Class TokenBlacklistImplementationValidator

java.lang.Object
com.broadleafcommerce.auth.authorization.security.tokenblacklist.autoconfigure.TokenBlacklistImplementationValidator
All Implemented Interfaces:
org.springframework.beans.factory.SmartInitializingSingleton

public class TokenBlacklistImplementationValidator extends Object implements org.springframework.beans.factory.SmartInitializingSingleton
Validates token blacklisting configuration on startup to prevent silent security downgrades.

This class is designed to address a critical security concern: if an administrator explicitly configures a token blacklisting implementation (such as REDIS or custom configurations, or inadvertently introduces a typo like REDDIS), but the system is missing the necessary runtime dependencies (e.g. spring-boot-starter-data-redis is absent from the classpath), the application would normally start up silently with blacklisting disabled.

To prevent this silent security downgrade, this validator implements SmartInitializingSingleton. After all singleton beans in the application context have been fully instantiated, it checks the configured implementation. If the implementation is any value other than NONE (case-insensitive), this validator verifies that a TokenBlacklistManager bean is actively present in the Spring Application Context. If no manager bean is found, it immediately throws an IllegalStateException, failing fast and preventing the microservice from accepting web traffic in an un-blacklisted state.

Since:
AuthenticationServices 3.0.0, Release Train 3.0.0
See Also:
  • Constructor Details

    • TokenBlacklistImplementationValidator

      public TokenBlacklistImplementationValidator(TokenBlacklistProperties properties, org.springframework.beans.factory.ObjectProvider<TokenBlacklistManager> tokenBlacklistManagerProvider)
  • Method Details

    • afterSingletonsInstantiated

      public void afterSingletonsInstantiated()
      Specified by:
      afterSingletonsInstantiated in interface org.springframework.beans.factory.SmartInitializingSingleton