Class ImpersonationEndpoint

java.lang.Object
com.broadleafcommerce.auth.user.web.endpoint.ImpersonationEndpoint

@FrameworkController public class ImpersonationEndpoint extends Object
Author:
Nick Crum (ncrum)
  • Field Details

  • Constructor Details

  • Method Details

    • impersonate

      @FrameworkGetMapping("/impersonate") @PreAuthorize("isAuthenticated() and hasAuthority(\'ALL_IMPERSONATE\')") public String impersonate(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, ImpersonationRequest impersonationRequest, org.springframework.security.core.Authentication authentication)
    • impersonateSelf

      @FrameworkGetMapping(value="/impersonate", params="impersonate_self=true") @PreAuthorize("isAuthenticated() and hasAuthority(\'ALL_IMPERSONATE\')") public String impersonateSelf(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, ImpersonationRequest impersonationRequest, org.springframework.security.core.Authentication authentication)
    • consumeToken

      @FrameworkGetMapping("/consume-token") public org.springframework.web.servlet.ModelAndView consumeToken(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, @RequestParam("signedJwt") String token)
    • getUserToImpersonate

      protected OAuth2UserDetails getUserToImpersonate(String clientId, String username)
    • getCsrUser

      protected OAuth2UserDetails getCsrUser(String clientId, String csrId)
    • loadAnonymousCsrUser

      protected OAuth2UserDetails loadAnonymousCsrUser(String clientId)
    • addSessionCookie

      protected void addSessionCookie(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, ImpersonationRequestToken impersonationRequest, OAuth2UserDetails impersonatedUser)
    • blacklistPreviousSessionTokenIfApplicable

      protected void blacklistPreviousSessionTokenIfApplicable(jakarta.servlet.http.HttpServletRequest request, String clientId, OAuth2SessionToken newSessionToken)
      Intercepts and blacklists any active session token previously stored in the request's cookies before issuing a new impersonation session. If token blacklisting is enabled, and there is already an active, valid session token found in the request, this method will add the previous session token to the blacklist, preventing its reuse in the future. This ensures that when a user starts a new impersonation session, only the newly issued value is valid, and the old token is not.
      Parameters:
      request - the HTTP request
      clientId - the client id for which to look up the session cookie
      newSessionToken - the new session token
      Since:
      AuthenticationServices 3.0.0, Release Train 3.0.0
    • getPreviousSessionCookie

      @Nullable protected jakarta.servlet.http.Cookie getPreviousSessionCookie(jakarta.servlet.http.HttpServletRequest request, String clientId)
    • handleUnexpectedTokenBlacklistOperationException

      protected void handleUnexpectedTokenBlacklistOperationException(TokenBlacklistRequest request, TokenBlacklistOperationException exception)
    • getCsrUserId

      protected String getCsrUserId(org.springframework.security.core.Authentication authentication)
    • getTokenBlacklistManager

      protected TokenBlacklistManager getTokenBlacklistManager()
    • setTokenBlacklistManager

      @Autowired(required=false) public void setTokenBlacklistManager(@Nullable TokenBlacklistManager tokenBlacklistManager)
    • getSessionTokenBlacklistUtility

      protected SessionTokenBlacklistUtility getSessionTokenBlacklistUtility()
    • setSessionTokenBlacklistUtility

      @Autowired public void setSessionTokenBlacklistUtility(SessionTokenBlacklistUtility sessionTokenBlacklistUtility)