Package org.cyclos.impl.access
Class PasswordServiceImpl
- java.lang.Object
-
- org.cyclos.impl.AbstractServerComponent
-
- org.cyclos.impl.AbstractNetworkedServerComponent
-
- org.cyclos.impl.BaseServiceImpl
-
- org.cyclos.impl.access.PasswordServiceImpl
-
- All Implemented Interfaces:
PasswordServiceLocal,PasswordService,Service
@Service public class PasswordServiceImpl extends BaseServiceImpl implements PasswordServiceLocal
Implementation forPasswordService
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description protected classPasswordServiceImpl.CharsetValidation
-
Field Summary
-
Fields inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
authHandler, conversionHandler, customFieldValueHandler, entityManagerHandler, groupsHandler, productsHandler, restBeanPropertyMapping, userLocatorHandler
-
Fields inherited from class org.cyclos.impl.AbstractServerComponent
accountHandler, configurationHandler, dataTranslationHandler, notificationHandler, profileFieldHandler, transactionHandler, translationHandler
-
Fields inherited from interface org.cyclos.services.access.PasswordService
MAX_PASSWORD_LENGTH, MIN_PASSWORD_LENGTH
-
-
Constructor Summary
Constructors Constructor Description PasswordServiceImpl()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description Stringactivate(PasswordTypeVO passwordTypeVO)Activates a password whose mode isPasswordMode.GENERATEDcreating a new password for the current user.voidaddValidations(Property property, BasicUser user, String username, PasswordType passwordType, boolean atRegistration)Adds all password validations according to specified password type.voidallowActivation(PasswordActionDTO params)Allows the given user to activate the given generated and pending passwordvoidblockByTries(Password password)Blocks the given password for exceeding triesvoidchange(ChangePasswordDTO dto)Manually changes a passwordvoidchangeForgottenPassword(ChangeForgottenPasswordDTO dto)Changes a manual password leaving asPasswordStatus.ACTIVE, or if generated, send a new one (leaving asPasswordStatus.ACTIVEorPasswordStatus.RESETwhether the user has the change permission or not)Pair<String,Password>create(BasicUser user, PasswordType passwordType, String value, PasswordStatus status)Creates a password for the given user and password type.voiddisable(PasswordActionDTO params)Disables a password.voidenable(PasswordActionDTO params)Enables a disabled password.booleanexists(BasicUser user, PasswordType type)Returns whether a valid password exists for the given user / password typeForgotPasswordRequestResponseforgotPasswordRequest(ForgotPasswordRequestDTO params)Initiates the forgot password operation, sending a code either by e-mail or SMS to the user.StringgenerateNew(ChangeGeneratedPasswordDTO params)Allows to change a generated password by generating a new oneChangeForgottenPasswordDatagetChangeForgottenPasswordData(@NotNull GetChangeForgottenPasswordDataParams params)Returns data for a forgot password change requestChangePasswordDatagetChangePasswordData(boolean changeSecondaryPassword)Returns data for change the main/secondary access password (manual or generated)UserPasswordsDatagetData(UserLocatorVO locator)Returns data for user passwordsDategetExpirationDate(Password password)Returns the expiration date according to the password's type.Pair<Password,PasswordStatus>getPasswordAndStatus(BasicUser user, PasswordType passwordType)Returns the status and the password record for the given user and password type.PasswordDatagetPasswordData(BasicUser user, PasswordType passwordType)Returns thePasswordDatafor the given user and password type.PasswordDatagetPasswordData(UserLocatorVO locator, PasswordTypeVO passwordTypeVO)Returns data for a given password of the given user.List<PasswordLog>getPasswordLogs(BasicUser user, PasswordType passwordType)Returns the logs for the passwords of the given type and userPropertyAccessgetPropertyAccess(Property<?,?> property, PasswordType passwordType, String value)Returns aPropertyAccessfor a validation suitable for a specific password typePasswordStatusgetRedundantAccessPasswordStatus(BasicUser user, PasswordType type)Returns the redundant password status for the given type.
