Interface UserCredentialRepository
- All Known Implementing Classes:
InMemoryUserCredentialRepository, JdbcUserCredentialRepository
public interface UserCredentialRepository
Where the passkeys users have registered are kept.
InMemoryUserCredentialRepository keeps them in this process, for a test
or a demonstration; JdbcUserCredentialRepository keeps them in the
server's database. Both do the two things the ceremonies depend on as one
step each, so that two requests at once cannot both pass:
save(CredentialRecord)stores a credential only when no credential has its id, whoever it belongs to;advance(byte[], long, boolean, boolean, long)moves the signature counter forward and never back.
-
Method Summary
Modifier and TypeMethodDescriptionbooleanadvance(byte[] credentialId, long signatureCount, boolean uvInitialized, boolean backupState, long lastUsed) Records a sign-in: the counter the authenticator sent, the flags it sent, and when.booleandelete(byte[] credentialId) Removes a credential.findByCredentialId(byte[] credentialId) The credential with this id, or null.findByUserId(byte[] userEntityUserId) The credentials of the user with this handle, oldest first; empty when they have none.booleansave(CredentialRecord record) Stores a new credential.
-
Method Details
-
save
Stores a new credential.- Returns:
- false, and nothing stored, when a credential with this id is there already -- this user's or another's
-
findByCredentialId
The credential with this id, or null. -
findByUserId
The credentials of the user with this handle, oldest first; empty when they have none. -
advance
boolean advance(byte[] credentialId, long signatureCount, boolean uvInitialized, boolean backupState, long lastUsed) Records a sign-in: the counter the authenticator sent, the flags it sent, and when.
The counter is taken only when it is greater than the one stored -- or when both are zero, which is an authenticator that keeps no counter. One statement decides and stores, so of two requests with the same assertion one is refused.
- Returns:
- false, and nothing changed, when the counter did not advance or the credential is gone
-
delete
boolean delete(byte[] credentialId) Removes a credential.- Returns:
- whether there was one
-