Class SecuritySchema
The tables the security layer's database-backed stores keep, as a migration set of the layer's own.
Nothing registers it unless the application asks, and an application that does not ask carries none of it. To ask, set
cn1.security.schema.enabled=true
in application.properties -- the build reads it there and registers the
set in the server's entry point -- or, in a server assembled by hand and in
a test, call
Migrations.register(SecuritySchema.migrations());
before the server starts.
The setting is the build's to read. A server that finds it true anywhere at run time -- the environment, a system property, a properties file beside it -- without the set having been registered does not start, and says where the setting belongs. Found false at run time, in a server built with it, the set is not applied: the tables are then whatever the database has.
The set is named security, keeps its history in
cn1_security_schema_history, and runs before the application's own
migrations, so those may refer to its tables.
Every table is named cn1_..., and the same on SQLite, PostgreSQL and
MySQL:
| Version | Tables | Used by |
|---|---|---|
| 1 | cn1_users, cn1_authorities |
JdbcUserDetailsManager |
| 2 | cn1_api_key |
JdbcApiKeyRepository |
| 3 | cn1_persistent_logins |
JdbcTokenRepository |
| 4 | cn1_mfa_totp, cn1_mfa_recovery_code |
JdbcTotpRepository, JdbcRecoveryCodeRepository |
| 5 | cn1_rate_limit |
JdbcRateLimiter |
| 6 | cn1_federated_identity |
JdbcFederatedIdentityRepository |
| 7 | cn1_oauth2_registered_client |
JdbcRegisteredClientRepository |
| 8 | cn1_oauth2_authorization, cn1_oauth2_token |
JdbcOAuth2AuthorizationService |
| 9 | cn1_webauthn_user, cn1_webauthn_credential |
JdbcPublicKeyCredentialUserEntityRepository, JdbcUserCredentialRepository |
| 10 | cn1_rate_limit.window_end |
Expiry-aware cleanup for limiters with different periods |
| 11 | cn1_persistent_logins.previous_token_hash |
Concurrent remember-me rotation grace |
A user name is kept twice: as it was given, and folded to lower case in the
username_key column every table is keyed by, which is what makes a lookup
ignore case the same way on all three engines. Only A to Z are folded;
see usernameKey(String).
A moment is epoch milliseconds in a 64-bit integer and a truth value is 0 or 1, as everywhere in the backend's own schemas.
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionstatic MigrationSetThe set, forMigrations.register.static StringusernameKey(String username) A user name as the tables are keyed by it:AtoZfolded to lower case, and nothing else changed.
-
Field Details
-
NAME
-
ENABLED
-
-
Method Details
-
migrations
The set, forMigrations.register. -
usernameKey
-