QOAuth2AuthorizationCodeFlow Class
The QOAuth2AuthorizationCodeFlow class provides an implementation of the Authorization Code Grant flow. More...
Header: | #include <QOAuth2AuthorizationCodeFlow> |
CMake: | find_package(Qt6 REQUIRED COMPONENTS NetworkAuth) target_link_libraries(mytarget PRIVATE Qt6::NetworkAuth) |
qmake: | QT += networkauth |
Inherits: | QAbstractOAuth2 |
Public Types
(since 6.8) enum class | PkceMethod { None, Plain, S256 } |
Public Functions
QOAuth2AuthorizationCodeFlow(QObject *parent = nullptr) | |
QOAuth2AuthorizationCodeFlow(QNetworkAccessManager *manager, QObject *parent = nullptr) | |
QOAuth2AuthorizationCodeFlow(const QString &clientIdentifier, QNetworkAccessManager *manager, QObject *parent = nullptr) | |
QOAuth2AuthorizationCodeFlow(const QUrl &authenticateUrl, const QUrl &accessTokenUrl, QNetworkAccessManager *manager, QObject *parent = nullptr) | |
QOAuth2AuthorizationCodeFlow(const QString &clientIdentifier, const QUrl &authenticateUrl, const QUrl &accessTokenUrl, QNetworkAccessManager *manager, QObject *parent = nullptr) | |
virtual | ~QOAuth2AuthorizationCodeFlow() |
(until 6.13) QUrl | accessTokenUrl() const |
(since 6.8) QOAuth2AuthorizationCodeFlow::PkceMethod | pkceMethod() const |
(until 6.13) void | setAccessTokenUrl(const QUrl &accessTokenUrl) |
(since 6.8) void | setPkceMethod(QOAuth2AuthorizationCodeFlow::PkceMethod method, qsizetype length = 43) |
Public Slots
virtual void | grant() override |
(until 6.13) void | refreshAccessToken() |
Protected Functions
QUrl | buildAuthenticateUrl(const QMultiMap<QString, QVariant> ¶meters = {}) |
void | requestAccessToken(const QString &code) |
Reimplemented Protected Functions
virtual void | resourceOwnerAuthorization(const QUrl &url, const QMultiMap<QString, QVariant> ¶meters = {}) override |
Protected Slots
(since 6.9) void | refreshTokensImplementation() |
Detailed Description
This class implements the Authorization Code Grant flow, which is used both to obtain and to refresh access tokens. It is a redirection-based flow so the user will need access to a web browser.
As a redirection-based flow this class requires a proper reply handler to be set. See Qt OAuth2 Overview, QOAuthHttpServerReplyHandler, and QOAuthUriSchemeReplyHandler.
Member Type Documentation
[since 6.8]
enum class QOAuth2AuthorizationCodeFlow::PkceMethod
List of available Proof Key for Code Exchange (PKCE) methods.
PKCE is a security measure to mitigate the risk of authorization code interception attacks. As such it is relevant for OAuth2 "Authorization Code" flow (grant) and in particular with native applications.
PKCE inserts additional parameters into authorization and access token requests. With the help of these parameters the authorization server is able to verify that an access token request originates from the same entity that issued the authorization request.
Constant | Value | Description |
---|---|---|
QOAuth2AuthorizationCodeFlow::PkceMethod::None | 255 | PKCE is not used. |
QOAuth2AuthorizationCodeFlow::PkceMethod::Plain | 1 | The Plain PKCE method is used. Use this only if it is not possible to use S256. With Plain method the code challenge equals to the code verifier. |
QOAuth2AuthorizationCodeFlow::PkceMethod::S256 | 0 | The S256 PKCE method is used. This is the default and the recommended method for native applications. With the S256 method the code challenge is a base64url-encoded value of the SHA-256 of the code verifier. |
This enum was introduced in Qt 6.8.
See also setPkceMethod() and pkceMethod().
Member Function Documentation
[explicit]
QOAuth2AuthorizationCodeFlow::QOAuth2AuthorizationCodeFlow(QObject *parent = nullptr)
Constructs a QOAuth2AuthorizationCodeFlow object with parent object parent.
[explicit]
QOAuth2AuthorizationCodeFlow::QOAuth2AuthorizationCodeFlow(QNetworkAccessManager *manager, QObject *parent = nullptr)
Constructs a QOAuth2AuthorizationCodeFlow object using parent as parent and sets manager as the network access manager.
QOAuth2AuthorizationCodeFlow::QOAuth2AuthorizationCodeFlow(const QString &clientIdentifier, QNetworkAccessManager *manager, QObject *parent = nullptr)
Constructs a QOAuth2AuthorizationCodeFlow object using parent as parent and sets manager as the network access manager. The client identifier is set to clientIdentifier.
