java.lang.Object
com.broadleafcommerce.auth.authorization.security.tokenblacklist.support.SessionTokenBlacklistUtility

public class SessionTokenBlacklistUtility extends Object
Shared utility for session token blacklisting operations, consolidating TTL calculation logic.
Since:
AuthenticationServices 3.0.0, Release Train 3.0.0
  • Constructor Details

    • SessionTokenBlacklistUtility

      public SessionTokenBlacklistUtility(TokenBlacklistProperties properties, StatelessUtil statelessUtil, com.broadleafcommerce.common.extension.TypeFactory typeFactory)
  • Method Details

    • determineSessionTokenBlacklistEntryTtl

      public Duration determineSessionTokenBlacklistEntryTtl(Map<String,Object> sessionTokenClaims)
      Determines the appropriate TTL for a session token blacklist entry based on its maximum expiration claim.
      Parameters:
      sessionTokenClaims - the session token claims containing the maximum expiration time
      Returns:
      the calculated Duration TTL
    • getMaxExpirationTimeClaim

      @Nullable protected Date getMaxExpirationTimeClaim(Map<String,Object> claims)
      Since SessionTokenClaimKeys.MAX_EXPIRATION_TIME can be either a Date or Number, we need to mimic the behavior of JWTClaimsSet.getDateClaim(String) to handle both scenarios.
      Parameters:
      claims - the session token claims
      Returns:
      the max expiration time claim value if available
    • blacklistPreviousSessionTokenIfApplicable

      public void blacklistPreviousSessionTokenIfApplicable(@Nullable TokenBlacklistManager blacklistManager, OAuth2SessionToken newSessionToken, Supplier<jakarta.servlet.http.Cookie> previousCookieSupplier, BiConsumer<TokenBlacklistRequest,TokenBlacklistOperationException> exceptionHandler, String loggablePurpose)

      Orchestrates the blacklisting of a previous, existing session token when a new session token is being issued. This flow ensures that if a previous session cookie is already present (ex: during a new login, auto-login, or impersonation event), the old session is properly blacklisted to prevent reuse.

      Delegates context-specific exception handling back to the caller via functional interfaces to preserve exact semantic parity and customization.

      Parameters:
      blacklistManager - the token blacklist manager to use
      newSessionToken - the newly issued session token
      previousCookieSupplier - supplier for the previous session cookie
      exceptionHandler - consumer to handle unexpected operations exceptions
      loggablePurpose - hint indicating the flow invoking this method (e.g., "new login", "auto-login", "impersonation")
    • verifyAndExtractClaims

      @Nullable protected Map<String,Object> verifyAndExtractClaims(String tokenValue)
      Quietly verifies and extracts the claims from the given session token value.
      Parameters:
      tokenValue - the token value to verify and extract claims from
      Returns:
      null if the token verification failed, else return the claims if token verification succeeded
    • buildTokenBlacklistRequest

      protected TokenBlacklistRequest buildTokenBlacklistRequest(String tokenId, Duration ttl)
    • getProperties

      protected TokenBlacklistProperties getProperties()
    • getStatelessUtil

      protected StatelessUtil getStatelessUtil()
    • getTypeFactory

      protected com.broadleafcommerce.common.extension.TypeFactory getTypeFactory()