Client API. The Codename One framework your app is built on: this runs on the device, not in a backend.

public final class SecureStorageTokenStore

  1. Object
  2. SecureStorageTokenStore

ImplementsTokenStore

A TokenStore that keeps an OidcClient’s tokens in the platform’s secure storage – the iOS keychain, the Android keystore, and what each desktop and browser port provides – instead of the application’s ordinary Storage.

client.setTokenStore(new SecureStorageTokenStore());

A refresh token is a long-lived credential: whoever reads it can keep a session alive without the user. That is the reason to prefer this store over the default one for any application that signs in to something that matters.

Quiet and gated

By default the store uses the non-prompting half of SecureStorage: entries are encrypted by the operating system and read without asking the user, which is what a token attached to every request needs. requireBiometrics(String) switches to the gated half, where reading (and on Android writing) shows a biometric prompt. An application that does this should load its tokens once, when it starts, and keep them in memory – OidcRequestAuthorizer does. Loading prompts only when this store saved something to read: before the first sign-in, and after clear(String), it completes with null without asking the user anything.

A platform with no secure storage

Nothing is downgraded silently. On a port with no secure storage every operation fails with an OidcException whose code is OidcException.STORAGE_UNAVAILABLE, so the application finds out the first time it runs there rather than discovering later where its refresh tokens went. allowPlainStorageFallback(boolean) is the explicit opt-in: with it, such a platform gets TokenStore.DefaultStorageTokenStore instead. The fallback is only used where secure storage cannot be reached at all, never because one write failed.

Both stores write the same document, so an entry can be copied from one to the other as is.

Constructors

public SecureStorageTokenStore()A store over the platform’s SecureStorage.getInstance().
public SecureStorageTokenStore(SecureStorage storage)A store over a particular SecureStorage.

Methods

public SecureStorageTokenStore requireBiometrics(String reason)Keeps the tokens behind a biometric prompt.
public SecureStorageTokenStore allowPlainStorageFallback(boolean allow)Whether a platform with no secure storage may keep the tokens in ordinary Storage instead.
public AsyncResource<OidcTokens> load(String key)Reads previously-saved tokens for key, or completes with null if nothing is stored.
public AsyncResource<Boolean> save(String key, OidcTokens tokens)Persists tokens under key.
public AsyncResource<Boolean> clear(String key)Removes the entry for key.

Inherited nested types

Inherited methods

Constructor details

SecureStorageTokenStore

public SecureStorageTokenStore()
A store over the platform’s SecureStorage.getInstance().

SecureStorageTokenStore

public SecureStorageTokenStore(SecureStorage storage)
A store over a particular SecureStorage.

Parameters

storage SecureStorage
the storage to keep entries in, or null for the platform’s own, looked up on each use

Method details

requireBiometrics

public SecureStorageTokenStore requireBiometrics(String reason)

Keeps the tokens behind a biometric prompt.

Reading then asks the user to authenticate, and on Android so does writing. Entries are bound to the enrolled biometrics: after the user enrolls a new finger or face the stored entry is gone for good, load(String) completes with null, and the user signs in again.

An entry written quietly is not visible to the gated half and the other way around, so decide once per application.

Parameters

reason String
the text of the prompt, or null to go back to quiet storage

Returns

this store

allowPlainStorageFallback

public SecureStorageTokenStore allowPlainStorageFallback(boolean allow)
Whether a platform with no secure storage may keep the tokens in ordinary Storage instead. Off by default.

Parameters

allow boolean
true to fall back on such a platform, false to fail there

Returns

this store

load

public AsyncResource<OidcTokens> load(String key)
Reads previously-saved tokens for key, or completes with null if nothing is stored.

save

public AsyncResource<Boolean> save(String key, OidcTokens tokens)
Persists tokens under key. Implementations should overwrite any existing entry atomically.

clear

public AsyncResource<Boolean> clear(String key)
Removes the entry for key. Completing with Boolean.FALSE means nothing was stored; completing with an error means the underlying store failed.