Class OneTimeTokenAuthenticationProvider
java.lang.Object
org.springframework.security.authentication.ott.OneTimeTokenAuthenticationProvider
- All Implemented Interfaces:
AuthenticationProvider
public final class OneTimeTokenAuthenticationProvider
extends Object
implements AuthenticationProvider
An
AuthenticationProvider responsible for authenticating users based on
one-time tokens. It uses an OneTimeTokenService to consume tokens and an
UserDetailsService to fetch user authorities.- Since:
- 6.4
-
Constructor Summary
ConstructorsConstructorDescriptionOneTimeTokenAuthenticationProvider(OneTimeTokenService oneTimeTokenService, UserDetailsService userDetailsService) -
Method Summary
Modifier and TypeMethodDescriptionauthenticate(Authentication authentication) Performs authentication with the same contract asAuthenticationManager.authenticate(Authentication).voidsetUserDetailsChecker(UserDetailsChecker userDetailsChecker) Use thisUserDetailsCheckerto verify the status of the loadedUserDetailsafter authentication.booleanReturnstrueif thisAuthenticationProvidersupports the indicatedAuthenticationobject.
-
Constructor Details
-
OneTimeTokenAuthenticationProvider
public OneTimeTokenAuthenticationProvider(OneTimeTokenService oneTimeTokenService, UserDetailsService userDetailsService)
-
-
Method Details
-
authenticate
Description copied from interface:AuthenticationProviderPerforms authentication with the same contract asAuthenticationManager.authenticate(Authentication).- Specified by:
authenticatein interfaceAuthenticationProvider- Parameters:
authentication- the authentication request object.- Returns:
- a fully authenticated object including credentials. May return
nullif theAuthenticationProvideris unable to support authentication of the passedAuthenticationobject. In such a case, the nextAuthenticationProviderthat supports the presentedAuthenticationclass will be tried. - Throws:
AuthenticationException- if authentication fails.
-
supports
Description copied from interface:AuthenticationProviderReturnstrueif thisAuthenticationProvidersupports the indicatedAuthenticationobject.Returning
truedoes not guarantee anAuthenticationProviderwill be able to authenticate the presentedAuthenticationobject. It simply indicates it can support closer evaluation of it. AnAuthenticationProvidercan still returnnullfrom theAuthenticationProvider.authenticate(Authentication)method to indicate anotherAuthenticationProvidershould be tried.Selection of an
AuthenticationProvidercapable of performing authentication is conducted at runtime by theProviderManager.- Specified by:
supportsin interfaceAuthenticationProvider- Parameters:
authentication-- Returns:
trueif the implementation can more closely evaluate theAuthenticationclass presented
-
setUserDetailsChecker
Use thisUserDetailsCheckerto verify the status of the loadedUserDetailsafter authentication.By default, no checks are performed, keeping this provider's behavior consistent with earlier versions of Spring Security. To reject authentication for accounts that are locked, disabled, or expired, provide a
AccountStatusUserDetailsChecker.- Parameters:
userDetailsChecker- theUserDetailsCheckerto use- Since:
- 7.2
-