Uses of Interface
com.broadleafcommerce.auth.user.session.OAuth2SessionToken
Packages that use OAuth2SessionToken
Package
Description
-
Uses of OAuth2SessionToken in com.broadleafcommerce.auth.authorization.security.tokenblacklist.support
Methods in com.broadleafcommerce.auth.authorization.security.tokenblacklist.support with parameters of type OAuth2SessionTokenModifier and TypeMethodDescriptionvoidSessionTokenBlacklistUtility.blacklistPreviousSessionTokenIfApplicable(TokenBlacklistManager blacklistManager, OAuth2SessionToken newSessionToken, Supplier<jakarta.servlet.http.Cookie> previousCookieSupplier, BiConsumer<TokenBlacklistRequest, TokenBlacklistOperationException> exceptionHandler, String loggablePurpose) Orchestrates the blacklisting of a previous, existing session token when a new session token is being issued. -
Uses of OAuth2SessionToken in com.broadleafcommerce.auth.security.service
Methods in com.broadleafcommerce.auth.security.service with parameters of type OAuth2SessionTokenModifier and TypeMethodDescriptionprotected voidDefaultUserLoginService.blacklistPreviousSessionTokenIfApplicable(jakarta.servlet.http.HttpServletRequest request, String clientId, OAuth2SessionToken newSessionToken) If token blacklisting is enabled, and there is already an active, valid session token found in the request, this method will add the previous session token to the blacklist, preventing its reuse in the future. -
Uses of OAuth2SessionToken in com.broadleafcommerce.auth.user.service
Methods in com.broadleafcommerce.auth.user.service that return OAuth2SessionTokenModifier and TypeMethodDescriptionDefaultImpersonationService.getImpersonationSessionToken(ImpersonationRequestToken token, OAuth2UserDetails impersonatedUser) ImpersonationService.getImpersonationSessionToken(ImpersonationRequestToken impersonationRequest, OAuth2UserDetails impersonatedUser) Creates anOAuth2SessionTokenfor the validatedImpersonationRequest.Methods in com.broadleafcommerce.auth.user.service with parameters of type OAuth2SessionTokenModifier and TypeMethodDescriptionprotected voidDefaultSessionAuthenticationStrategy.blacklistPreviousSessionTokenIfApplicable(jakarta.servlet.http.HttpServletRequest request, String sessionCookieName, OAuth2SessionToken newSessionToken) If token blacklisting is enabled, and there is already an active, valid session token found in the request, this method will add the previous session token to the blacklist, preventing its reuse in the future. -
Uses of OAuth2SessionToken in com.broadleafcommerce.auth.user.session
Classes in com.broadleafcommerce.auth.user.session that implement OAuth2SessionTokenModifier and TypeClassDescriptionclassAnOAuth2SessionTokenthat holds the claims within aHashMap.Methods in com.broadleafcommerce.auth.user.session that return OAuth2SessionTokenModifier and TypeMethodDescriptionStatelessUtil.getSessionToken(String clientId, String userId, String subject, Map<String, Object> additionalClaims) Creates aOAuth2SessionTokenfor the provided client ID and subject with the set of additional claims.StatelessUtilImpl.getSessionToken(String clientId, String userId, String subject, Map<String, Object> additionalClaims) OAuth2SessionAuthenticationToken.getToken()The JWT token from the BLSID-[client_id] session cookie.StatelessUtil.refreshSessionToken(OAuth2SessionToken sessionToken) Returns aOAuth2SessionTokenwith a refreshed expiration time.StatelessUtilImpl.refreshSessionToken(OAuth2SessionToken sessionToken) Methods in com.broadleafcommerce.auth.user.session with parameters of type OAuth2SessionTokenModifier and TypeMethodDescriptionjakarta.servlet.http.CookieStatelessUtil.createSessionCookie(OAuth2SessionToken sessionToken) Deprecated.jakarta.servlet.http.CookieStatelessUtilImpl.createSessionCookie(OAuth2SessionToken