QOAuth2AuthorizationCodeFlow::QOAuth2AuthorizationCodeFlow(const QUrl &authenticateUrl, const QUrl &accessTokenUrl, QNetworkAccessManager *manager, QObject *parent = nullptr)
Constructs a QOAuth2AuthorizationCodeFlow object using parent as parent and sets manager as the network access manager. The authenticate URL is set to authenticateUrl and the access token URL is set to accessTokenUrl.
QOAuth2AuthorizationCodeFlow::QOAuth2AuthorizationCodeFlow(const QString &clientIdentifier, const QUrl &authenticateUrl, const QUrl &accessTokenUrl, QNetworkAccessManager *manager, QObject *parent = nullptr)
Constructs a QOAuth2AuthorizationCodeFlow object using parent as parent and sets manager as the network access manager. The client identifier is set to clientIdentifier the authenticate URL is set to authenticateUrl and the access token URL is set to accessTokenUrl.
[virtual noexcept]
QOAuth2AuthorizationCodeFlow::~QOAuth2AuthorizationCodeFlow()
Destroys the QOAuth2AuthorizationCodeFlow instance.
[until 6.13]
QUrl QOAuth2AuthorizationCodeFlow::accessTokenUrl() const
This function is scheduled for deprecation in version 6.13.
Use QAbstractOAuth2::tokenUrl() instead.
Returns the URL used to request the access token.
See also setAccessTokenUrl().
[protected]
QUrl QOAuth2AuthorizationCodeFlow::buildAuthenticateUrl(const QMultiMap<QString, QVariant> ¶meters = {})
Generates an authentication URL to be used in the Authorization Request using parameters.
[override virtual slot]
void QOAuth2AuthorizationCodeFlow::grant()
Reimplements: QAbstractOAuth::grant().
Starts the authentication flow as described in The OAuth 2.0 Authorization Framework
[noexcept, since 6.8]
QOAuth2AuthorizationCodeFlow::PkceMethod QOAuth2AuthorizationCodeFlow::pkceMethod() const
Returns the current PKCE method.
This function was introduced in Qt 6.8.
See also setPkceMethod() and QOAuth2AuthorizationCodeFlow::PkceMethod.
[slot, until 6.13]
void QOAuth2AuthorizationCodeFlow::refreshAccessToken()
This function is scheduled for deprecation in version 6.13.
Use QAbstractOAuth2::refreshTokens() instead.
Call this function to refresh the token.
This function calls refreshTokensImplementation().
[protected slot, since 6.9]
void QOAuth2AuthorizationCodeFlow::refreshTokensImplementation()
This function sends a token refresh request.
If the refresh request was initiated successfully, the status is set to QAbstractOAuth::Status::RefreshingToken; otherwise the requestFailed() signal is emitted and the status is not changed.
This function has no effect if the token refresh process is already in progress.
If refreshing the token fails and an access token exists, the status is set to QAbstractOAuth::Status::Granted, and to QAbstractOAuth::Status::NotAuthenticated if an access token does not exist.
This function was introduced in Qt 6.9.
See also QAbstractOAuth::requestFailed() and QAbstractOAuth2::refreshTokens().
[protected]
void QOAuth2AuthorizationCodeFlow::requestAccessToken(const QString &code)
Requests an access token from the received code. The code is received as a response when the user completes a successful authentication in the browser.
[override virtual protected]
void QOAuth2AuthorizationCodeFlow::resourceOwnerAuthorization(const QUrl &url, const QMultiMap<QString, QVariant> ¶meters = {})
Reimplements: QAbstractOAuth::resourceOwnerAuthorization(const QUrl &url, const QMultiMap<QString, QVariant> ¶meters).
Builds an authentication URL using url and parameters. This function emits an authorizeWithBrowser() signal to require user interaction.
[until 6.13]
void QOAuth2AuthorizationCodeFlow::setAccessTokenUrl(const QUrl &accessTokenUrl)
This function is scheduled for deprecation in version 6.13.
Use QAbstractOAuth2::setTokenUrl() instead.
Sets the URL used to request the access token to accessTokenUrl.
See also accessTokenUrl().
[since 6.8]
void QOAuth2AuthorizationCodeFlow::setPkceMethod(QOAuth2AuthorizationCodeFlow::PkceMethod method, qsizetype length = 43)
Sets the current PKCE method to method.
Optionally, the length parameter can be used to set the length of the code_verifier
. The value must be between 43 and 128 bytes. The 'code verifier' itself is random-generated by the library.
This function was introduced in Qt 6.8.
See also pkceMethod() and QOAuth2AuthorizationCodeFlow::PkceMethod.
© 2025 The Qt Company Ltd. Documentation contributions included herein are the copyrights of their respective owners. The documentation provided herein is licensed under the terms of the GNU Free Documentation License version 1.3 as published by the Free Software Foundation. Qt and respective logos are trademarks of The Qt Company Ltd. in Finland and/or other countries worldwide. All other trademarks are property of their respective owners.