ConcurrentSessionControlAuthenticationStrategy instead@Deprecated public class ConcurrentSessionControlStrategy extends SessionFixationProtectionStrategy implements MessageSourceAware
SessionRegistry is used as the source of data on authenticated users and session data.
 
 If a user has reached the maximum number of permitted sessions, the behaviour depends on the
 exceptionIfMaxExceeded property. The default behaviour is to expired the least recently used session, which
 will be invalidated by the ConcurrentSessionFilter if accessed again. If exceptionIfMaxExceeded is
 set to true, however, the user will be prevented from starting a new authenticated session.
 
 This strategy can be injected into both the SessionManagementFilter and instances of
 AbstractAuthenticationProcessingFilter (typically UsernamePasswordAuthenticationFilter).
| Modifier and Type | Class and Description | 
|---|---|
| protected static class  | org.springframework.security.web.authentication.session.AbstractSessionFixationProtectionStrategy.NullEventPublisher | 
| Modifier and Type | Field and Description | 
|---|---|
| protected org.apache.commons.logging.Log | logger | 
| protected MessageSourceAccessor | messagesDeprecated.  | 
| Constructor and Description | 
|---|
| ConcurrentSessionControlStrategy(SessionRegistry sessionRegistry)Deprecated.  | 
| Modifier and Type | Method and Description | 
|---|---|
| protected void | allowableSessionsExceeded(List<SessionInformation> sessions,
                         int allowableSessions,
                         SessionRegistry registry)Deprecated.  Allows subclasses to customise behaviour when too many sessions are detected. | 
| protected int | getMaximumSessionsForThisUser(Authentication authentication)Deprecated.  Method intended for use by subclasses to override the maximum number of sessions that are permitted for
 a particular authentication. | 
| void | onAuthentication(Authentication authentication,
                javax.servlet.http.HttpServletRequest request,
                javax.servlet.http.HttpServletResponse response)Deprecated.  In addition to the steps from the superclass, the sessionRegistry will be updated with the new session information. | 
| protected void | onSessionChange(String originalSessionId,
               javax.servlet.http.HttpSession newSession,
               Authentication auth)Called when the session has been changed and the old attributes have been migrated to the new session. | 
| void | setAlwaysCreateSession(boolean alwaysCreateSession)Deprecated.  | 
| void | setApplicationEventPublisher(ApplicationEventPublisher applicationEventPublisher)Sets the  ApplicationEventPublisherto use for submittingSessionFixationProtectionEvent. | 
| void | setExceptionIfMaximumExceeded(boolean exceptionIfMaximumExceeded)Deprecated.  Sets the exceptionIfMaximumExceeded property, which determines whether the user should be prevented
 from opening more sessions than allowed. | 
| void | setMaximumSessions(int maximumSessions)Deprecated.  Sets the maxSessions property. | 
| void | setMessageSource(MessageSource messageSource)Deprecated.  | 
extractAttributes, setMigrateSessionAttributes, setRetainedAttributesprotected MessageSourceAccessor messages
protected final org.apache.commons.logging.Log logger
public ConcurrentSessionControlStrategy(SessionRegistry sessionRegistry)
sessionRegistry - the session registry which should be updated when the authenticated session is changed.public void onAuthentication(Authentication authentication, javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response)
onAuthentication in interface SessionAuthenticationStrategyprotected int getMaximumSessionsForThisUser(Authentication authentication)
maximumSessions value
 for the bean.authentication - to determine the maximum sessions forprotected void allowableSessionsExceeded(List<SessionInformation> sessions, int allowableSessions, SessionRegistry registry) throws SessionAuthenticationException
sessions - either null or all unexpired sessions associated with the principalallowableSessions - the number of concurrent sessions the user is allowed to haveregistry - an instance of the SessionRegistry for subclass useSessionAuthenticationExceptionpublic void setExceptionIfMaximumExceeded(boolean exceptionIfMaximumExceeded)
exceptionIfMaximumExceeded - defaults to false.public void setMaximumSessions(int maximumSessions)
maximumSessions - the maximimum number of permitted sessions a user can have open simultaneously.public void setMessageSource(MessageSource messageSource)
setMessageSource in interface MessageSourceAwarepublic final void setAlwaysCreateSession(boolean alwaysCreateSession)
protected void onSessionChange(String originalSessionId, javax.servlet.http.HttpSession newSession, Authentication auth)
 The default implementation of this method publishes a SessionFixationProtectionEvent to notify
 the application that the session ID has changed. If you override this method and still wish these events to be
 published, you should call super.onSessionChange() within your overriding method.
originalSessionId - the original session identifiernewSession - the newly created sessionauth - the token for the newly authenticated principalpublic void setApplicationEventPublisher(ApplicationEventPublisher applicationEventPublisher)
ApplicationEventPublisher to use for submitting
 SessionFixationProtectionEvent. The default is to not submit the
 SessionFixationProtectionEvent.setApplicationEventPublisher in interface ApplicationEventPublisherAwareapplicationEventPublisher - the ApplicationEventPublisher. Cannot be null.