The redundant statuses are stored directly in the user entity only for the password types set for access (including secondary login)SetSecurityQuestionDatagetSetSecurityQuestionData()Returns data used to set the security questionPair<PasswordStatus,Set<PasswordAction>>getStatusAndActions(BasicUser user, PasswordType passwordType)Similar toPasswordService.getData(org.cyclos.model.users.users.UserLocatorVO), but with fewer data and preventing calculating the status twicebooleanisPendingSecurityQuestion()Returns whether the currently authenticated user needs to set a security questionbooleanisUserCanChangePassword(BasicUser user, PasswordType passwordType)Returns if the given user can change the password for the given typeprotected voidregisterNetworkMappings(NetworkPathRegistry networkPathRegistry)Needs to be overridden by subclasses to register the path up to the networkbooleanremove(BasicUser user, PasswordType passwordType)Removes the password of the given user and typeList<String>requestNewOTP(SendMedium medium, String channel, List<Long> mobilePhones)Generates a new OTP (removing any previous password, if any) and sends it by the specified medium using the confirmation mode configured the given channel for the logged user.List<String>requestNewOTPForSecondaryPassword(SendMedium medium, List<Long> mobilePhones)Same as#requestNewOTP(SendMedium, String)but using the secondary password type configured in the current channel for the logged user.voidreset(PasswordActionDTO params)Resets the given generated password and allow it to be activated againvoidresetAndSend(ResetAndSendPasswordDTO params)Generates a new value of a manual password and send it to the user (for example, via e-mail).voidresetSecurityQuestion(UserLocatorVO locator)Resets the security question, forcing the user to set a new one in the next loginvoidsetSecurityQuestion(BasicUser user, SetSecurityQuestionDTO params)Sets the securiy question for the given uservoidsetSecurityQuestion(SetSecurityQuestionDTO params)Sets the security question's answer for the logged uservoidunblock(PasswordActionDTO params)Unblocks the given user passwordvoidupdateUser(BasicUser user)Update the redundant password status information on the user-
Methods inherited from class org.cyclos.impl.BaseServiceImpl
initializeNetworkMappings
-
Methods inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
canManage, checkManagesUser, checkPermission, checkRelatesToUser, checkValue, clearAlreadyValidated, getBaseEntityManagerHandler, getConfiguration, getLoggedBasicUser, getLoggedUser, getProducts, getTranslatedName, getTranslatedValue, hasPermission, hasValue, inSameNetwork, inSameNetworkOrGlobal, isAdmin, isAlreadyValidated, isBroker, isGlobalAdmin, isGlobalAdminInNetwork, isGuest, isLoggedIn, isMember, isMemberOnly, isNetworkAdmin, isOperator, isRelatedToUser, isSystem, isUserManager, isUserManagerOf, message, message, permission, permission, permissionOptionalValue, permissionOptionalValue, setAlreadyValidated, toDate, toDateTime, validate
-
Methods inherited from class org.cyclos.impl.AbstractServerComponent
dataTranslationProxy, dataTranslationProxy, delete, detach, doDataTranslationProxy, find, flush, from, getApplicationContext, getFormatter, getFormatter, getFormatter, getLogger, getRemoteAddress, getSessionData, mailContentBuilder, message, message, persist, processBatch, processBatch, refresh, remove, selectFrom, subQuery, update
-
-
-
-
Method Detail
-
activate
public String activate(PasswordTypeVO passwordTypeVO) throws FrameworkException, IllegalActionException
Description copied from interface:PasswordServiceActivates a password whose mode isPasswordMode.GENERATEDcreating a new password for the current user.- Specified by:
activatein interfacePasswordService- Throws:
IllegalActionException- When the given password type is not generated, or is not in any of the following statuses:FrameworkException
-
addValidations
public void addValidations(Property property, BasicUser user, String username, PasswordType passwordType, boolean atRegistration)
Description copied from interface:PasswordServiceLocalAdds all password validations according to specified password type.- Specified by:
addValidationsin interfacePasswordServiceLocal
-
allowActivation
public void allowActivation(PasswordActionDTO params) throws FrameworkException, IllegalActionException
Description copied from interface:PasswordServiceAllows the given user to activate the given generated and pending password- Specified by:
allowActivationin interfacePasswordService- Throws:
