Client API. The Codename One framework your app is built on: this runs on the device, not in a backend.
public final class SecureStorageTokenStore
- Object
- SecureStorageTokenStore
ImplementsTokenStore
A TokenStore that keeps an OidcClient’s tokens in the platform’s secure storage – the
iOS keychain, the Android keystore, and what each desktop and browser port provides – instead
of the application’s ordinary Storage.
client.setTokenStore(new SecureStorageTokenStore());
A refresh token is a long-lived credential: whoever reads it can keep a session alive without the user. That is the reason to prefer this store over the default one for any application that signs in to something that matters.
Quiet and gated
By default the store uses the non-prompting half of SecureStorage: entries are encrypted by
the operating system and read without asking the user, which is what a token attached to
every request needs. requireBiometrics(String) switches to the gated half, where reading
(and on Android writing) shows a biometric prompt. An application that does this should load
its tokens once, when it starts, and keep them in memory – OidcRequestAuthorizer does.
Loading prompts only when this store saved something to read: before the first sign-in, and
after clear(String), it completes with null without asking the user anything.
A platform with no secure storage
Nothing is downgraded silently. On a port with no secure storage every operation fails with
an OidcException whose code is OidcException.STORAGE_UNAVAILABLE, so the application
finds out the first time it runs there rather than discovering later where its refresh tokens
went. allowPlainStorageFallback(boolean) is the explicit opt-in: with it, such a platform
gets TokenStore.DefaultStorageTokenStore instead. The fallback is only used where secure
storage cannot be reached at all, never because one write failed.
Both stores write the same document, so an entry can be copied from one to the other as is.
Constructors
public SecureStorageTokenStore() | A store over the platform’s SecureStorage.getInstance(). |
public SecureStorageTokenStore(SecureStorage storage) | A store over a particular SecureStorage. |
Methods
Inherited nested types
Inherited methods
Constructor details
SecureStorageTokenStore
public SecureStorageTokenStore()SecureStorage.getInstance().SecureStorageTokenStore
public SecureStorageTokenStore(SecureStorage storage)SecureStorage.Parameters
storageSecureStorage- the storage to keep entries in, or null for the platform’s own, looked up on each use
Method details
requireBiometrics
public SecureStorageTokenStore requireBiometrics(String reason)Keeps the tokens behind a biometric prompt.
Reading then asks the user to authenticate, and on Android so does writing. Entries are
bound to the enrolled biometrics: after the user enrolls a new finger or face the stored
entry is gone for good, load(String) completes with null, and the user signs in again.
An entry written quietly is not visible to the gated half and the other way around, so decide once per application.
Parameters
reasonString- the text of the prompt, or null to go back to quiet storage
Returns
allowPlainStorageFallback
public SecureStorageTokenStore allowPlainStorageFallback(boolean allow)Storage instead. Off by default.Parameters
allowboolean- true to fall back on such a platform, false to fail there
Returns
load
public AsyncResource<OidcTokens> load(String key)key, or completes with null if
nothing is stored.save
public AsyncResource<Boolean> save(String key, OidcTokens tokens)tokens under key. Implementations should overwrite any
existing entry atomically.clear
public AsyncResource<Boolean> clear(String key)key. Completing with Boolean.FALSE means
nothing was stored; completing with an error means the underlying
store failed.