Class AuthenticationLogoutHandler
java.lang.Object
com.broadleafcommerce.auth.user.web.logout.AuthenticationLogoutHandler
- All Implemented Interfaces:
org.springframework.security.web.authentication.logout.LogoutHandler
public class AuthenticationLogoutHandler
extends Object
implements org.springframework.security.web.authentication.logout.LogoutHandler
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voidblacklistSessionTokenIfApplicable(jakarta.servlet.http.Cookie loginCookie, Map<String, Object> existingSessionCookieClaims, AuthorizedClient client, AuthorizationServer server) If token blacklisting is enabled, this method will add the given session token to the blacklist, preventing its reuse in the future.protected TokenBlacklistRequestbuildTokenBlacklistRequest(String tokenId, Duration ttl, AuthorizedClient client, AuthorizationServer server) protected AuthorizedClientfindClient(String clientId) protected AuthorizationServerfindServer(AuthorizedClient client) protected AuthorizationServerService<AuthorizationServer>protected AuthorizedClientService<AuthorizedClient>protected RememberMeLogoutHandlerDelegateprotected SessionTokenBlacklistUtilityprotected StatelessUtilprotected StringgetStringClaim(String claimName, Map<String, Object> claims) protected TokenBlacklistManagerprotected com.broadleafcommerce.common.extension.TypeFactoryprotected voidhandleUnexpectedTokenBlacklistOperationException(TokenBlacklistRequest request, TokenBlacklistOperationException exception) voidlogout(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, org.springframework.security.core.Authentication authentication) protected voidrevokeOAuth2AuthorizedClientIfApplicable(Map<String, Object> existingSessionCookieClaims, AuthorizedClient authorizedClient, AuthorizationServer authorizationServer) Revokes any 3rd Party IDP Login state, if applicable.voidsetAuthorizationServerService(AuthorizationServerService<AuthorizationServer> authorizationServerService) voidsetAuthorizedClientService(AuthorizedClientService<AuthorizedClient> authorizedClientService) voidsetOAuth2AuthorizedClientEntityService(OAuth2AuthorizedClientEntityService<OAuth2AuthorizedClientEntity> oAuth2AuthorizedClientEntityService) voidsetRememberMeLogoutHandlerDelegate(RememberMeLogoutHandlerDelegate rememberMeLogoutHandlerDelegate) voidsetSessionTokenBlacklistUtility(SessionTokenBlacklistUtility sessionTokenBlacklistUtility) voidsetTokenBlacklistManager(TokenBlacklistManager tokenBlacklistManager) voidsetTypeFactory(com.broadleafcommerce.common.extension.TypeFactory typeFactory)
-
Constructor Details
-
AuthenticationLogoutHandler
-
-
Method Details
-
logout
public void logout(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, org.springframework.security.core.Authentication authentication) - Specified by:
logoutin interfaceorg.springframework.security.web.authentication.logout.LogoutHandler
-
blacklistSessionTokenIfApplicable
protected void blacklistSessionTokenIfApplicable(jakarta.servlet.http.Cookie loginCookie, Map<String, Object> existingSessionCookieClaims, AuthorizedClient client, AuthorizationServer server) If token blacklisting is enabled, this method will add the given session token to the blacklist, preventing its reuse in the future.- Parameters:
loginCookie- the full login cookieexistingSessionCookieClaims- the pre-validated and verified session cookie claims from the session tokenclient- theAuthorizedClientthat this logout is being initiated forserver- theAuthorizationServerunder which theauthorizedClientexists- Since:
- AuthenticationServices 3.0.0, Release Train 3.0.0
-
buildTokenBlacklistRequest
protected TokenBlacklistRequest buildTokenBlacklistRequest(String tokenId, Duration ttl, AuthorizedClient client, AuthorizationServer server) -
handleUnexpectedTokenBlacklistOperationException
protected void handleUnexpectedTokenBlacklistOperationException(TokenBlacklistRequest request, TokenBlacklistOperationException exception) -
revokeOAuth2AuthorizedClientIfApplicable
protected void revokeOAuth2AuthorizedClientIfApplicable(Map<String, Object> existingSessionCookieClaims, AuthorizedClient authorizedClient, AuthorizationServer authorizationServer) Revokes any 3rd Party IDP Login state, if applicable.We cannot use
OAuth2AuthorizedClientRepository.removeAuthorizedClient(String, Authentication, HttpServletRequest, HttpServletResponse), because it typically expects something likeOAuth2LoginAuthenticationTokenas the authentication argument. However, in this logout handler, theAuthenticationwe get will be null since the logout filter does not have any security on it.Thus, we invoke
OAuth2AuthorizedClientEntityServicedirectly with parameters we harvest from other sources.- Parameters:
existingSessionCookieClaims- a map of claims harvested from the existing Broadleaf session cookieauthorizedClient- theAuthorizedClientthat this logout is being initiated forauthorizationServer- theAuthorizationServerunder which theauthorizedClientexists
-
getStringClaim
-
findClient
-
findServer
-
getSessionUtil
-
setOAuth2AuthorizedClientEntityService
@Autowired public void setOAuth2AuthorizedClientEntityService(OAuth2AuthorizedClientEntityService<OAuth2AuthorizedClientEntity> oAuth2AuthorizedClientEntityService) -
getOAuth2AuthorizedClientEntityService
protected OAuth2AuthorizedClientEntityService<OAuth2AuthorizedClientEntity> getOAuth2AuthorizedClientEntityService() -
setAuthorizedClientService
@Autowired public void setAuthorizedClientService(AuthorizedClientService<AuthorizedClient> authorizedClientService) -
getAuthorizedClientService
-
setAuthorizationServerService
@Autowired public void setAuthorizationServerService(AuthorizationServerService<AuthorizationServer> authorizationServerService) -
getAuthorizationServerService
-
setRememberMeLogoutHandlerDelegate
@Autowired(required=false) public void setRememberMeLogoutHandlerDelegate(RememberMeLogoutHandlerDelegate rememberMeLogoutHandlerDelegate) -
getRememberMeLogoutHandlerDelegate
-
setTokenBlacklistManager
@Autowired(required=false) public void setTokenBlacklistManager(TokenBlacklistManager tokenBlacklistManager) -
getTokenBlacklistManager
-
setSessionTokenBlacklistUtility
@Autowired public void setSessionTokenBlacklistUtility(SessionTokenBlacklistUtility sessionTokenBlacklistUtility) -
getSessionTokenBlacklistUtility
-
setTypeFactory
@Autowired public void setTypeFactory(com.broadleafcommerce.common.extension.TypeFactory typeFactory) -
getTypeFactory
protected com.broadleafcommerce.common.extension.TypeFactory getTypeFactory()
-