Class SessionTokenBlacklistUtility
java.lang.Object
com.broadleafcommerce.auth.authorization.security.tokenblacklist.support.SessionTokenBlacklistUtility
Shared utility for session token blacklisting operations, consolidating TTL calculation logic.
- Since:
- AuthenticationServices 3.0.0, Release Train 3.0.0
-
Constructor Summary
ConstructorsConstructorDescriptionSessionTokenBlacklistUtility(TokenBlacklistProperties properties, StatelessUtil statelessUtil, com.broadleafcommerce.common.extension.TypeFactory typeFactory) -
Method Summary
Modifier and TypeMethodDescriptionvoidblacklistPreviousSessionTokenIfApplicable(TokenBlacklistManager blacklistManager, OAuth2SessionToken newSessionToken, Supplier<jakarta.servlet.http.Cookie> previousCookieSupplier, BiConsumer<TokenBlacklistRequest, TokenBlacklistOperationException> exceptionHandler, String loggablePurpose) Orchestrates the blacklisting of a previous, existing session token when a new session token is being issued.protected TokenBlacklistRequestbuildTokenBlacklistRequest(String tokenId, Duration ttl) determineSessionTokenBlacklistEntryTtl(Map<String, Object> sessionTokenClaims) Determines the appropriate TTL for a session token blacklist entry based on its maximum expiration claim.protected DategetMaxExpirationTimeClaim(Map<String, Object> claims) SinceSessionTokenClaimKeys.MAX_EXPIRATION_TIMEcan be either aDateorNumber, we need to mimic the behavior ofJWTClaimsSet.getDateClaim(String)to handle both scenarios.protected TokenBlacklistPropertiesprotected StatelessUtilprotected com.broadleafcommerce.common.extension.TypeFactoryverifyAndExtractClaims(String tokenValue) Quietly verifies and extracts the claims from the given session token value.
-
Constructor Details
-
SessionTokenBlacklistUtility
public SessionTokenBlacklistUtility(TokenBlacklistProperties properties, StatelessUtil statelessUtil, com.broadleafcommerce.common.extension.TypeFactory typeFactory)
-
-
Method Details
-
determineSessionTokenBlacklistEntryTtl
Determines the appropriate TTL for a session token blacklist entry based on its maximum expiration claim.- Parameters:
sessionTokenClaims- the session token claims containing the maximum expiration time- Returns:
- the calculated Duration TTL
-
getMaxExpirationTimeClaim
SinceSessionTokenClaimKeys.MAX_EXPIRATION_TIMEcan be either aDateorNumber, we need to mimic the behavior ofJWTClaimsSet.getDateClaim(String)to handle both scenarios.- Parameters:
claims- the session token claims- Returns:
- the max expiration time claim value if available
-
blacklistPreviousSessionTokenIfApplicable
public void blacklistPreviousSessionTokenIfApplicable(@Nullable TokenBlacklistManager blacklistManager, OAuth2SessionToken newSessionToken, Supplier<jakarta.servlet.http.Cookie> previousCookieSupplier, BiConsumer<TokenBlacklistRequest, TokenBlacklistOperationException> exceptionHandler, String loggablePurpose) Orchestrates the blacklisting of a previous, existing session token when a new session token is being issued. This flow ensures that if a previous session cookie is already present (ex: during a new login, auto-login, or impersonation event), the old session is properly blacklisted to prevent reuse.
Delegates context-specific exception handling back to the caller via functional interfaces to preserve exact semantic parity and customization.
- Parameters:
blacklistManager- the token blacklist manager to usenewSessionToken- the newly issued session tokenpreviousCookieSupplier- supplier for the previous session cookieexceptionHandler- consumer to handle unexpected operations exceptionsloggablePurpose- hint indicating the flow invoking this method (e.g., "new login", "auto-login", "impersonation")
-
verifyAndExtractClaims
Quietly verifies and extracts the claims from the given session token value.- Parameters:
tokenValue- the token value to verify and extract claims from- Returns:
- null if the token verification failed, else return the claims if token verification succeeded
-
buildTokenBlacklistRequest
-
getProperties
-
getStatelessUtil
-
getTypeFactory
protected com.broadleafcommerce.common.extension.TypeFactory getTypeFactory()
-