Class DefaultUserLoginService

java.lang.Object
com.broadleafcommerce.auth.security.service.DefaultUserLoginService
All Implemented Interfaces:
UserLoginService

public class DefaultUserLoginService extends Object implements UserLoginService
  • Constructor Details

  • Method Details

    • loginUser

      public void loginUser(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, String clientId, String username, String password)
      Description copied from interface: UserLoginService
      Login a user outside of the filter chain
      Specified by:
      loginUser in interface UserLoginService
      Parameters:
      request - The HttpServletRequest that prompted the login request
      response - The HttpServletResponse for the given HttpServletRequest
      clientId - The client id that the user belongs to
      username - The user's username
      password - The user's unencoded password
    • autoLoginInternal

      protected void autoLoginInternal(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, String clientId, String username, String password)
    • blacklistPreviousSessionTokenIfApplicable

      protected void blacklistPreviousSessionTokenIfApplicable(jakarta.servlet.http.HttpServletRequest request, String clientId, OAuth2SessionToken newSessionToken)
      If token blacklisting is enabled, and there is already an active, valid session token found in the request, this method will add the previous session token to the blacklist, preventing its reuse in the future. This ensures that when a user undergoes an auto-login event (e.g., following registration or password reset), only the newly issued value is valid, and the old token is not.
      Parameters:
      request - the HTTP request
      clientId - the client id for which to look up the session cookie
      newSessionToken - the new session token
      Since:
      AuthenticationServices 3.0.0, Release Train 3.0.0
    • getPreviousSessionCookie

      @Nullable protected jakarta.servlet.http.Cookie getPreviousSessionCookie(jakarta.servlet.http.HttpServletRequest request, String clientId)
    • handleUnexpectedTokenBlacklistOperationException

      protected void handleUnexpectedTokenBlacklistOperationException(TokenBlacklistRequest request, TokenBlacklistOperationException exception)
    • getUserDetailsService

      protected OAuth2UserDetailsService getUserDetailsService()
    • getSessionUtil

      protected StatelessUtil getSessionUtil()
    • getTokenBlacklistManager

      protected TokenBlacklistManager getTokenBlacklistManager()
    • setTokenBlacklistManager

      @Autowired(required=false) public void setTokenBlacklistManager(@Nullable TokenBlacklistManager tokenBlacklistManager)
    • getSessionTokenBlacklistUtility

      protected SessionTokenBlacklistUtility getSessionTokenBlacklistUtility()
    • setSessionTokenBlacklistUtility

      @Autowired public void setSessionTokenBlacklistUtility(SessionTokenBlacklistUtility sessionTokenBlacklistUtility)