Class DefaultUserLoginService
java.lang.Object
com.broadleafcommerce.auth.security.service.DefaultUserLoginService
- All Implemented Interfaces:
UserLoginService
-
Constructor Summary
ConstructorsConstructorDescriptionDefaultUserLoginService(OAuth2UserDetailsService userDetailsService, StatelessUtil sessionUtil) -
Method Summary
Modifier and TypeMethodDescriptionprotected voidautoLoginInternal(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, String clientId, String username, String password) protected voidblacklistPreviousSessionTokenIfApplicable(jakarta.servlet.http.HttpServletRequest request, String clientId, OAuth2SessionToken newSessionToken) If token blacklisting is enabled, and there is already an active, valid session token found in the request, this method will add the previous session token to the blacklist, preventing its reuse in the future.protected jakarta.servlet.http.CookiegetPreviousSessionCookie(jakarta.servlet.http.HttpServletRequest request, String clientId) protected SessionTokenBlacklistUtilityprotected StatelessUtilprotected TokenBlacklistManagerprotected OAuth2UserDetailsServiceprotected voidhandleUnexpectedTokenBlacklistOperationException(TokenBlacklistRequest request, TokenBlacklistOperationException exception) voidloginUser(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, String clientId, String username, String password) Login a user outside of the filter chainvoidsetSessionTokenBlacklistUtility(SessionTokenBlacklistUtility sessionTokenBlacklistUtility) voidsetTokenBlacklistManager(TokenBlacklistManager tokenBlacklistManager)
-
Constructor Details
-
DefaultUserLoginService
public DefaultUserLoginService(OAuth2UserDetailsService userDetailsService, StatelessUtil sessionUtil)
-
-
Method Details
-
loginUser
public void loginUser(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, String clientId, String username, String password) Description copied from interface:UserLoginServiceLogin a user outside of the filter chain- Specified by:
loginUserin interfaceUserLoginService- Parameters:
request- TheHttpServletRequestthat prompted the login requestresponse- TheHttpServletResponsefor the givenHttpServletRequestclientId- The client id that the user belongs tousername- The user's usernamepassword- The user's unencoded password
-
autoLoginInternal
-
blacklistPreviousSessionTokenIfApplicable
protected void blacklistPreviousSessionTokenIfApplicable(jakarta.servlet.http.HttpServletRequest request, String clientId, OAuth2SessionToken newSessionToken) If token blacklisting is enabled, and there is already an active, valid session token found in the request, this method will add the previous session token to the blacklist, preventing its reuse in the future. This ensures that when a user undergoes an auto-login event (e.g., following registration or password reset), only the newly issued value is valid, and the old token is not.- Parameters:
request- the HTTP requestclientId- the client id for which to look up the session cookienewSessionToken- the new session token- Since:
- AuthenticationServices 3.0.0, Release Train 3.0.0
-
getPreviousSessionCookie
@Nullable protected jakarta.servlet.http.Cookie getPreviousSessionCookie(jakarta.servlet.http.HttpServletRequest request, String clientId) -
handleUnexpectedTokenBlacklistOperationException
protected void handleUnexpectedTokenBlacklistOperationException(TokenBlacklistRequest request, TokenBlacklistOperationException exception) -
getUserDetailsService
-
getSessionUtil
-
getTokenBlacklistManager
-
setTokenBlacklistManager
@Autowired(required=false) public void setTokenBlacklistManager(@Nullable TokenBlacklistManager tokenBlacklistManager) -
getSessionTokenBlacklistUtility
-
setSessionTokenBlacklistUtility
@Autowired public void setSessionTokenBlacklistUtility(SessionTokenBlacklistUtility sessionTokenBlacklistUtility)
-