IllegalActionException- When the given password is not generated / doesn't apply to the given userFrameworkException
-
blockByTries
public void blockByTries(Password password)
Description copied from interface:PasswordServiceLocalBlocks the given password for exceeding tries- Specified by:
blockByTriesin interfacePasswordServiceLocal
-
change
public void change(ChangePasswordDTO dto)
Description copied from interface:PasswordServiceManually changes a password- Specified by:
changein interfacePasswordService
-
changeForgottenPassword
public void changeForgottenPassword(ChangeForgottenPasswordDTO dto) throws FrameworkException, InvalidSecurityAnswerException
Description copied from interface:PasswordServiceChanges a manual password leaving asPasswordStatus.ACTIVE, or if generated, send a new one (leaving asPasswordStatus.ACTIVEorPasswordStatus.RESETwhether the user has the change permission or not)- Specified by:
changeForgottenPasswordin interfacePasswordService- Throws:
FrameworkExceptionInvalidSecurityAnswerException
-
create
public Pair<String,Password> create(BasicUser user, PasswordType passwordType, String value, PasswordStatus status) throws FrameworkException, IllegalActionException
Description copied from interface:PasswordServiceLocalCreates a password for the given user and password type. When the given password is null, a value is generated if status isPasswordStatus.ACTIVE,PasswordStatus.EXPIRED,PasswordStatus.RESET.- Specified by:
createin interfacePasswordServiceLocal- Returns:
- a pair with the plain password value and the Password entity.
- Throws:
IllegalActionException- When the given password type doesn't apply to the given user or the password should be generatedFrameworkException
-
disable
public void disable(PasswordActionDTO params)
Description copied from interface:PasswordServiceDisables a password. A disabled password cannot be used again, unless re-enabled- Specified by:
disablein interfacePasswordService
-
enable
public void enable(PasswordActionDTO params)
Description copied from interface:PasswordServiceEnables a disabled password. A disabled password cannot be used again, unless re-enabled- Specified by:
enablein interfacePasswordService
-
exists
public boolean exists(BasicUser user, PasswordType type)
Description copied from interface:PasswordServiceLocalReturns whether a valid password exists for the given user / password type- Specified by:
existsin interfacePasswordServiceLocal
-
forgotPasswordRequest
public ForgotPasswordRequestResponse forgotPasswordRequest(ForgotPasswordRequestDTO params) throws FrameworkException
Description copied from interface:PasswordServiceInitiates the forgot password operation, sending a code either by e-mail or SMS to the user. May also require a security question verification. Returns the e-mail address of phone numbers the code was sent to. The value will be masked if not the same one as requested in the params.- Specified by:
forgotPasswordRequestin interfacePasswordService- Throws:
FrameworkException
-
generateNew
public String generateNew(ChangeGeneratedPasswordDTO params)
Description copied from interface:PasswordServiceAllows to change a generated password by generating a new one- Specified by:
generateNewin interfacePasswordService
-
getChangeForgottenPasswordData
public ChangeForgottenPasswordData getChangeForgottenPasswordData(@NotNull @NotNull GetChangeForgottenPasswordDataParams params) throws FrameworkException
Description copied from interface:PasswordServiceReturns data for a forgot password change request- Specified by:
getChangeForgottenPasswordDatain interfacePasswordService- Throws:
FrameworkException
-
getChangePasswordData
public ChangePasswordData getChangePasswordData(boolean changeSecondaryPassword) throws FrameworkException
Description copied from interface:PasswordServiceReturns data for change the main/secondary access password (manual or generated)- Specified by:
getChangePasswordDatain interfacePasswordService- Throws:
FrameworkException
-
getData
public UserPasswordsData getData(UserLocatorVO locator)
Description copied from interface:PasswordServiceReturns data for user passwords- Specified by:
getDatain interfacePasswordService
-
getExpirationDate
public Date getExpirationDate(Password password)
Description copied from interface:PasswordServiceLocalReturns the expiration date according to the password's type. Null if the password does not expire.- Specified by:
getExpirationDatein interfacePasswordServiceLocal
-
getPasswordAndStatus
