Interface UserCredentialRepository

All Known Implementing Classes:
InMemoryUserCredentialRepository, JdbcUserCredentialRepository

public interface UserCredentialRepository

Where the passkeys users have registered are kept.

InMemoryUserCredentialRepository keeps them in this process, for a test or a demonstration; JdbcUserCredentialRepository keeps them in the server's database. Both do the two things the ceremonies depend on as one step each, so that two requests at once cannot both pass:

  • Method Summary

    Modifier and Type
    Method
    Description
    boolean
    advance(byte[] credentialId, long signatureCount, boolean uvInitialized, boolean backupState, long lastUsed)
    Records a sign-in: the counter the authenticator sent, the flags it sent, and when.
    boolean
    delete(byte[] credentialId)
    Removes a credential.
    findByCredentialId(byte[] credentialId)
    The credential with this id, or null.
    findByUserId(byte[] userEntityUserId)
    The credentials of the user with this handle, oldest first; empty when they have none.
    boolean
    Stores a new credential.
  • Method Details

    • save

      boolean save(CredentialRecord record)
      Stores a new credential.
      Returns:
      false, and nothing stored, when a credential with this id is there already -- this user's or another's
    • findByCredentialId

      CredentialRecord findByCredentialId(byte[] credentialId)
      The credential with this id, or null.
    • findByUserId

      List<CredentialRecord> findByUserId(byte[] userEntityUserId)
      The credentials of the user with this handle, oldest first; empty when they have none.
    • advance

      boolean advance(byte[] credentialId, long signatureCount, boolean uvInitialized, boolean backupState, long lastUsed)

      Records a sign-in: the counter the authenticator sent, the flags it sent, and when.

      The counter is taken only when it is greater than the one stored -- or when both are zero, which is an authenticator that keeps no counter. One statement decides and stores, so of two requests with the same assertion one is refused.

      Returns:
      false, and nothing changed, when the counter did not advance or the credential is gone
    • delete

      boolean delete(byte[] credentialId)
      Removes a credential.
      Returns:
      whether there was one