Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public class DaoAuthenticationProvider

  1. Object
  2. DaoAuthenticationProvider

ImplementsAuthenticationProvider

Checks a username and password against a UserDetailsService: loads the user, compares the password through a PasswordEncoder, and refuses an account that is locked, disabled or expired.

A username nobody has still costs one password comparison, against a hash made for the purpose, so the time an answer takes does not say whether the account exists. And a password stored in an older encoding is rewritten in the current one on a successful sign-in, when a UserDetailsPasswordService is there to store it.

Constructors

public DaoAuthenticationProvider()
public DaoAuthenticationProvider(UserDetailsService userDetailsService)

Methods

public void setUserDetailsService(UserDetailsService userDetailsService)
public UserDetailsService getUserDetailsService()
public void setPasswordEncoder(PasswordEncoder passwordEncoder)The encoder passwords are compared with; a delegating one unless set.
public synchronized PasswordEncoder getPasswordEncoder()
public void setUserDetailsPasswordService(UserDetailsPasswordService service)Where a password re-encoded on sign-in is stored; without one a password in an older encoding stays as it is.
public synchronized void setMaxConcurrentPasswordChecks(int maxConcurrentPasswordChecks)The most password checks this provider lets run in the process at one time.
public void setHideUserNotFoundExceptions(boolean hide)Whether an unknown username is reported as bad credentials, which is the default, rather than as a UsernameNotFoundException a client could tell apart from a wrong password.
public boolean supports(Class<?> authentication)Whether this provider checks tokens of this class.
public Authentication authenticate(Authentication authentication)The accepted authentication, or null when this provider cannot decide and the next one should be asked.

Inherited methods

Constructor details

DaoAuthenticationProvider

public DaoAuthenticationProvider()

DaoAuthenticationProvider

public DaoAuthenticationProvider(UserDetailsService userDetailsService)

Method details

setUserDetailsService

public void setUserDetailsService(UserDetailsService userDetailsService)

getUserDetailsService

public UserDetailsService getUserDetailsService()

setPasswordEncoder

public void setPasswordEncoder(PasswordEncoder passwordEncoder)
The encoder passwords are compared with; a delegating one unless set.

getPasswordEncoder

public synchronized PasswordEncoder getPasswordEncoder()

setUserDetailsPasswordService

public void setUserDetailsPasswordService(UserDetailsPasswordService service)
Where a password re-encoded on sign-in is stored; without one a password in an older encoding stays as it is.

setMaxConcurrentPasswordChecks

public synchronized void setMaxConcurrentPasswordChecks(int maxConcurrentPasswordChecks)

The most password checks this provider lets run in the process at one time. A sign-in that would be one more is refused at once with a ServiceBusyException, which a chain answers 503 with Retry-After; no bound unless set, or with cn1.security.password.maxConcurrent for the provider a chain makes itself.

Checking a password is tens of milliseconds of processor that cannot be interrupted, on purpose. A request’s thread is cheap while it waits on a socket, and is not while it hashes: every check holds one of the server’s few host threads for its whole length. Without a bound, a burst of sign-ins – or somebody guessing passwords – takes them all, and every other request waits behind work it has nothing to do with. With one, the sign-ins beyond it are told to come back, and the rest of the server stays quick.

The bound never queues: a queue of password checks is the same pile of work, served later to clients that have already given up. Something near the number of processors, less one or two for everything else, is a reasonable value.

setHideUserNotFoundExceptions

public void setHideUserNotFoundExceptions(boolean hide)
Whether an unknown username is reported as bad credentials, which is the default, rather than as a UsernameNotFoundException a client could tell apart from a wrong password.

supports

public boolean supports(Class<?> authentication)
Whether this provider checks tokens of this class.

authenticate

public Authentication authenticate(Authentication authentication)
The accepted authentication, or null when this provider cannot decide and the next one should be asked.

Throws

AuthenticationException
when the token is refused