Package io.jans.as.server.service
Class SessionIdService
- java.lang.Object
-
- io.jans.as.server.service.SessionIdService
-
@RequestScoped @Named public class SessionIdService extends java.lang.Object
- Version:
- December 8, 2018
- Author:
- Yuriy Zabrovarnyy, Yuriy Movchan, Javier Rojas Blum
-
-
Field Summary
Fields Modifier and Type Field Description static java.lang.String
OP_BROWSER_STATE
static java.lang.String
SESSION_CUSTOM_STATE
-
Constructor Summary
Constructors Constructor Description SessionIdService()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description java.util.List<java.lang.String>
acrValuesList(java.lang.String acrValues)
By definition we expects space separated acr values as it is defined in spec.SessionId
assertAuthenticatedSessionCorrespondsToNewRequest(SessionId session, java.lang.String acrValuesStr)
java.lang.String
computeSessionState(SessionId sessionId, java.lang.String clientId, java.lang.String redirectUri)
void
externalEvent(SessionEvent event)
java.util.List<SessionId>
findByUser(java.lang.String userDn)
SessionId
generateAuthenticatedSessionId(javax.servlet.http.HttpServletRequest httpRequest, java.lang.String userDn)
SessionId
generateAuthenticatedSessionId(javax.servlet.http.HttpServletRequest httpRequest, java.lang.String userDn, java.lang.String prompt)
SessionId
generateAuthenticatedSessionId(javax.servlet.http.HttpServletRequest httpRequest, java.lang.String userDn, java.util.Map<java.lang.String,java.lang.String> sessionIdAttributes)
SessionId
generateUnauthenticatedSessionId(java.lang.String userDn)
SessionId
generateUnauthenticatedSessionId(java.lang.String userDn, java.util.Date authenticationDate, SessionIdState state, java.util.Map<java.lang.String,java.lang.String> sessionIdAttributes, boolean persist)
java.lang.String
getAcr(SessionId session)
java.util.Set<SessionId>
getCurrentSessions()
int
getServerSessionIdLifetimeInSeconds()
java.util.Map<java.lang.String,java.lang.String>
getSessionAttributes(SessionId sessionId)
@Nullable SessionId
getSessionByDn(@Nullable java.lang.String dn)
@Nullable SessionId
getSessionByDn(@Nullable java.lang.String dn, boolean silently)
@Nullable SessionId
getSessionById(@Nullable java.lang.String sessionId, boolean silently)
@Nullable SessionId
getSessionBySid(@Nullable java.lang.String sid)
SessionId
getSessionId()
SessionId
getSessionId(java.lang.String sessionId)
SessionId
getSessionId(java.lang.String sessionId, boolean silently)
SessionId
getSessionId(javax.servlet.http.HttpServletRequest request)
io.jans.as.common.model.common.User
getUser(SessionId sessionId)
boolean
isExpired(SessionId sessionId)
boolean
isSessionIdAuthenticated(SessionId sessionId)
boolean
isSessionValid(SessionId sessionId)
boolean
persistSessionId(SessionId sessionId)
boolean
persistSessionId(SessionId sessionId, boolean forcePersistence)
boolean
reinitLogin(SessionId session, boolean force)
boolean
remove(SessionId sessionId)
void
remove(java.util.List<SessionId> list)
SessionId
resetToStep(SessionId session, int resetToStep)
SessionId
setSessionIdStateAuthenticated(javax.servlet.http.HttpServletRequest httpRequest, javax.servlet.http.HttpServletResponse httpResponse, SessionId sessionId, java.lang.String userDn)
boolean
updateSessionId(SessionId sessionId)
boolean
updateSessionId(SessionId sessionId, boolean updateLastUsedAt)
boolean
updateSessionId(SessionId sessionId, boolean updateLastUsedAt, boolean forceUpdate, boolean modified)
void
updateSessionIdIfNeeded(SessionId sessionId, boolean modified)
-
-
-
Field Detail
-
OP_BROWSER_STATE
public static final java.lang.String OP_BROWSER_STATE
- See Also:
- Constant Field Values
-
SESSION_CUSTOM_STATE
public static final java.lang.String SESSION_CUSTOM_STATE
- See Also:
- Constant Field Values
-
-
Method Detail
-
getCurrentSessions
public java.util.Set<SessionId> getCurrentSessions()
-
getAcr
public java.lang.String getAcr(SessionId session)
-
assertAuthenticatedSessionCorrespondsToNewRequest
public SessionId assertAuthenticatedSessionCorrespondsToNewRequest(SessionId session, java.lang.String acrValuesStr) throws AcrChangedException
