Class TokenBlacklistImplementationValidator
- All Implemented Interfaces:
org.springframework.beans.factory.SmartInitializingSingleton
This class is designed to address a critical security concern: if an administrator explicitly
configures a token blacklisting implementation (such as REDIS or custom configurations,
or inadvertently introduces a typo like REDDIS), but the system is missing the necessary
runtime dependencies (e.g. spring-boot-starter-data-redis is absent from the classpath),
the application would normally start up silently with blacklisting disabled.
To prevent this silent security downgrade, this validator implements
SmartInitializingSingleton. After all singleton beans in the application context have
been fully instantiated, it checks the configured implementation. If the implementation is any
value other than NONE (case-insensitive), this validator verifies that a
TokenBlacklistManager bean is actively present in the Spring Application Context. If no
manager bean is found, it immediately throws an IllegalStateException, failing fast and
preventing the microservice from accepting web traffic in an un-blacklisted state.
- Since:
- AuthenticationServices 3.0.0, Release Train 3.0.0
- See Also:
-
Constructor Summary
ConstructorsConstructorDescriptionTokenBlacklistImplementationValidator(TokenBlacklistProperties properties, org.springframework.beans.factory.ObjectProvider<TokenBlacklistManager> tokenBlacklistManagerProvider) -
Method Summary
-
Constructor Details
-
TokenBlacklistImplementationValidator
public TokenBlacklistImplementationValidator(TokenBlacklistProperties properties, org.springframework.beans.factory.ObjectProvider<TokenBlacklistManager> tokenBlacklistManagerProvider)
-
-
Method Details
-
afterSingletonsInstantiated
public void afterSingletonsInstantiated()- Specified by:
afterSingletonsInstantiatedin interfaceorg.springframework.beans.factory.SmartInitializingSingleton
-