return accessToken;
}
protected SecurityContext createSecurityContext(HttpServletRequest request,
ServerAccessToken token) {
UserSubject endUserSubject = token.getSubject();
UserSubject clientSubject = token.getClient().getSubject();
final UserSubject theSubject =
OAuthRequestFilter.this.useUserSubject ? endUserSubject : clientSubject;
return new SecurityContext() {
public Principal getUserPrincipal() {
return theSubject != null ? new SimplePrincipal(theSubject.getLogin()) : null;
}
public boolean isUserInRole(String role) {
if (theSubject == null) {
return false;
}
return theSubject.getRoles().contains(role);
}
};
}