Lots of extending and overriding... Seems like a better approach, coming from JS land is to add my logic to the controller where I can read the token and make a HTTPS call to my IDP provider...
@laurspilca I've been reading your new security book and I've a question if you can help me in the right place. I need to validate an oauth token that is sent in the request body due a vendor restriction. What would be the best way to go about it?
Seems like I have to cache the request body (can only be read once?) and then override the get header method where I return the oauth token when the requested header is "Authorization".