public interface TokenAuthenticationManager
Modifier and Type | Method and Description |
---|---|
Token |
authenticateApplication(Application application,
ApplicationAuthenticationContext authenticationContext,
TokenLifetime tokenLifetime)
Authenticates an application and generates an authentication token.
|
Token |
authenticateApplicationWithoutValidatingPassword(Application application,
ApplicationAuthenticationContext authenticationContext,
TokenLifetime tokenLifetime)
Authenticates an application and generates an authentication token, ignoring the credentials.
|
Token |
authenticateUser(Application application,
UserAuthenticationContext authenticateContext,
TokenLifetime tokenLifetime)
Authenticates a user and and generates an authentication token.
|
Token |
authenticateUserWithoutValidatingPassword(Application application,
UserAuthenticationContext authenticateContext)
Feigns the authentication process for a user and creates a token for the authentication without validating the password.
|
List<Application> |
findAuthorisedApplications(User user,
String applicationName)
Returns a list of applications a user
is authorised to authenticate with.
|
User |
findUserByToken(Token token,
Application application)
Will find a user via the passed in token.
|
Token |
findUserTokenByKey(String tokenKey,
Application application)
Returns the token matching a given key
|
Date |
getTokenExpiryTime(Token token)
Returns the expiry time of a token.
|
void |
invalidateAllTokens()
Invalidates all user and application tokens.
|
Optional<Token> |
invalidateToken(String token)
Attempts to invalidate a Token based on the passed in Token key (random hash).
|
void |
invalidateTokensForUser(String username,
String exclusionToken,
String applicationName)
Invalidates all sessions for a user, possibly excluding a specific one.
|
void |
removeExpiredTokens()
Removes all tokens that have exceeded their expiry time.
|
Token |
validateApplicationToken(String tokenKey,
ValidationFactor[] validationFactors)
Validates an application token key given validation factors.
|
Token |
validateUserToken(Application application,
String userTokenKey,
ValidationFactor[] validationFactors)
Validates a user token key given validation factors and checks that the user is allowed to authenticate
with the specified application
|
Token authenticateApplication(Application application, ApplicationAuthenticationContext authenticationContext, TokenLifetime tokenLifetime) throws InvalidAuthenticationException
application
- the application being authenticatedauthenticationContext
- application authentication credentials.tokenLifetime
- Requested lifetime of the tokenInvalidAuthenticationException
- authentication was not successful because either the application does not exist, the password is incorrect, the application is inactive or there was a problem generating the authentication token.Token authenticateApplicationWithoutValidatingPassword(Application application, ApplicationAuthenticationContext authenticationContext, TokenLifetime tokenLifetime) throws InvalidAuthenticationException
This method should only be used to generate a token for an application that has already authenticated via some other means (eg. TLS client certificates) as this method bypasses any password checks.
application
- the application being authenticatedauthenticationContext
- application authentication credentials.tokenLifetime
- Requested lifetime of the tokenInvalidAuthenticationException
- authentication was not successful because either the application does not exist, the application is inactive or there was a problem generating the authentication token.Token authenticateUser(Application application, UserAuthenticationContext authenticateContext, TokenLifetime tokenLifetime) throws InvalidAuthenticationException, OperationFailedException, InactiveAccountException, ApplicationAccessDeniedException, ExpiredCredentialException
The RemoteDirectory.authenticate(String, com.atlassian.crowd.embedded.api.PasswordCredential)
method is
iteratively called for each assigned directory. If the user does not exist in one directory, the directory is skipped and the next one is examined. If the user does
not exist in any of the assigned directories then an InvalidAuthenticationException
is thrown.
application
- authenticateContext
- The authentication details for the user.tokenLifetime
- Requested lifetime of the tokenInvalidAuthenticationException
- The authentication was not successful.OperationFailedException
- error thrown by directory implementation when attempting to find or authenticate the user.InactiveAccountException
- user account is inactive.ApplicationAccessDeniedException
- user does not have access to authenticate with application.ExpiredCredentialException
- the user's credentials have expired. The user must change their credentials in order to successfully authenticate.Token authenticateUserWithoutValidatingPassword(Application application, UserAuthenticationContext authenticateContext) throws InvalidAuthenticationException, OperationFailedException, InactiveAccountException, ApplicationAccessDeniedException
This method should only be used to generate a token for a user that has already authenticated credentials via some other means (eg. SharePoint NTLM connector) as this method bypasses any password checks.
