Class InMemoryOAuth2AuthorizationService
java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.InMemoryOAuth2AuthorizationService
- All Implemented Interfaces:
OAuth2AuthorizationService
public final class InMemoryOAuth2AuthorizationService
extends Object
implements OAuth2AuthorizationService
Grants kept in this process: gone when it stops, and unknown to any other.
For development, tests and a server that runs as one process and can lose
its refresh tokens on a restart; see
JdbcOAuth2AuthorizationService.-
Nested Class Summary
Nested classes/interfaces inherited from interface OAuth2AuthorizationService
OAuth2AuthorizationService.StoredToken -
Field Summary
Fields inherited from interface OAuth2AuthorizationService
CODE, DEVICE_CODE, REFRESH_TOKEN, USER_CODE -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidRecords a secret issued under a grant.booleanconsumeToken(String kind, String tokenHash, long now) Uses a secret up, if it is there, unused and has not expired atnow, and recordsnowas when.booleanAnswers a device grant that isOAuth2Authorization.PENDING: makes itOAuth2Authorization.ACTIVEforprincipalName, orOAuth2Authorization.DENIED.booleanextendToken(String kind, String tokenHash, long now, long expiresAt) Extends an unused, unexpired token to at leastexpiresAt, atomically.The grant with this id, or null: one that was removed is revoked.What is stored for a secret, whatever its state; null when nothing is.booleanissueTokens(String authorizationId, long now, long expiresAt, String refreshTokenHash, boolean reuse) Issues tokens only while an active, unexpired grant still exists.booleanClaims a polling interval on an unused, unexpired token.intpurgeExpired(long now, int limit) Forgets up tolimitgrants and secrets that expired beforenow.voidRemoves the grant and every secret issued under it.voidsave(OAuth2Authorization authorization) Storesauthorization, in place of the one with its id if there is one.voidtouchToken(String kind, String tokenHash, long now) Records that a secret was presented atnow, without checking its previous timestamp.
-
Constructor Details
-
InMemoryOAuth2AuthorizationService
public InMemoryOAuth2AuthorizationService()
-
-
Method Details
-
save
Description copied from interface:OAuth2AuthorizationServiceStoresauthorization, in place of the one with its id if there is one.- Specified by:
savein interfaceOAuth2AuthorizationService
-
findById
Description copied from interface:OAuth2AuthorizationServiceThe grant with this id, or null: one that was removed is revoked.- Specified by:
findByIdin interfaceOAuth2AuthorizationService
-
remove
Description copied from interface:OAuth2AuthorizationServiceRemoves the grant and every secret issued under it.- Specified by:
removein interfaceOAuth2AuthorizationService
-
addToken
Description copied from interface:OAuth2AuthorizationServiceRecords a secret issued under a grant.- Specified by:
addTokenin interfaceOAuth2AuthorizationService- Parameters:
kind-OAuth2AuthorizationService.CODE,OAuth2AuthorizationService.REFRESH_TOKEN,OAuth2AuthorizationService.DEVICE_CODEorOAuth2AuthorizationService.USER_CODEtokenHash- the SHA-256 of the secretexpiresAt- epoch milliseconds
-
issueTokens
public boolean issueTokens(String authorizationId, long now, long expiresAt, String refreshTokenHash, boolean reuse) Description copied from interface:OAuth2AuthorizationServiceIssues tokens only while an active, unexpired grant still exists. Extending the grant and adding or extending its refresh token must be one atomic operation with respect toOAuth2AuthorizationService.remove(String), including across server processes. A removed grant must never be recreated. Custom stores must implement this operation before issuing user tokens; the default fails closed.- Specified by:
issueTokensin interfaceOAuth2AuthorizationService- Parameters:
refreshTokenHash- null when no refresh token is issuedreuse- whether the hash names an existing unused, unexpired refresh token- Returns:
- false when the grant or reused refresh token is no longer valid
-
findToken
Description copied from interface:OAuth2AuthorizationServiceWhat is stored for a secret, whatever its state; null when nothing is.- Specified by:
findTokenin interfaceOAuth2AuthorizationService
-
consumeToken
Description copied from interface:OAuth2AuthorizationServiceUses a secret up, if it is there, unused and has not expired atnow, and recordsnowas when.- Specified by:
consumeTokenin interfaceOAuth2AuthorizationService- Returns:
- whether THIS call used it up
-
touchToken
Description copied from interface:OAuth2AuthorizationServiceRecords that a secret was presented atnow, without checking its previous timestamp. UseOAuth2AuthorizationService.pollToken(String, String, long, long)to enforce a polling interval.- Specified by:
touchTokenin interfaceOAuth2AuthorizationService
-
pollToken
Description copied from interface:OAuth2AuthorizationServiceClaims a polling interval on an unused, unexpired token. Checking the previous poll and recordingnowmust be one atomic operation, including across processes sharing a database. Rejected polls do not claim an interval. Custom stores must implement this before enabling the device grant.- Specified by:
pollTokenin interfaceOAuth2AuthorizationService- Parameters:
intervalMillis- the minimum time between accepted polls, greater than zero- Returns:
- whether this call claimed the interval
-
extendToken
Description copied from interface:OAuth2AuthorizationServiceExtends an unused, unexpired token to at leastexpiresAt, atomically. Returns false if it is missing, used or expired atnow. Custom stores must implement this before enabling refresh token reuse.- Specified by:
extendTokenin interfaceOAuth2AuthorizationService
-
decide
public boolean decide(String id, boolean approved, String principalName, Map<String, Object> attributes) Description copied from interface:OAuth2AuthorizationServiceAnswers a device grant that isOAuth2Authorization.PENDING: makes itOAuth2Authorization.ACTIVEforprincipalName, orOAuth2Authorization.DENIED.- Specified by:
decidein interfaceOAuth2AuthorizationService- Parameters:
attributes- what to remember of the user who approved, merged into the grant's own- Returns:
- whether THIS call answered it
-
purgeExpired
public int purgeExpired(long now, int limit) Description copied from interface:OAuth2AuthorizationServiceForgets up tolimitgrants and secrets that expired beforenow.- Specified by:
purgeExpiredin interfaceOAuth2AuthorizationService- Returns:
- how many were forgotten
-