public Pair<Password,PasswordStatus> getPasswordAndStatus(BasicUser user, PasswordType passwordType)
Description copied from interface:PasswordServiceLocalReturns the status and the password record for the given user and password type. The returned status may be different from the one in the password. For example, the password might have never been created (will be null) or there could be one of the calculated statuses, like blocked or expired.- Specified by:
getPasswordAndStatusin interfacePasswordServiceLocal
-
getPasswordData
public PasswordData getPasswordData(BasicUser user, PasswordType passwordType) throws FrameworkException
Description copied from interface:PasswordServiceLocalReturns thePasswordDatafor the given user and password type.- Specified by:
getPasswordDatain interfacePasswordServiceLocal- Throws:
FrameworkException
-
getPasswordData
public PasswordData getPasswordData(UserLocatorVO locator, PasswordTypeVO passwordTypeVO) throws FrameworkException
Description copied from interface:PasswordServiceReturns data for a given password of the given user.- Specified by:
getPasswordDatain interfacePasswordService- Throws:
FrameworkException
-
getPasswordLogs
public List<PasswordLog> getPasswordLogs(BasicUser user, PasswordType passwordType)
Description copied from interface:PasswordServiceLocalReturns the logs for the passwords of the given type and user- Specified by:
getPasswordLogsin interfacePasswordServiceLocal
-
getPropertyAccess
public PropertyAccess getPropertyAccess(Property<?,?> property, PasswordType passwordType, String value)
Description copied from interface:PasswordServiceLocalReturns aPropertyAccessfor a validation suitable for a specific password type- Specified by:
getPropertyAccessin interfacePasswordServiceLocal
-
getRedundantAccessPasswordStatus
public PasswordStatus getRedundantAccessPasswordStatus(BasicUser user, PasswordType type)
Description copied from interface:PasswordServiceLocalReturns the redundant password status for the given type.
The redundant statuses are stored directly in the user entity only for the password types set for access (including secondary login)- Specified by:
getRedundantAccessPasswordStatusin interfacePasswordServiceLocal
-
getSetSecurityQuestionData
public SetSecurityQuestionData getSetSecurityQuestionData() throws FrameworkException
Description copied from interface:PasswordServiceReturns data used to set the security question- Specified by:
getSetSecurityQuestionDatain interfacePasswordService- Throws:
FrameworkException
-
getStatusAndActions
public Pair<PasswordStatus,Set<PasswordAction>> getStatusAndActions(BasicUser user, PasswordType passwordType) throws FrameworkException
Description copied from interface:PasswordServiceLocalSimilar toPasswordService.getData(org.cyclos.model.users.users.UserLocatorVO), but with fewer data and preventing calculating the status twice- Specified by:
getStatusAndActionsin interfacePasswordServiceLocal- Throws:
FrameworkException
-
isPendingSecurityQuestion
public boolean isPendingSecurityQuestion()
Description copied from interface:PasswordServiceLocalReturns whether the currently authenticated user needs to set a security question- Specified by:
isPendingSecurityQuestionin interfacePasswordServiceLocal
-
isUserCanChangePassword
public boolean isUserCanChangePassword(BasicUser user, PasswordType passwordType) throws FrameworkException
Description copied from interface:PasswordServiceLocalReturns if the given user can change the password for the given type- Specified by:
isUserCanChangePasswordin interfacePasswordServiceLocal- Throws:
FrameworkException
-
remove
public boolean remove(BasicUser user, PasswordType passwordType) throws FrameworkException
Description copied from interface:PasswordServiceLocalRemoves the password of the given user and type- Specified by:
removein interfacePasswordServiceLocal- Throws:
FrameworkException
-
requestNewOTP
public List<String> requestNewOTP(SendMedium medium, String channel, List<Long> mobilePhones) throws FrameworkException
Description copied from interface:PasswordServiceGenerates a new OTP (removing any previous password, if any) and sends it by the specified medium using the confirmation mode configured the given channel for the logged user. If the channel is null then it use the current channel.- Specified by:
requestNewOTPin interfacePasswordService- Parameters:
medium- the medium used to send the OTP.channel- the channel used to get the confirmation mode configuration (password type / device)- Returns:
- the email or the normalized phones number the OTP was sent.