If you want actual password authentication, use the authenticateUser(Application, UserAuthenticationContext, TokenLifetime)
method.
application
- authenticateContext
- The authentication details for the user.InvalidAuthenticationException
- if the authentication was not successful.OperationFailedException
- if the error thrown by directory implementation when attempting to find or authenticate the user.InactiveAccountException
- if the user account is inactive.ApplicationAccessDeniedException
- if the user does not have access to authenticate with application.Token validateApplicationToken(String tokenKey, ValidationFactor[] validationFactors) throws InvalidTokenException
tokenKey
- returns a valid token corresponding to the tokenKey.validationFactors
- validation factors for generating the token hash.InvalidTokenException
- if the tokenKey or corresponding client validation factors do not represent a valid application token.Token validateUserToken(Application application, String userTokenKey, ValidationFactor[] validationFactors) throws InvalidTokenException, ApplicationAccessDeniedException, OperationFailedException
application
- the application performing the authenticationuserTokenKey
- returns a valid token corresponding to the tokenKey.validationFactors
- validation factors for generating the token hash.InvalidTokenException
- if the userTokenKey or corresponding validationFactors do not represent a valid SSO token.OperationFailedException
- there was an error communicating with an underlying directory when determining if a user is allowed to authenticate with the application (eg. if a user has the appropriate group memberships).ApplicationAccessDeniedException
- the user is not allowed to authenticate with the application.Optional<Token> invalidateToken(String token)
If the token does not exist (ie. already invalidated) this method returns Optional.empty()
. If an existing token is successfully invalidated, a
TokenInvalidatedEvent is fired, and the invalidated token is returned
token
- the token key (random hash) to invalidate.void invalidateAllTokens()
void removeExpiredTokens()
NOTE: Do not call this method from the web layer, as this is wrapped in a Spring managed transaction.
User findUserByToken(Token token, Application application) throws InvalidTokenException, OperationFailedException
token
- the tokenapplication
- the application to do the lookup forInvalidTokenException
- if the User or Directory cannot be found that relates to the given token,
or the token is associated to an Application and not a UserOperationFailedException
- if there was an issue accessing the user from the underlying directoryToken findUserTokenByKey(String tokenKey, Application application) throws InvalidTokenException, ApplicationAccessDeniedException, OperationFailedException
tokenKey
- the token keyapplication
- the application to do the lookup forInvalidTokenException
- if the token cannot be found by the give key,
or the token is associated to an Application and not a UserOperationFailedException
- if there was an issue accessing the user from the underlying directoryApplicationAccessDeniedException
- the user is not allowed to authenticate with the application.List<Application> findAuthorisedApplications(User user, String applicationName) throws OperationFailedException, DirectoryNotFoundException, ApplicationNotFoundException
NOTE: this is a potentially expensive call, iterating all applications and all group mappings for each application and determining group membership, ie. expense = number of applications * number of group mappings per application.
user
- user to search for.applicationName
- name of the current applicationOperationFailedException
- if there was an error querying directory.DirectoryNotFoundException
- if the directory could not be found.ApplicationNotFoundException
- if the application could not be foundvoid invalidateTokensForUser(String username, @Nullable String exclusionToken, String applicationName) throws UserNotFoundException, ApplicationNotFoundException
applicationName
- name of the current applicationexclusionToken
- the random hash of a token to leave validUserNotFoundException
ApplicationNotFoundException
Copyright © 2020 Atlassian. All rights reserved.