Class DaoAuthenticationProvider

java.lang.Object
com.codename1.backend.security.DaoAuthenticationProvider
All Implemented Interfaces:
AuthenticationProvider

public class DaoAuthenticationProvider extends Object implements AuthenticationProvider

Checks a username and password against a UserDetailsService: loads the user, compares the password through a PasswordEncoder, and refuses an account that is locked, disabled or expired.

A username nobody has still costs one password comparison, against a hash made for the purpose, so the time an answer takes does not say whether the account exists. And a password stored in an older encoding is rewritten in the current one on a successful sign-in, when a UserDetailsPasswordService is there to store it.

  • Constructor Details

    • DaoAuthenticationProvider

      public DaoAuthenticationProvider()
    • DaoAuthenticationProvider

      public DaoAuthenticationProvider(UserDetailsService userDetailsService)
  • Method Details

    • setUserDetailsService

      public void setUserDetailsService(UserDetailsService userDetailsService)
    • getUserDetailsService

      public UserDetailsService getUserDetailsService()
    • setPasswordEncoder

      public void setPasswordEncoder(PasswordEncoder passwordEncoder)
      The encoder passwords are compared with; a delegating one unless set.
    • getPasswordEncoder

      public PasswordEncoder getPasswordEncoder()
    • setUserDetailsPasswordService

      public void setUserDetailsPasswordService(UserDetailsPasswordService service)
      Where a password re-encoded on sign-in is stored; without one a password in an older encoding stays as it is.
    • setMaxConcurrentPasswordChecks

      public void setMaxConcurrentPasswordChecks(int maxConcurrentPasswordChecks)

      The most password checks this provider lets run in the process at one time. A sign-in that would be one more is refused at once with a ServiceBusyException, which a chain answers 503 with Retry-After; no bound unless set, or with cn1.security.password.maxConcurrent for the provider a chain makes itself.

      Checking a password is tens of milliseconds of processor that cannot be interrupted, on purpose. A request's thread is cheap while it waits on a socket, and is not while it hashes: every check holds one of the server's few host threads for its whole length. Without a bound, a burst of sign-ins -- or somebody guessing passwords -- takes them all, and every other request waits behind work it has nothing to do with. With one, the sign-ins beyond it are told to come back, and the rest of the server stays quick.

      The bound never queues: a queue of password checks is the same pile of work, served later to clients that have already given up. Something near the number of processors, less one or two for everything else, is a reasonable value.

    • setHideUserNotFoundExceptions

      public void setHideUserNotFoundExceptions(boolean hide)
      Whether an unknown username is reported as bad credentials, which is the default, rather than as a UsernameNotFoundException a client could tell apart from a wrong password.
    • supports

      public boolean supports(Class<?> authentication)
      Description copied from interface: AuthenticationProvider
      Whether this provider checks tokens of this class.
      Specified by:
      supports in interface AuthenticationProvider
    • authenticate

      public Authentication authenticate(Authentication authentication)
      Description copied from interface: AuthenticationProvider

      The accepted authentication, or null when this provider cannot decide and the next one should be asked.

      Throws
      • AuthenticationException: when the token is refused
      Specified by:
      authenticate in interface AuthenticationProvider