- Throws:
AcrChangedException
-
reinitLogin
public boolean reinitLogin(SessionId session, boolean force)
- Parameters:
session
-force
-- Returns:
- returns whether session was updated
-
getSessionId
public SessionId getSessionId()
-
getSessionAttributes
public java.util.Map<java.lang.String,java.lang.String> getSessionAttributes(SessionId sessionId)
-
generateAuthenticatedSessionId
public SessionId generateAuthenticatedSessionId(javax.servlet.http.HttpServletRequest httpRequest, java.lang.String userDn) throws InvalidSessionStateException
- Throws:
InvalidSessionStateException
-
generateAuthenticatedSessionId
public SessionId generateAuthenticatedSessionId(javax.servlet.http.HttpServletRequest httpRequest, java.lang.String userDn, java.lang.String prompt) throws InvalidSessionStateException
- Throws:
InvalidSessionStateException
-
generateAuthenticatedSessionId
public SessionId generateAuthenticatedSessionId(javax.servlet.http.HttpServletRequest httpRequest, java.lang.String userDn, java.util.Map<java.lang.String,java.lang.String> sessionIdAttributes) throws InvalidSessionStateException
- Throws:
InvalidSessionStateException
-
generateUnauthenticatedSessionId
public SessionId generateUnauthenticatedSessionId(java.lang.String userDn)
-
generateUnauthenticatedSessionId
public SessionId generateUnauthenticatedSessionId(java.lang.String userDn, java.util.Date authenticationDate, SessionIdState state, java.util.Map<java.lang.String,java.lang.String> sessionIdAttributes, boolean persist)
-
computeSessionState
public java.lang.String computeSessionState(SessionId sessionId, java.lang.String clientId, java.lang.String redirectUri)
-
setSessionIdStateAuthenticated
public SessionId setSessionIdStateAuthenticated(javax.servlet.http.HttpServletRequest httpRequest, javax.servlet.http.HttpServletResponse httpResponse, SessionId sessionId, java.lang.String userDn)
-
persistSessionId
public boolean persistSessionId(SessionId sessionId)
-
persistSessionId
public boolean persistSessionId(SessionId sessionId, boolean forcePersistence)
-
updateSessionId
public boolean updateSessionId(SessionId sessionId)
-
updateSessionId
public boolean updateSessionId(SessionId sessionId, boolean updateLastUsedAt)
-
updateSessionId
public boolean updateSessionId(SessionId sessionId, boolean updateLastUsedAt, boolean forceUpdate, boolean modified)
-
isExpired
public boolean isExpired(SessionId sessionId)
-
getServerSessionIdLifetimeInSeconds
public int getServerSessionIdLifetimeInSeconds()
-
updateSessionIdIfNeeded
public void updateSessionIdIfNeeded(SessionId sessionId, boolean modified)
-
getSessionById
@Nullable public @Nullable SessionId getSessionById(@Nullable @Nullable java.lang.String sessionId, boolean silently)
-
getSessionByDn
@Nullable public @Nullable SessionId getSessionByDn(@Nullable @Nullable java.lang.String dn)
-
getSessionBySid
@Nullable public @Nullable SessionId getSessionBySid(@Nullable @Nullable java.lang.String sid)
-
getSessionByDn
@Nullable public @Nullable SessionId getSessionByDn(@Nullable @Nullable java.lang.String dn, boolean silently)
-
getSessionId
public SessionId getSessionId(javax.servlet.http.HttpServletRequest request)
-
getSessionId
public SessionId getSessionId(java.lang.String sessionId)
-
getSessionId
public SessionId getSessionId(java.lang.String sessionId, boolean silently)
-
remove
public boolean remove(SessionId sessionId)
-
remove
public void remove(java.util.List<SessionId> list)
-
isSessionValid
public boolean isSessionValid(SessionId sessionId)
-
isSessionIdAuthenticated
public boolean isSessionIdAuthenticated(SessionId sessionId)
-
acrValuesList
public java.util.List<java.lang.String> acrValuesList(java.lang.String acrValues)
By definition we expects space separated acr values as it is defined in spec. But we also try maybe some client sent it to us as json array. So we try both.- Returns:
- acr value list
-
getUser
public io.jans.as.common.model.common.User getUser(SessionId sessionId)
-
findByUser
public java.util.List<SessionId> findByUser(java.lang.String userDn)
-
externalEvent
public void externalEvent(SessionEvent event)
-
-