sessionToken) protected org.springframework.security.core.AuthenticationOAuth2SessionAuthenticationProvider.createSuccessAuthentication(OAuth2UserDetails user, OAuth2SessionToken sessionToken) protected Collection<org.springframework.security.core.GrantedAuthority>OAuth2SessionAuthenticationProvider.getAuthorities(OAuth2UserDetails user, OAuth2SessionToken sessionToken) org.springframework.http.ResponseCookieStatelessUtil.getSessionCookie(OAuth2SessionToken sessionToken) Gets aResponseCookiefor theOAuth2SessionToken.org.springframework.http.ResponseCookieStatelessUtilImpl.getSessionCookie(OAuth2SessionToken sessionToken) protected booleanOAuth2SessionAuthenticationProvider.isSessionTokenFromThirdPartyLogin(OAuth2SessionToken sessionToken) protected OAuth2UserDetailsOAuth2SessionAuthenticationProvider.loadUser(com.nimbusds.jwt.SignedJWT jwt, OAuth2SessionToken sessionToken, String clientId) Loads the appropriateuserfor the request.StatelessUtil.refreshSessionToken(OAuth2SessionToken sessionToken) Returns aOAuth2SessionTokenwith a refreshed expiration time.StatelessUtilImpl.refreshSessionToken(OAuth2SessionToken sessionToken) protected voidOAuth2SessionAuthenticationProvider.validateCredentialsNonExpired(OAuth2UserDetails userDetails, String clientId, OAuth2SessionToken sessionToken) Validate that for the provided session token, the associated user's credentials are not considered expired.protected voidOAuth2SessionAuthenticationProvider.validateUserDetails(OAuth2UserDetails userDetails, String clientId, OAuth2SessionToken sessionToken) Constructors in com.broadleafcommerce.auth.user.session with parameters of type OAuth2SessionTokenModifierConstructorDescriptionDefaultOAuth2SessionToken(OAuth2SessionToken sessionToken) Copy constructor for session token.OAuth2SessionAuthenticationToken(OAuth2SessionToken sessionToken, Collection<? extends org.springframework.security.core.GrantedAuthority> authorities) This constructor should only be used byAuthenticationManagerorAuthenticationProviderimplementations that are satisfied with producing a trusted (i.e.OAuth2SessionAuthenticationToken(OAuth2SessionToken sessionToken, Collection<? extends org.springframework.security.core.GrantedAuthority> authorities, Object principal) This constructor should only be used byAuthenticationManagerorAuthenticationProviderimplementations that are satisfied with producing a trusted (i.e. -
Uses of OAuth2SessionToken in com.broadleafcommerce.auth.user.session.token.enhancer
Methods in com.broadleafcommerce.auth.user.session.token.enhancer that return types with arguments of type OAuth2SessionTokenModifier and TypeMethodDescriptionprotected Optional<OAuth2SessionToken>AbstractUserAccessTokenEnhancer.getSessionToken(org.springframework.security.core.Authentication userPrincipal) Get thesession tokenfrom theauthentication token.protected Optional<OAuth2SessionToken>CurrentUserCacheAccessTokenEnhancer.getSessionToken(org.springframework.security.core.Authentication userPrincipal) Get thesession tokenfrom theauthentication token.TokenEnhancerUtility.getSessionToken(org.springframework.security.core.Authentication userPrincipal) Get thesession tokenfrom theauthentication token. -
Uses of OAuth2SessionToken in com.broadleafcommerce.auth.user.web.endpoint
Methods in com.broadleafcommerce.auth.user.web.endpoint with parameters of type OAuth2SessionTokenModifier and TypeMethodDescriptionprotected voidImpersonationEndpoint.blacklistPreviousSessionTokenIfApplicable(jakarta.servlet.http.HttpServletRequest request, String clientId, OAuth2SessionToken newSessionToken) Intercepts and blacklists any active session token previously stored in the request's cookies before issuing a new impersonation session.
StatelessUtil.getSessionCookie(OAuth2SessionToken)