Interface Authentication

All Known Implementing Classes:
AbstractAuthenticationToken, AnonymousAuthenticationToken, ApiKeyAuthenticationToken, BearerTokenAuthenticationToken, JwtAuthenticationToken, OAuth2AuthenticationToken, RememberMeAuthenticationToken, UsernamePasswordAuthenticationToken, WebAuthnAuthentication

public interface Authentication

Who a request is from: a credential presented for checking, or -- once an AuthenticationManager has accepted it -- the principal and what it may do.

A controller receives the current one by declaring a parameter of this type; anywhere else it is SecurityContextHolder.getContext().getAuthentication().

  • Method Details

    • getAuthorities

      Collection<? extends GrantedAuthority> getAuthorities()
      What the principal has been granted; empty before authentication.
    • getCredentials

      Object getCredentials()
      What proves the principal is who it says: a password, usually, and null once it has been checked.
    • getDetails

      Object getDetails()
      Anything else the mechanism recorded about the request, or null.
    • getPrincipal

      Object getPrincipal()
      The identity: a username before authentication, and afterwards usually the UserDetails it was resolved to.
    • isAuthenticated

      boolean isAuthenticated()
      Whether this has been accepted. A token a client merely presented is not.
    • setAuthenticated

      void setAuthenticated(boolean isAuthenticated)
      Marks the token trusted or not. Implementations refuse true from outside: a trusted token is made by a constructor that says so.
    • getName

      String getName()
      The principal's name.