Class DaoAuthenticationProvider
- All Implemented Interfaces:
AuthenticationProvider
Checks a username and password against a UserDetailsService: loads the user,
compares the password through a PasswordEncoder, and refuses an account
that is locked, disabled or expired.
A username nobody has still costs one password comparison, against a hash
made for the purpose, so the time an answer takes does not say whether the
account exists. And a password stored in an older encoding is rewritten in
the current one on a successful sign-in, when a UserDetailsPasswordService
is there to store it.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionauthenticate(Authentication authentication) The accepted authentication, or null when this provider cannot decide and the next one should be asked.voidsetHideUserNotFoundExceptions(boolean hide) Whether an unknown username is reported as bad credentials, which is the default, rather than as aUsernameNotFoundExceptiona client could tell apart from a wrong password.voidsetMaxConcurrentPasswordChecks(int maxConcurrentPasswordChecks) The most password checks this provider lets run in the process at one time.voidsetPasswordEncoder(PasswordEncoder passwordEncoder) The encoder passwords are compared with; a delegating one unless set.voidWhere a password re-encoded on sign-in is stored; without one a password in an older encoding stays as it is.voidsetUserDetailsService(UserDetailsService userDetailsService) booleanWhether this provider checks tokens of this class.
-
Constructor Details
-
DaoAuthenticationProvider
public DaoAuthenticationProvider() -
DaoAuthenticationProvider
-
-
Method Details
-
setUserDetailsService
-
getUserDetailsService
-
setPasswordEncoder
The encoder passwords are compared with; a delegating one unless set. -
getPasswordEncoder
-
setUserDetailsPasswordService
Where a password re-encoded on sign-in is stored; without one a password in an older encoding stays as it is. -
setMaxConcurrentPasswordChecks
public void setMaxConcurrentPasswordChecks(int maxConcurrentPasswordChecks) The most password checks this provider lets run in the process at one time. A sign-in that would be one more is refused at once with a
ServiceBusyException, which a chain answers 503 withRetry-After; no bound unless set, or withcn1.security.password.maxConcurrentfor the provider a chain makes itself.Checking a password is tens of milliseconds of processor that cannot be interrupted, on purpose. A request's thread is cheap while it waits on a socket, and is not while it hashes: every check holds one of the server's few host threads for its whole length. Without a bound, a burst of sign-ins -- or somebody guessing passwords -- takes them all, and every other request waits behind work it has nothing to do with. With one, the sign-ins beyond it are told to come back, and the rest of the server stays quick.
The bound never queues: a queue of password checks is the same pile of work, served later to clients that have already given up. Something near the number of processors, less one or two for everything else, is a reasonable value.
-
setHideUserNotFoundExceptions
public void setHideUserNotFoundExceptions(boolean hide) Whether an unknown username is reported as bad credentials, which is the default, rather than as aUsernameNotFoundExceptiona client could tell apart from a wrong password. -
supports
Description copied from interface:AuthenticationProviderWhether this provider checks tokens of this class.- Specified by:
supportsin interfaceAuthenticationProvider
-
authenticate
Description copied from interface:AuthenticationProviderThe accepted authentication, or null when this provider cannot decide and the next one should be asked.
Throws
AuthenticationException: when the token is refused
- Specified by:
authenticatein interfaceAuthenticationProvider
-