/* * Copyright (C) 2008-2022, Juick * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU Affero General Public License as * published by the Free Software Foundation, either version 3 of the * License, or (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU Affero General Public License for more details. * * You should have received a copy of the GNU Affero General Public License * along with this program. If not, see . */ package com.github.scribejava.apis; import io.jsonwebtoken.Jwts; import io.jsonwebtoken.SignatureAlgorithm; import org.tomitribe.churchkey.Key; import java.time.Instant; import java.time.ZoneId; import java.time.ZonedDateTime; import java.util.Date; public record AppleClientSecretGenerator(String subject, String teamId, String keyId, Key signingKey) { public String getClientSecret() { Instant now = Instant.now(); return Jwts.builder() .header() .add("kid", keyId) .and() .issuer(teamId) .audience() .add("https://appleid.apple.com") .and() .issuedAt(Date.from(now)) .subject(subject) .expiration(Date.from(ZonedDateTime.ofInstant(now, ZoneId.of("UTC")).plusMonths(1).toInstant())) .signWith(SignatureAlgorithm.ES256, signingKey.getKey()) .compact(); } public java.security.Key getPublicKey() { return signingKey.getPublicKey().getKey(); } }