Package org.cyclos.security.access
Class LoginServiceSecurity
- java.lang.Object
-
- org.cyclos.impl.AbstractServerComponent
-
- org.cyclos.impl.AbstractNetworkedServerComponent
-
- org.cyclos.security.BaseServiceSecurity
-
- org.cyclos.security.access.LoginServiceSecurity
-
- All Implemented Interfaces:
LoginService,Service
@Security public class LoginServiceSecurity extends BaseServiceSecurity implements LoginService
Security layer forLoginService
-
-
Field Summary
-
Fields inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
authHandler, conversionHandler, customFieldValueHandler, entityManagerHandler, groupsHandler, productsHandler, restBeanPropertyMapping, userLocatorHandler
-
Fields inherited from class org.cyclos.impl.AbstractServerComponent
accountHandler, configurationHandler, dataTranslationHandler, notificationHandler, profileFieldHandler, transactionHandler, translationHandler
-
-
Constructor Summary
Constructors Constructor Description LoginServiceSecurity()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidcheckSecondaryPassword(String password)Validate the secondary password for the logged userUserAuthVOgetAuthenticatedUser()Returns the currently authenticated userLoginDatagetLoginData(String channelName, Long deviceId, PinLocatorVO pinLocator)Returns the data for user login according to the given channel name and based in the current session configuration.PasswordInputDTOgetSecondaryPasswordInput()Returns the input for the secondary password for the logged user.UserLoginResultlogin(LoginDTO params)Creates a session for the currently authenticated user and optionally sets a timeout for it.UserLoginDetailedResultloginUser(UserLoginDTO params)Creates a session for a user, indicating a remote address (from the client connection) a channel and optionally a timeout.
Must be called by administrators with permissions to login other users, and is used when there is a system which relays logins to Cyclos.voidlogout()Invalidates the current user session, if the current request was authenticated with a sessionbooleanlogoutUser(String token)Removes the session with the given token, returning whether the sessions was actually removedStringreplaceSession()Replaces the current session token with another one.protected EntityCheck<?>resolveEntityCheck()Must be implemented in order to return theEntityCheckmanaged by this security component, or null if none-
Methods inherited from class org.cyclos.security.BaseServiceSecurity
checkGuest, checkId, checkIds, checkInternalName, checkLoggedIn, checkManagesUser, checkRelatesToUser, checkScope, checkVO, checkVOs, doInitialize, getEntityCheckRegistry, getUser, initialize
-
Methods inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
canManage, checkManagesUser, checkPermission, checkRelatesToUser, checkValue, clearAlreadyValidated, getBaseEntityManagerHandler, getConfiguration, getLoggedBasicUser, getLoggedUser, getProducts, getTranslatedName, getTranslatedValue, hasPermission, hasValue, inSameNetwork, inSameNetworkOrGlobal, isAdmin, isAlreadyValidated, isBroker, isGlobalAdmin, isGlobalAdminInNetwork, isGuest, isLoggedIn, isMember, isMemberOnly, isNetworkAdmin, isOperator, isRelatedToUser, isSystem, isUserManager, isUserManagerOf, message, message, permission, permission, permissionOptionalValue, permissionOptionalValue, setAlreadyValidated, toDate, toDateTime, validate
-
Methods inherited from class org.cyclos.impl.AbstractServerComponent
dataTranslationProxy, dataTranslationProxy, delete, detach, doDataTranslationProxy, find, flush, from, getApplicationContext, getFormatter, getFormatter, getFormatter, getLogger, getRemoteAddress, getSessionData, mailContentBuilder, message, message, persist, processBatch, processBatch, refresh, remove, selectFrom, subQuery, update
-
-
-
-
Method Detail
-
checkSecondaryPassword
public void checkSecondaryPassword(String password)
Description copied from interface:LoginServiceValidate the secondary password for the logged user- Specified by:
checkSecondaryPasswordin interfaceLoginService
-
getAuthenticatedUser
public UserAuthVO getAuthenticatedUser() throws FrameworkException
Description copied from interface:LoginServiceReturns the currently authenticated user- Specified by:
getAuthenticatedUserin interfaceLoginService- Throws:
FrameworkException
-
getLoginData
public LoginData getLoginData(String channelName, Long deviceId, PinLocatorVO pinLocator)
Description copied from interface:LoginServiceReturns the data for user login according to the given channel name and based in the current session configuration.- Specified by:
getLoginDatain interfaceLoginServicedeviceId- (Optional) A trusted device id can be given to know if it is operative, if so then a pending device confirmation will be created (in a new read-write transaction) and its id returned in the result data. Otherwise no confirmation will be created.pinLocator- (Optional) A device pin locator can be given to know it it is operative
-
getSecondaryPasswordInput
public PasswordInputDTO getSecondaryPasswordInput()
Description copied from interface:LoginServiceReturns the input for the secondary password for the logged user.- Specified by:
getSecondaryPasswordInputin interfaceLoginService
-
login
public UserLoginResult login(LoginDTO params) throws FrameworkException, LoginException, RemoteAddressBlockedException
Description copied from interface:LoginServiceCreates a session for the currently authenticated user and optionally sets a timeout for it. Also, if an identity provider state id is given, and such state exists, the user that performed the login will be linked to that provider- Specified by:
loginin interfaceLoginService- Throws:
FrameworkExceptionLoginExceptionRemoteAddressBlockedException
-
loginUser
public UserLoginDetailedResult loginUser(UserLoginDTO params) throws FrameworkException, LoginException, RemoteAddressBlockedException
Description copied from interface:LoginServiceCreates a session for a user, indicating a remote address (from the client connection) a channel and optionally a timeout.
Must be called by administrators with permissions to login other users, and is used when there is a system which relays logins to Cyclos.- Specified by:
loginUserin interfaceLoginService- Throws:
FrameworkExceptionLoginExceptionRemoteAddressBlockedException
-
logout
public void logout() throws FrameworkExceptionDescription copied from interface:LoginServiceInvalidates the current user session, if the current request was authenticated with a session- Specified by:
logoutin interfaceLoginService- Throws:
FrameworkException
-
logoutUser
public boolean logoutUser(String token) throws FrameworkException
Description copied from interface:LoginServiceRemoves the session with the given token, returning whether the sessions was actually removed- Specified by:
logoutUserin interfaceLoginService- Throws:
FrameworkException
-
replaceSession
public String replaceSession() throws FrameworkException
Description copied from interface:LoginServiceReplaces the current session token with another one. Only works if the current authentication is done via a session. The current session will have a new token generated, and that token is returned. If not connected as a session, will return null.- Specified by:
replaceSessionin interfaceLoginService- Throws:
FrameworkException
-
resolveEntityCheck
protected EntityCheck<?> resolveEntityCheck()
Description copied from class:BaseServiceSecurityMust be implemented in order to return theEntityCheckmanaged by this security component, or null if none- Specified by:
resolveEntityCheckin classBaseServiceSecurity
-
-