Class DefaultApiKeyService<P extends ApiKey>

java.lang.Object
com.broadleafcommerce.data.tracking.core.service.BaseMappableCrudEntityService<P>
com.broadleafcommerce.data.tracking.core.service.BaseRsqlMappableCrudEntityService<P>
com.broadleafcommerce.auth.server.service.apikey.DefaultApiKeyService<P>
Type Parameters:
P - the business domain type
All Implemented Interfaces:
ApiKeyService<P>, com.broadleafcommerce.data.tracking.core.service.MappableCrudEntityService<P>, com.broadleafcommerce.data.tracking.core.service.RsqlMappableCrudEntityService<P>

public class DefaultApiKeyService<P extends ApiKey> extends com.broadleafcommerce.data.tracking.core.service.BaseRsqlMappableCrudEntityService<P> implements ApiKeyService<P>
Default implementation of ApiKeyService.
See Also:
  • Constructor Details

  • Method Details

    • readByHashedKey

      public Optional<P> readByHashedKey(String hashedKey)
      Description copied from interface: ApiKeyService
      Finds an API key by its hashed value.
      Specified by:
      readByHashedKey in interface ApiKeyService<P extends ApiKey>
      Parameters:
      hashedKey - the hashed key
      Returns:
      an Optional containing the API key if found, or empty otherwise
    • readAllByAuthorizedClientId

      public org.springframework.data.domain.Page<P> readAllByAuthorizedClientId(String authorizedClientId, org.springframework.data.domain.Pageable pageable, cz.jirutka.rsql.parser.ast.Node filters, boolean validateClientAccessibility)
      Description copied from interface: ApiKeyService
      Retrieves all API keys belonging to the specified client.
      Specified by:
      readAllByAuthorizedClientId in interface ApiKeyService<P extends ApiKey>
      Parameters:
      authorizedClientId - the AuthorizedClient.getId()
      pageable - the pagination parameters
      filters - additional filters used to restrict results. Cannot be null - use EmptyNode if no additional filters should be applied.
      validateClientAccessibility - whether to perform authentication context and tenant checks
      Returns:
      a page of API keys
    • internalReadAllByAuthorizedClientId

      public org.springframework.data.domain.Page<P> internalReadAllByAuthorizedClientId(String authorizedClientId, org.springframework.data.domain.Pageable pageable, cz.jirutka.rsql.parser.ast.Node filters)
      Description copied from interface: ApiKeyService

      This method is intended for internal system usage in trusted flows, and bypasses the standard client existence/accessibility validations from the external-facing ApiKeyService.readAllByAuthorizedClientId(String, Pageable, Node, boolean).

      Retrieves all API keys belonging to the specified client.

      Specified by:
      internalReadAllByAuthorizedClientId in interface ApiKeyService<P extends ApiKey>
      Parameters:
      authorizedClientId - the AuthorizedClient.getId()
      pageable - the pagination parameters
      filters - additional filters used to restrict results. Cannot be null - use EmptyNode if no additional filters should be applied.
      Returns:
      a page of API keys
    • readByAuthorizedClientIdAndApiKeyId

      public P readByAuthorizedClientIdAndApiKeyId(String authorizedClientId, String id, boolean validateClientAccessibility)
      Description copied from interface: ApiKeyService
      Retrieves a specific API key belonging to the specified client.
      Specified by:
      readByAuthorizedClientIdAndApiKeyId in interface ApiKeyService<P extends ApiKey>
      Parameters:
      authorizedClientId - the AuthorizedClient.getId()
      id - the API key ID
      validateClientAccessibility - whether to perform authentication context and tenant checks
      Returns:
      the API key
    • createApiKey

      public ApiKeyCreateResponse createApiKey(String authorizedClientId, ApiKeyCreateRequest request, boolean validateClientAccessibility)
      Description copied from interface: ApiKeyService
      Creates a new API key for the given client.
      Specified by:
      createApiKey in interface ApiKeyService<P extends ApiKey>
      Parameters:
      authorizedClientId - the AuthorizedClient.getId()
      request - the create request containing configuration
      validateClientAccessibility - whether to perform authentication context and tenant checks
      Returns:
      the create response containing the one-time plaintext key
    • buildApiKey

      protected P buildApiKey(String authorizedClientId, ApiKeyCreateRequest request, ApiKeyGenerationResult genResult)
    • buildApiKeyCreateResponse

      protected ApiKeyCreateResponse buildApiKeyCreateResponse(P savedKey, ApiKeyGenerationResult genResult)
    • updateApiKey

      public P updateApiKey(String authorizedClientId, String id, ApiKeyUpdateRequest request, boolean validateClientAccessibility)
      Description copied from interface: ApiKeyService
      Updates an existing API key.
      Specified by:
      updateApiKey in interface ApiKeyService<P extends ApiKey>
      Parameters:
      authorizedClientId - the AuthorizedClient.getId()
      id - the API key ID
      request - the update request containing the updated fields
      validateClientAccessibility - whether to perform authentication context and tenant checks
      Returns:
      the updated API key
    • mapUpdatesToApiKey

      protected void mapUpdatesToApiKey(P existing, ApiKeyUpdateRequest request)
    • deleteApiKey

      public void deleteApiKey(String authorizedClientId, String id, boolean validateClientAccessibility)
      Description copied from interface: ApiKeyService
      Deletes an API key.
      Specified by:
      deleteApiKey in interface ApiKeyService<P extends ApiKey>
      Parameters:
      authorizedClientId - the AuthorizedClient.getId()
      id - the API key ID
      validateClientAccessibility - whether to perform authentication context and tenant checks
    • findByIdAndAuthorizedClientId

      protected P findByIdAndAuthorizedClientId(String id, String authorizedClientId)
    • buildApiKeyGenerationRequest

      protected ApiKeyGenerationRequest buildApiKeyGenerationRequest(AuthorizedClient client)
    • getClientAndValidateAccess

      protected AuthorizedClient getClientAndValidateAccess(String authorizedClientId, boolean validateClientAccessibility)
    • validateClientAccessibility

      protected void validateClientAccessibility(AuthorizedClient targetClient, AuthorizationServer targetServer)
    • getRepository

      protected ApiKeyRepository<com.broadleafcommerce.data.tracking.core.Identifiable> getRepository()
      Overrides:
      getRepository in class com.broadleafcommerce.data.tracking.core.service.BaseMappableCrudEntityService<P extends ApiKey>
    • getAuthorizedClientService

      protected AuthorizedClientService<AuthorizedClient> getAuthorizedClientService()
    • getAuthorizationServerService

      protected AuthorizationServerService<AuthorizationServer> getAuthorizationServerService()
    • getApiKeyGenerator

      protected ApiKeyGenerator getApiKeyGenerator()
    • getTypeFactory

      protected com.broadleafcommerce.common.extension.TypeFactory getTypeFactory()
    • getAuthenticationUtils

      protected com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils getAuthenticationUtils()