Class JdbcUserCredentialRepository

java.lang.Object
com.codename1.backend.security.webauthn.JdbcUserCredentialRepository
All Implemented Interfaces:
UserCredentialRepository

public final class JdbcUserCredentialRepository extends Object implements UserCredentialRepository

Credentials kept in the server's database, in the cn1_webauthn_credential table of SecuritySchema.

A row holds nothing secret: a public key verifies and cannot sign.

A credential's id is the table's key through its SHA-256, so that storing one whose id is taken is refused by the key itself, whichever user has it and however many requests try at once. The signature counter is moved by one statement that names the condition it moves under, so the database decides, and of two requests carrying the same assertion one changes no row.

  • Constructor Details

    • JdbcUserCredentialRepository

      public JdbcUserCredentialRepository(DataSource dataSource)
  • Method Details

    • save

      public boolean save(CredentialRecord record)
      Description copied from interface: UserCredentialRepository
      Stores a new credential.
      Specified by:
      save in interface UserCredentialRepository
      Returns:
      false, and nothing stored, when a credential with this id is there already -- this user's or another's
    • findByCredentialId

      public CredentialRecord findByCredentialId(byte[] credentialId)
      Description copied from interface: UserCredentialRepository
      The credential with this id, or null.
      Specified by:
      findByCredentialId in interface UserCredentialRepository
    • findByUserId

      public List<CredentialRecord> findByUserId(byte[] userEntityUserId)
      Description copied from interface: UserCredentialRepository
      The credentials of the user with this handle, oldest first; empty when they have none.
      Specified by:
      findByUserId in interface UserCredentialRepository
    • advance

      public boolean advance(byte[] credentialId, long signatureCount, boolean uvInitialized, boolean backupState, long lastUsed)
      Description copied from interface: UserCredentialRepository

      Records a sign-in: the counter the authenticator sent, the flags it sent, and when.

      The counter is taken only when it is greater than the one stored -- or when both are zero, which is an authenticator that keeps no counter. One statement decides and stores, so of two requests with the same assertion one is refused.

      Specified by:
      advance in interface UserCredentialRepository
      Returns:
      false, and nothing changed, when the counter did not advance or the credential is gone
    • delete

      public boolean delete(byte[] credentialId)
      Description copied from interface: UserCredentialRepository
      Removes a credential.
      Specified by:
      delete in interface UserCredentialRepository
      Returns:
      whether there was one