Class JdbcUserCredentialRepository
- All Implemented Interfaces:
UserCredentialRepository
Credentials kept in the server's database, in the
cn1_webauthn_credential table of
SecuritySchema.
A row holds nothing secret: a public key verifies and cannot sign.
A credential's id is the table's key through its SHA-256, so that storing one whose id is taken is refused by the key itself, whichever user has it and however many requests try at once. The signature counter is moved by one statement that names the condition it moves under, so the database decides, and of two requests carrying the same assertion one changes no row.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbooleanadvance(byte[] credentialId, long signatureCount, boolean uvInitialized, boolean backupState, long lastUsed) Records a sign-in: the counter the authenticator sent, the flags it sent, and when.booleandelete(byte[] credentialId) Removes a credential.findByCredentialId(byte[] credentialId) The credential with this id, or null.findByUserId(byte[] userEntityUserId) The credentials of the user with this handle, oldest first; empty when they have none.booleansave(CredentialRecord record) Stores a new credential.
-
Constructor Details
-
JdbcUserCredentialRepository
-
-
Method Details
-
save
Description copied from interface:UserCredentialRepositoryStores a new credential.- Specified by:
savein interfaceUserCredentialRepository- Returns:
- false, and nothing stored, when a credential with this id is there already -- this user's or another's
-
findByCredentialId
Description copied from interface:UserCredentialRepositoryThe credential with this id, or null.- Specified by:
findByCredentialIdin interfaceUserCredentialRepository
-
findByUserId
Description copied from interface:UserCredentialRepositoryThe credentials of the user with this handle, oldest first; empty when they have none.- Specified by:
findByUserIdin interfaceUserCredentialRepository
-
advance
public boolean advance(byte[] credentialId, long signatureCount, boolean uvInitialized, boolean backupState, long lastUsed) Description copied from interface:UserCredentialRepositoryRecords a sign-in: the counter the authenticator sent, the flags it sent, and when.
The counter is taken only when it is greater than the one stored -- or when both are zero, which is an authenticator that keeps no counter. One statement decides and stores, so of two requests with the same assertion one is refused.
- Specified by:
advancein interfaceUserCredentialRepository- Returns:
- false, and nothing changed, when the counter did not advance or the credential is gone
-
delete
public boolean delete(byte[] credentialId) Description copied from interface:UserCredentialRepositoryRemoves a credential.- Specified by:
deletein interfaceUserCredentialRepository- Returns:
- whether there was one
-