package com.github.jobson.auth.jwt;

import com.fasterxml.jackson.annotation.JsonProperty;
import com.github.jobson.auth.AuthenticationBootstrap;
import com.github.jobson.auth.PermitAllAuthorizer;
import com.github.jobson.config.AuthenticationConfig;
import io.dropwizard.auth.AuthFilter;
import io.jsonwebtoken.SignatureAlgorithm;
import org.hibernate.validator.constraints.NotEmpty;

import javax.crypto.spec.SecretKeySpec;
import javax.validation.constraints.NotNull;
import java.security.Key;
import java.security.Principal;
import java.util.Base64;

public final class JsonWebTokenConfig implements AuthenticationConfig {

    private String secretKey;  // Base64 string

     * @deprecated Used by JSON deserializer.
    public JsonWebTokenConfig() {}

    public JsonWebTokenConfig(String secretKey) {
        this.secretKey = secretKey;

    public String getSecretKey() {
        return secretKey;

    public SignatureAlgorithm getSignatureAlgorithm() {
        return SignatureAlgorithm.HS512;

    public AuthFilter<?, Principal> createAuthFilter(AuthenticationBootstrap bootstrap) {
        final byte[] decodedSecretKey = Base64.getDecoder().decode(secretKey);
        final Key secretKeyKey = new SecretKeySpec(decodedSecretKey, 0, decodedSecretKey.length, this.getSignatureAlgorithm().toString());

        return new JsonWebTokenAuthFilter.Builder<>()
                .setAuthenticator(new JsonWebTokenAuthenticator(secretKeyKey, this.getSignatureAlgorithm()))
                .setAuthorizer(new PermitAllAuthorizer())