Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
public class DaoAuthenticationProvider
- Object
- DaoAuthenticationProvider
ImplementsAuthenticationProvider
Checks a username and password against a UserDetailsService: loads the user,
compares the password through a PasswordEncoder, and refuses an account
that is locked, disabled or expired.
A username nobody has still costs one password comparison, against a hash
made for the purpose, so the time an answer takes does not say whether the
account exists. And a password stored in an older encoding is rewritten in
the current one on a successful sign-in, when a UserDetailsPasswordService
is there to store it.
Constructors
public DaoAuthenticationProvider() | |
public DaoAuthenticationProvider(UserDetailsService userDetailsService) |
Methods
Inherited methods
Constructor details
DaoAuthenticationProvider
public DaoAuthenticationProvider()DaoAuthenticationProvider
public DaoAuthenticationProvider(UserDetailsService userDetailsService)Method details
setUserDetailsService
public void setUserDetailsService(UserDetailsService userDetailsService)getUserDetailsService
public UserDetailsService getUserDetailsService()setPasswordEncoder
public void setPasswordEncoder(PasswordEncoder passwordEncoder)getPasswordEncoder
public synchronized PasswordEncoder getPasswordEncoder()setUserDetailsPasswordService
public void setUserDetailsPasswordService(UserDetailsPasswordService service)setMaxConcurrentPasswordChecks
public synchronized void setMaxConcurrentPasswordChecks(int maxConcurrentPasswordChecks)The most password checks this provider lets run in the process at one
time. A sign-in that would be one more is refused at once with a
ServiceBusyException, which a chain answers 503 with Retry-After;
no bound unless set, or with cn1.security.password.maxConcurrent for
the provider a chain makes itself.
Checking a password is tens of milliseconds of processor that cannot be interrupted, on purpose. A request’s thread is cheap while it waits on a socket, and is not while it hashes: every check holds one of the server’s few host threads for its whole length. Without a bound, a burst of sign-ins – or somebody guessing passwords – takes them all, and every other request waits behind work it has nothing to do with. With one, the sign-ins beyond it are told to come back, and the rest of the server stays quick.
The bound never queues: a queue of password checks is the same pile of work, served later to clients that have already given up. Something near the number of processors, less one or two for everything else, is a reasonable value.
setHideUserNotFoundExceptions
public void setHideUserNotFoundExceptions(boolean hide)UsernameNotFoundException a client could tell
apart from a wrong password.supports
public boolean supports(Class<?> authentication)authenticate
public Authentication authenticate(Authentication authentication)Throws
AuthenticationException- when the token is refused