- Throws:
SmsSendingException- only if medium isSendMedium.SMSand the OTP could not be sent to any enabled for sms phone.FrameworkException
-
requestNewOTPForSecondaryPassword
public List<String> requestNewOTPForSecondaryPassword(SendMedium medium, List<Long> mobilePhones) throws FrameworkException, SmsSendingException
Description copied from interface:PasswordServiceSame as#requestNewOTP(SendMedium, String)but using the secondary password type configured in the current channel for the logged user.- Specified by:
requestNewOTPForSecondaryPasswordin interfacePasswordService- Throws:
FrameworkExceptionSmsSendingException
-
reset
public void reset(PasswordActionDTO params)
Description copied from interface:PasswordServiceResets the given generated password and allow it to be activated again- Specified by:
resetin interfacePasswordService
-
resetAndSend
public void resetAndSend(ResetAndSendPasswordDTO params)
Description copied from interface:PasswordServiceGenerates a new value of a manual password and send it to the user (for example, via e-mail). If the password is generated, it will be initially active. If it is manual, it will keep the statusPasswordStatus.RESET, forcing the user to change it.- Specified by:
resetAndSendin interfacePasswordService
-
resetSecurityQuestion
public void resetSecurityQuestion(UserLocatorVO locator) throws FrameworkException
Description copied from interface:PasswordServiceResets the security question, forcing the user to set a new one in the next login- Specified by:
resetSecurityQuestionin interfacePasswordService- Throws:
FrameworkException
-
setSecurityQuestion
public void setSecurityQuestion(BasicUser user, SetSecurityQuestionDTO params)
Description copied from interface:PasswordServiceLocalSets the securiy question for the given user- Specified by:
setSecurityQuestionin interfacePasswordServiceLocal
-
setSecurityQuestion
public void setSecurityQuestion(SetSecurityQuestionDTO params) throws FrameworkException
Description copied from interface:PasswordServiceSets the security question's answer for the logged user- Specified by:
setSecurityQuestionin interfacePasswordService- Throws:
FrameworkException
-
unblock
public void unblock(PasswordActionDTO params)
Description copied from interface:PasswordServiceUnblocks the given user password- Specified by:
unblockin interfacePasswordService
-
updateUser
public void updateUser(BasicUser user)
Description copied from interface:PasswordServiceLocalUpdate the redundant password status information on the user- Specified by:
updateUserin interfacePasswordServiceLocal- See Also:
getRedundantAccessPasswordStatus(BasicUser, PasswordType)
-
registerNetworkMappings
protected void registerNetworkMappings(NetworkPathRegistry networkPathRegistry)
Description copied from class:BaseServiceImplNeeds to be overridden by subclasses to register the path up to the network- Specified by:
registerNetworkMappingsin classBaseServiceImpl
-
-