Class JdbcApiKeyRepository

java.lang.Object
com.codename1.backend.security.apikey.JdbcApiKeyRepository
All Implemented Interfaces:
ApiKeyRepository

public final class JdbcApiKeyRepository extends Object implements ApiKeyRepository

API keys kept in the server's database, in the cn1_api_key table of SecuritySchema. Only a key's hash is stored; the key itself is shown once, by ApiKeyGenerator, and never again.

@Bean
ApiKeyRepository apiKeys(DataSource dataSource) {
    return new JdbcApiKeyRepository(dataSource);
}
  • Constructor Details

    • JdbcApiKeyRepository

      public JdbcApiKeyRepository(DataSource dataSource)
  • Method Details

    • setClock

      public void setClock(Clock clock)
      The clock a key's creation time is read from; for tests.
    • findByHash

      public ApiKey findByHash(String hash)
      Description copied from interface: ApiKeyRepository
      The key with this hash, or null. A revoked key is returned like any other; refusing it is the caller's.
      Specified by:
      findByHash in interface ApiKeyRepository
      Parameters:
      hash - the lowercase hexadecimal SHA-256 of a presented key
    • save

      public void save(ApiKey key) throws IOException
      Stores a new key. A scope may not contain a space.
      Throws:
      IOException
    • revoke

      public boolean revoke(String id) throws IOException
      Revokes the key with this id.
      Returns:
      whether this call revoked it: false when there is no such key, or it was revoked already
      Throws:
      IOException
    • delete

      public boolean delete(String id) throws IOException
      Forgets the key with this id altogether.
      Throws:
      IOException
    • findByOwner

      public List<ApiKey> findByOwner(String owner) throws IOException
      The keys of one owner, oldest first.
      Throws:
      IOException