Class HttpSessionSecurityContextRepository
- All Implemented Interfaces:
SecurityContextRepository
Keeps who is signed in in the HTTP session, under
SPRING_SECURITY_CONTEXT_KEY.
What is stored is a map of plain values -- the name, the authorities, whether
the authentication is trusted, and its details when they are plain values
too -- rather than the Authentication itself. The database session store
keeps what JSON can write and hands it to whichever server takes the
client's next request, so an object would not survive the trip, and a
server whose sessions are in memory behaves the same way so that moving
to the database changes nothing.
The consequence: on a later request the principal is a
User rebuilt from the name and authorities, with no password, not the
object the user store returned at sign-in.
A way of signing in whose authentication is a kind of its own -- a user of
another identity provider, a passkey -- keeps that kind through an
AuthenticationCodec, which its configurer registers with
HttpSecurity.authenticationCodec(AuthenticationCodec); see there. A subclass that needs
something else again overrides toMap(Authentication) and fromMap(Map).
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe session attribute the context is stored under. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidAdds a codec; seeAuthenticationCodec.booleancontainsContext(HttpServer.Request request) Whether anything is stored forrequest's client.protected AuthenticationThe authenticationtoMap(Authentication)stored, or null whenstoredis not one.loadContext(HttpServer.Request request) The context stored forrequest's client; an empty one when there is none.voidsaveContext(SecurityContext context, HttpServer.Request request) Storescontextfor the client's later requests.voidsetAllowSessionCreation(boolean allowSessionCreation) Whether saving may start a session; true unless changed.toMap(Authentication authentication) authenticationas the plain values a session store can keep.
-
Field Details
-
SPRING_SECURITY_CONTEXT_KEY
The session attribute the context is stored under.- See Also:
-
-
Constructor Details
-
HttpSessionSecurityContextRepository
public HttpSessionSecurityContextRepository()
-
-
Method Details
-
addAuthenticationCodec
Adds a codec; seeAuthenticationCodec. One of a kind that is here already replaces it. -
setAllowSessionCreation
public void setAllowSessionCreation(boolean allowSessionCreation) Whether saving may start a session; true unless changed. A chain withSessionCreationPolicy.NEVERturns it off. -
loadContext
Description copied from interface:SecurityContextRepositoryThe context stored forrequest's client; an empty one when there is none.- Specified by:
loadContextin interfaceSecurityContextRepository
-
saveContext
Description copied from interface:SecurityContextRepositoryStorescontextfor the client's later requests. An empty context, or an anonymous one, removes what was stored.- Specified by:
saveContextin interfaceSecurityContextRepository
-
containsContext
Description copied from interface:SecurityContextRepositoryWhether anything is stored forrequest's client.- Specified by:
containsContextin interfaceSecurityContextRepository
-
toMap
authenticationas the plain values a session store can keep. -
fromMap
The authenticationtoMap(Authentication)stored, or null whenstoredis not one.
-