Class AuthenticationServiceImpl
java.lang.Object
org.craftercms.profile.services.impl.AuthenticationServiceImpl
- All Implemented Interfaces:
AuthenticationService
Default implementation of
AuthenticationService.- Author:
- avasquez
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringprotected intprotected intprotected intstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringprotected org.craftercms.commons.security.permissions.PermissionEvaluator<AccessToken, String> protected PersistentLoginRepositoryprotected ProfileServiceprotected TicketRepository -
Constructor Summary
ConstructorsConstructorDescriptionAuthenticationServiceImpl(org.craftercms.commons.security.permissions.PermissionEvaluator<AccessToken, String> permissionEvaluator, TicketRepository ticketRepository, PersistentLoginRepository persistentLoginRepository) -
Method Summary
Modifier and TypeMethodDescriptionauthenticate(String tenantName, String username, String password) Authenticates the user, and returns a ticket identifying the authentication.protected voidcheckIfManageTicketsIsAllowed(String tenantName) protected voidcountAsFail(Profile profile) createPersistentLogin(String profileId) Creates a persistent login, use for remember me functionality.createTicket(String profileId) Create a new ticket for the specified profile.voiddeletePersistentLogin(String loginId) Deletes the persistent login.getPersistentLogin(String loginId) Returns the persistent login object for the given ID.Returns the ticket object for the given ticket ID.voidinvalidateTicket(String ticketId) Invalidates the ticket.protected booleanisProfileInTimeOut(Profile profile) refreshPersistentLoginToken(String loginId) Refreshes the token of the specified persistent login.voidsetFailedLoginAttemptsBeforeDelay(int failedLoginAttemptsBeforeDelay) voidsetFailedLoginAttemptsBeforeLock(int failedLoginAttemptsBeforeLock) voidsetLockTime(int lockTime) voidsetProfileService(ProfileService profileService)
-
Field Details
-
LOG_KEY_AUTHENTICATION_SUCCESSFUL
- See Also:
-
LOG_KEY_TICKET_CREATED
- See Also:
-
LOG_KEY_TICKET_REQUESTED
- See Also:
-
LOG_KEY_TICKET_INVALIDATED
- See Also:
-
LOG_KEY_PERSISTENT_LOGIN_CREATED
- See Also:
-
LOG_KEY_PERSISTENT_LOGIN_TOKEN_REFRESHED
- See Also:
-
LOG_KEY_PERSISTENT_LOGIN_DELETED
- See Also:
-
ERROR_KEY_CREATE_TICKET_ERROR
- See Also:
-
ERROR_KEY_GET_TICKET_ERROR
- See Also:
-
ERROR_KEY_UPDATE_TICKET_ERROR
- See Also:
-
ERROR_KEY_DELETE_TICKET_ERROR
- See Also:
-
ERROR_KEY_CREATE_PERSISTENT_LOGIN_ERROR
- See Also:
-
ERROR_KEY_GET_PERSISTENT_LOGIN_ERROR
- See Also:
-
ERROR_KEY_UPDATE_PERSISTENT_LOGIN_ERROR
- See Also:
-
ERROR_KEY_DELETE_PERSISTENT_LOGIN_ERROR
- See Also:
-
ERROR_KEY_WAIT_IS_ABORTED
- See Also:
-
permissionEvaluator
protected org.craftercms.commons.security.permissions.PermissionEvaluator<AccessToken,String> permissionEvaluator -
ticketRepository
-
persistentLoginRepository
-
profileService
-
lockTime
protected int lockTime -
failedLoginAttemptsBeforeLock
protected int failedLoginAttemptsBeforeLock -
failedLoginAttemptsBeforeDelay
protected int failedLoginAttemptsBeforeDelay
-
-
Constructor Details
-
AuthenticationServiceImpl
public AuthenticationServiceImpl(org.craftercms.commons.security.permissions.PermissionEvaluator<AccessToken, String> permissionEvaluator, TicketRepository ticketRepository, PersistentLoginRepository persistentLoginRepository)
-
-
Method Details
-
setProfileService
-
authenticate
public Ticket authenticate(String tenantName, String username, String password) throws ProfileException Description copied from interface:AuthenticationServiceAuthenticates the user, and returns a ticket identifying the authentication.- Specified by:
authenticatein interfaceAuthenticationService- Parameters:
tenantName- the tenant's nameusername- the usernamepassword- the password- Returns:
- the ticket
- Throws:
ProfileException
-
countAsFail
- Throws:
ProfileException
-
isProfileInTimeOut
-
createTicket
Description copied from interface:AuthenticationServiceCreate a new ticket for the specified profile.Note: this method should only be used when authentication is done through other means (like when authenticating through Facebook or Twitter) different than profile, or when authenticating through a persistent login
- Specified by:
createTicketin interfaceAuthenticationService- Parameters:
profileId- the ID of the profile- Returns:
- the ticket
- Throws:
ProfileException
-
getTicket
Description copied from interface:AuthenticationServiceReturns the ticket object for the given ticket ID.- Specified by:
getTicketin interfaceAuthenticationService- Parameters:
ticketId- the ID of the ticket- Returns:
- the ticket object, or null if no ticket found or ticket has expired
- Throws:
ProfileException
-
invalidateTicket
Description copied from interface:AuthenticationServiceInvalidates the ticket.- Specified by:
invalidateTicketin interfaceAuthenticationService- Parameters:
ticketId- the ID of the ticket to invalidate- Throws:
ProfileException
-
createPersistentLogin
Description copied from interface:AuthenticationServiceCreates a persistent login, use for remember me functionality.- Specified by:
createPersistentLoginin interfaceAuthenticationService- Parameters:
profileId- the ID of the profile- Returns:
- the persistent login
- Throws:
ProfileException
-
getPersistentLogin
Description copied from interface:AuthenticationServiceReturns the persistent login object for the given ID.- Specified by:
getPersistentLoginin interfaceAuthenticationService- Parameters:
loginId- the ID of the login- Returns:
- the persistent login, or null if not found
- Throws:
ProfileException
-
refreshPersistentLoginToken
Description copied from interface:AuthenticationServiceRefreshes the token of the specified persistent login.- Specified by:
refreshPersistentLoginTokenin interfaceAuthenticationService- Parameters:
loginId- the ID of the persistent login- Returns:
- the persistent login with the refreshed token
- Throws:
ProfileException
-
deletePersistentLogin
Description copied from interface:AuthenticationServiceDeletes the persistent login.- Specified by:
deletePersistentLoginin interfaceAuthenticationService- Parameters:
loginId- the ID of the login to invalidate- Throws:
ProfileException
-
checkIfManageTicketsIsAllowed
-
setLockTime
public void setLockTime(int lockTime) -
setFailedLoginAttemptsBeforeLock
public void setFailedLoginAttemptsBeforeLock(int failedLoginAttemptsBeforeLock) -
setFailedLoginAttemptsBeforeDelay
public void setFailedLoginAttemptsBeforeDelay(int failedLoginAttemptsBeforeDelay)
-