public interface PasswordHandler
| Modifier and Type | Field and Description |
|---|---|
static java.lang.String |
ATTR_PASSWORD
Script attribute: the password value to check
|
static java.lang.String |
ATTR_PASSWORD_TYPE
Script attribute: the password type being checked
|
static java.lang.String |
ATTR_USER
Script attribute: the user to check password
|
| Modifier and Type | Method and Description |
|---|---|
org.cyclos.impl.access.CredentialAccessor |
accessor(@NotNull CredentialUsage usage)
Return a new
CredentialAccessor for the given (required) credential usage. |
void |
checkPassword(org.cyclos.impl.system.ChannelAccessAccessor channelAccess,
CredentialUsage usage,
org.cyclos.impl.access.UserPrincipal userPrincipal,
CreateDeviceConfirmationParams params,
boolean allowExpired,
java.lang.String password)
Checks the password / device confirmation for the given configuration, usage and user identification (i.e
UserPrincipal). |
void |
checkPassword(PasswordType passwordType,
BasicUser user,
boolean forLogin,
java.lang.String password)
Use with caution: this method doesn't take into account the trusted devices.
|
java.lang.String |
encode(BasicUser user,
PasswordType passwordType,
java.lang.String value)
Encodes the password according to its type
|
PasswordInputDTO |
getPasswordInput(org.cyclos.impl.system.ChannelAccessAccessor channelAccessAccessor,
CredentialUsage usage,
BasicUser basicUser)
Returns the password input information for the given user, usage and channel configuration.
|
java.util.Map<PasswordType,java.lang.Boolean> |
getPasswordTypesAtRegistration(Group group,
UserRegistration registration,
PasswordMode mode)
Returns a map of
PasswordType marked to be saved at registration for the specified group and registration
type, and a flag indicating if the password type is also used for access. |
void |
ignoreNextConfirmationPasswords()
Sets the current transaction to ignore confirmation passwords from this point onwards
|
boolean |
matches(Password password,
java.lang.String plainPassword)
Returns whether the given plain password matches the stored password
|
void |
notifyPasswordStatusChanged(PasswordType type,
BasicUser user,
PasswordStatus status)
Notifies the user that a password has changed its status
|
PinInputDTO |
toPinInput(org.cyclos.impl.system.ChannelAccessAccessor channelAccess)
Returns a
PinInputDTO compatible with the given channel access |
boolean |
wasConfirmationPasswordCheckedwithDevice()
Returns true if the confirmation password (
CredentialUsage.CONFIRMATION) was already checked and also if
the check was made with a trusted device. |
static final java.lang.String ATTR_USER
static final java.lang.String ATTR_PASSWORD_TYPE
static final java.lang.String ATTR_PASSWORD
org.cyclos.impl.access.CredentialAccessor accessor(@NotNull
@NotNull CredentialUsage usage)
CredentialAccessor for the given (required) credential usage.void checkPassword(org.cyclos.impl.system.ChannelAccessAccessor channelAccess,
CredentialUsage usage,
org.cyclos.impl.access.UserPrincipal userPrincipal,
CreateDeviceConfirmationParams params,
boolean allowExpired,
java.lang.String password)
throws PasswordException
UserPrincipal).CreateDeviceConfirmationParams object is required only when the password value represents a
device confirmation. In that case it's used to make sure that the operation the user confirmed is the same for
which the password is being checked for.PasswordExceptionvoid checkPassword(PasswordType passwordType, BasicUser user, boolean forLogin, java.lang.String password) throws PasswordException
accessor(CredentialUsage) or
#checkPassword(ChannelConfiguration, CredentialUsage, BasicUser, CreateDeviceConfirmationParams, boolean, String)PasswordExceptionjava.lang.String encode(BasicUser user, PasswordType passwordType, java.lang.String value)
PasswordInputDTO getPasswordInput(org.cyclos.impl.system.ChannelAccessAccessor channelAccessAccessor, CredentialUsage usage, BasicUser basicUser)
java.util.Map<PasswordType,java.lang.Boolean> getPasswordTypesAtRegistration(Group group, UserRegistration registration, PasswordMode mode)
PasswordType marked to be saved at registration for the specified group and registration
type, and a flag indicating if the password type is also used for access.group - the group the user will be registeredregistration - if UserRegistration.PUBLIC then it will read from the group's product. Otherwise it
will read from the logged user's products.mode - a filter (Optional) Only PasswordMode.MANUAL and PasswordMode.GENERATED are
supported.void ignoreNextConfirmationPasswords()
boolean matches(Password password, java.lang.String plainPassword)
void notifyPasswordStatusChanged(PasswordType type, BasicUser user, PasswordStatus status)
PinInputDTO toPinInput(org.cyclos.impl.system.ChannelAccessAccessor channelAccess)
PinInputDTO compatible with the given channel accessboolean wasConfirmationPasswordCheckedwithDevice()
CredentialUsage.CONFIRMATION) was already checked and also if
the check was made with a trusted device.