Class AuthenticationLogoutHandler

java.lang.Object
com.broadleafcommerce.auth.user.web.logout.AuthenticationLogoutHandler
All Implemented Interfaces:
org.springframework.security.web.authentication.logout.LogoutHandler

public class AuthenticationLogoutHandler extends Object implements org.springframework.security.web.authentication.logout.LogoutHandler
  • Constructor Details

    • AuthenticationLogoutHandler

      public AuthenticationLogoutHandler(StatelessUtil sessionUtil)
  • Method Details

    • logout

      public void logout(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, org.springframework.security.core.Authentication authentication)
      Specified by:
      logout in interface org.springframework.security.web.authentication.logout.LogoutHandler
    • blacklistSessionTokenIfApplicable

      protected void blacklistSessionTokenIfApplicable(jakarta.servlet.http.Cookie loginCookie, Map<String,Object> existingSessionCookieClaims, AuthorizedClient client, AuthorizationServer server)
      If token blacklisting is enabled, this method will add the given session token to the blacklist, preventing its reuse in the future.
      Parameters:
      loginCookie - the full login cookie
      existingSessionCookieClaims - the pre-validated and verified session cookie claims from the session token
      client - the AuthorizedClient that this logout is being initiated for
      server - the AuthorizationServer under which the authorizedClient exists
      Since:
      AuthenticationServices 3.0.0, Release Train 3.0.0
    • buildTokenBlacklistRequest

      protected TokenBlacklistRequest buildTokenBlacklistRequest(String tokenId, Duration ttl, AuthorizedClient client, AuthorizationServer server)
    • handleUnexpectedTokenBlacklistOperationException

      protected void handleUnexpectedTokenBlacklistOperationException(TokenBlacklistRequest request, TokenBlacklistOperationException exception)
    • revokeOAuth2AuthorizedClientIfApplicable

      protected void revokeOAuth2AuthorizedClientIfApplicable(Map<String,Object> existingSessionCookieClaims, AuthorizedClient authorizedClient, AuthorizationServer authorizationServer)
      Revokes any 3rd Party IDP Login state, if applicable.

      We cannot use OAuth2AuthorizedClientRepository.removeAuthorizedClient(String, Authentication, HttpServletRequest, HttpServletResponse), because it typically expects something like OAuth2LoginAuthenticationToken as the authentication argument. However, in this logout handler, the Authentication we get will be null since the logout filter does not have any security on it.

      Thus, we invoke OAuth2AuthorizedClientEntityService directly with parameters we harvest from other sources.

      Parameters:
      existingSessionCookieClaims - a map of claims harvested from the existing Broadleaf session cookie
      authorizedClient - the AuthorizedClient that this logout is being initiated for
      authorizationServer - the AuthorizationServer under which the authorizedClient exists
    • getStringClaim

      @Nullable protected String getStringClaim(String claimName, Map<String,Object> claims)
    • findClient

      protected AuthorizedClient findClient(String clientId)
    • findServer

      protected AuthorizationServer findServer(AuthorizedClient client)
    • getSessionUtil

      protected StatelessUtil getSessionUtil()
    • setOAuth2AuthorizedClientEntityService

      @Autowired public void setOAuth2AuthorizedClientEntityService(OAuth2AuthorizedClientEntityService<OAuth2AuthorizedClientEntity> oAuth2AuthorizedClientEntityService)
    • getOAuth2AuthorizedClientEntityService

      protected OAuth2AuthorizedClientEntityService<OAuth2AuthorizedClientEntity> getOAuth2AuthorizedClientEntityService()
    • setAuthorizedClientService

      @Autowired public void setAuthorizedClientService(AuthorizedClientService<AuthorizedClient> authorizedClientService)
    • getAuthorizedClientService

      protected AuthorizedClientService<AuthorizedClient> getAuthorizedClientService()
    • setAuthorizationServerService

      @Autowired public void setAuthorizationServerService(AuthorizationServerService<AuthorizationServer> authorizationServerService)
    • getAuthorizationServerService

      protected AuthorizationServerService<AuthorizationServer> getAuthorizationServerService()
    • setRememberMeLogoutHandlerDelegate

      @Autowired(required=false) public void setRememberMeLogoutHandlerDelegate(RememberMeLogoutHandlerDelegate rememberMeLogoutHandlerDelegate)
    • getRememberMeLogoutHandlerDelegate

      @Nullable protected RememberMeLogoutHandlerDelegate getRememberMeLogoutHandlerDelegate()
    • setTokenBlacklistManager

      @Autowired(required=false) public void setTokenBlacklistManager(TokenBlacklistManager tokenBlacklistManager)
    • getTokenBlacklistManager

      @Nullable protected TokenBlacklistManager getTokenBlacklistManager()
    • setSessionTokenBlacklistUtility

      @Autowired public void setSessionTokenBlacklistUtility(SessionTokenBlacklistUtility sessionTokenBlacklistUtility)
    • getSessionTokenBlacklistUtility

      protected SessionTokenBlacklistUtility getSessionTokenBlacklistUtility()
    • setTypeFactory

      @Autowired public void setTypeFactory(com.broadleafcommerce.common.extension.TypeFactory typeFactory)
    • getTypeFactory

      protected com.broadleafcommerce.common.extension.TypeFactory getTypeFactory()