DPoPKeyManager

Properties

Link copied to clipboard

RFC 9449 token type string. Canonical casing — compare via isDPoPTokenType since RFC 6749 §5.1 does not mandate casing; servers may return "dpop", "DPoP", or any variant.

Functions

Link copied to clipboard

Idempotently deletes the key pair for alias.

Link copied to clipboard
Link copied to clipboard
fun hasCompleteDPoPCredentials(credentialsIdentifier: String?, tokenType: String?): Boolean

Returns whether the persisted fields required to use tokenType are internally consistent. A DPoP-bound credential must identify the key pair used for its proof; Bearer and transitional credentials do not require that identifier.

Link copied to clipboard

Returns true iff a key pair is already present in the AndroidKeyStore for the given alias. Side-effect-free — does NOT mint a key pair on miss.

Link copied to clipboard
fun hasKeyPairForCredentialsIdentifier(credentialsIdentifier: String?): Boolean

Convenience overload — computes the alias for credentialsIdentifier and calls hasKeyPair.

Link copied to clipboard

Returns true iff tokenType matches "DPoP" case-insensitively (RFC 6749 §5.1). Handles null/empty safely — never returns true for those.

Link copied to clipboard
fun shouldAttachDPoP(credentialsIdentifier: String?, tokenType: String?): Boolean

Decides whether a DPoP proof should be attached to a request for a credential identified by credentialsIdentifier.