Class DelegatingPasswordEncoder
java.lang.Object
com.codename1.backend.security.crypto.DelegatingPasswordEncoder
- All Implemented Interfaces:
PasswordEncoder
Reads which scheme a stored password was made with from the {id} in front
of it, so one user store can hold passwords of several ages:
{pbkdf2-sha256}pbkdf2$210000$3q2-7w$kZ...
{bcrypt}$2a$10$dXJ3SW6G7P50lGmMkkmwe.20cQQubK3.HZWzG3YB1tlRy.fqvM/BG
{noop}password
New passwords are encoded with the scheme named at construction. A stored
password of any other scheme reports upgradeEncoding(String), which is what makes
a sign-in re-encode it.
-
Constructor Summary
ConstructorsConstructorDescriptionDelegatingPasswordEncoder(String idForEncode, Map<String, PasswordEncoder> idToPasswordEncoder) -
Method Summary
Modifier and TypeMethodDescriptionencode(CharSequence rawPassword) The password as it should be stored: salted and hashed, so encoding one password twice gives two different results.booleanmatches(CharSequence rawPassword, String prefixEncodedPassword) WhetherrawPasswordis the passwordencodedPasswordwas made from.voidThe encoder a stored password with no{id}, or one this encoder does not know, is checked with.booleanupgradeEncoding(String prefixEncodedPassword) WhetherencodedPasswordshould be encoded again for better protection: it was made by an older scheme, or with fewer rounds than this encoder uses now.
-
Constructor Details
-
DelegatingPasswordEncoder
public DelegatingPasswordEncoder(String idForEncode, Map<String, PasswordEncoder> idToPasswordEncoder) - Parameters:
idForEncode- the scheme new passwords are encoded withidToPasswordEncoder- every scheme a stored password may name
-
-
Method Details
-
setDefaultPasswordEncoderForMatches
The encoder a stored password with no{id}, or one this encoder does not know, is checked with. Unless set, such a password is refused with an exception saying so: set this to the scheme of a store that predates the prefixes. -
encode
Description copied from interface:PasswordEncoderThe password as it should be stored: salted and hashed, so encoding one password twice gives two different results.- Specified by:
encodein interfacePasswordEncoder
-
matches
Description copied from interface:PasswordEncoderWhetherrawPasswordis the passwordencodedPasswordwas made from.- Specified by:
matchesin interfacePasswordEncoder
-
upgradeEncoding
Description copied from interface:PasswordEncoderWhetherencodedPasswordshould be encoded again for better protection: it was made by an older scheme, or with fewer rounds than this encoder uses now.- Specified by:
upgradeEncodingin interfacePasswordEncoder
-