 * Copyright (C) 2023 Nordix Foundation
7 * Licensed under the Apache License, Version 2.0 (the "License");
8 * you may not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
11 * http://www.apache.org/licenses/LICENSE-2.0
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS,
15 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
18 * ========================LICENSE_END===================================
21 package org.oran.pmproducer.oauth2;
23 import java.util.Base64;
24 import java.util.HashSet;
26 import lombok.ToString;
27 import org.apache.kafka.common.security.oauthbearer.OAuthBearerToken;
28 import org.oran.pmproducer.exceptions.ServiceException;
30 public class OAuthBearerTokenJwt implements OAuthBearerToken {
31 private static final com.google.gson.Gson gson = new com.google.gson.GsonBuilder().disableHtmlEscaping().create();
33 private final String jwtTokenRaw;
34 private final JwtTokenBody tokenBody;
37 private static class JwtTokenBody {
38 String sub = ""; // principalName
39 long exp = 0; // expirationTime
40 long iat = 0; // startTime
44 public static OAuthBearerTokenJwt create(String tokenRaw)
45 throws ServiceException {
46 String[] chunks = tokenRaw.split("\\.");
47 Base64.Decoder decoder = Base64.getUrlDecoder();
48 if (chunks.length < 2) {
49 throw new ServiceException("Could not parse JWT token: " + tokenRaw);
52 String payloadStr = new String(decoder.decode(chunks[1]));
53 JwtTokenBody token = gson.fromJson(payloadStr, JwtTokenBody.class);
54 return new OAuthBearerTokenJwt(token, tokenRaw);
57 private OAuthBearerTokenJwt(JwtTokenBody jwtTokenBody, String accessToken) {
59 this.jwtTokenRaw = accessToken;
60 this.tokenBody = jwtTokenBody;
64 public String value() {
69 public Set<String> scope() {
70 Set<String> res = new HashSet<>();
71 if (!this.tokenBody.scope.isEmpty()) {
72 res.add(this.tokenBody.scope);
78 public long lifetimeMs() {
79 if (this.tokenBody.exp == 0) {
80 return Long.MAX_VALUE;
82 return this.tokenBody.exp * 1000;
86 public String principalName() {
87 return this.tokenBody.sub;
91 public Long startTimeMs() {
92 return this.tokenBody.iat;