java.lang.Object
com.broadleafcommerce.auth.authorization.security.tokenblacklist.autoconfigure.TokenBlacklistProperties

@ConfigurationProperties("broadleaf.auth.security.token-blacklist-manager") public class TokenBlacklistProperties extends Object
General properties configuring token blacklisting behavior.
Since:
AuthenticationServices 3.0.0, Release Train 3.0.0
  • Constructor Details

    • TokenBlacklistProperties

      public TokenBlacklistProperties()
  • Method Details

    • getImplementation

      public String getImplementation()
      The token blacklisting implementation to use. By default, token blacklisting is disabled.
      See Also:
    • getDefaultSessionTokenBlacklistTtl

      public Duration getDefaultSessionTokenBlacklistTtl()
      In the unlikely event that a session token does not define a SessionTokenClaimKeys.MAX_EXPIRATION_TIME and a reasonable TTL for its blacklist entry cannot be determined, this value drives the default TTL that should be used for its blacklist entry.
    • getSessionTokenBlacklistTtlExpirationBuffer

      public Duration getSessionTokenBlacklistTtlExpirationBuffer()
      Typically, the TTL for a session token blacklist entry would be set to match the time the session token's absolute maximum lifetime would normally expire (since after that maximum expiration, it would naturally be rejected even without blacklisting). This property allows for an additional duration buffer to be added to that TTL, basically ensuring that even after the token would have naturally reached its maximum expiration, the blacklist entry would stick around for some more time.
    • setImplementation

      public void setImplementation(String implementation)
      The token blacklisting implementation to use. By default, token blacklisting is disabled.
      See Also:
    • setDefaultSessionTokenBlacklistTtl

      public void setDefaultSessionTokenBlacklistTtl(Duration defaultSessionTokenBlacklistTtl)
      In the unlikely event that a session token does not define a SessionTokenClaimKeys.MAX_EXPIRATION_TIME and a reasonable TTL for its blacklist entry cannot be determined, this value drives the default TTL that should be used for its blacklist entry.
    • setSessionTokenBlacklistTtlExpirationBuffer

      public void setSessionTokenBlacklistTtlExpirationBuffer(Duration sessionTokenBlacklistTtlExpirationBuffer)
      Typically, the TTL for a session token blacklist entry would be set to match the time the session token's absolute maximum lifetime would normally expire (since after that maximum expiration, it would naturally be rejected even without blacklisting). This property allows for an additional duration buffer to be added to that TTL, basically ensuring that even after the token would have naturally reached its maximum expiration, the blacklist entry would stick around for some more time.
    • equals

      public boolean equals(Object o)
      Overrides:
      equals in class Object
    • canEqual

      protected boolean canEqual(Object other)
    • hashCode

      public int hashCode()
      Overrides:
      hashCode in class Object
    • toString

      public String toString()
      Overrides:
      toString in class Object