Class AuthenticatedState
- Since:
- 2.1.0
-
Constructor Summary
ConstructorsConstructorDescriptionAuthenticatedState(@Nullable AuthenticationAttributes authenticationAttributes, @Nullable AuthenticationAttributes intermediateAuthenticationAttributes) -
Method Summary
Modifier and TypeMethodDescriptionReturns the authentication attributes of the user or null if the user is not logged in.Returns the username of the authenticated user.booleanReturns whether authentication has occurred.booleanReturns true if the authentication attributes are intermediate attributes.
-
Constructor Details
-
AuthenticatedState
public AuthenticatedState() -
AuthenticatedState
public AuthenticatedState(@Nullable AuthenticationAttributes authenticationAttributes, @Nullable AuthenticationAttributes intermediateAuthenticationAttributes)
-
-
Method Details
-
getUsername
Returns the username of the authenticated user.If
isAuthenticated()returns false, calling this method will cause an Exception to be thrown.- Returns:
- the authenticated username
-
isAuthenticated
public boolean isAuthenticated()Returns whether authentication has occurred.- Returns:
trueif authenticated,falseotherwise.
-
getAuthenticationAttributes
Returns the authentication attributes of the user or null if the user is not logged in.If the user has logged in with multiple authenticators (i.e., multi-factor authentication was used), then only the last (i.e., newest) authentication attributes are returned. If SSO was used, the newest session's attributes is what will be returned unless an ACR was provided in the request and the user had an SSO session for that ACR; in that case, the attributes will not be the newest but the ones associated from the requested session.
If the authenticator is called during an AuthenticationAction as a required authentication, then these attributes are the intermediate attributes. I.e. they may not not the same attributes that will end up in the SSO session later on. They can still be treated as truth since they come from the factor that ran before the current authenticator.
If the authenticator needs to know if they are intermediate use
isIntermediateState()- Returns:
- the authentication attributes or intermediate attributes of the user or null if the user is not logged in
- Since:
- 3.0.0
-
isIntermediateState
public boolean isIntermediateState()Returns true if the authentication attributes are intermediate attributes. These are only available if the authenticator is called from an authentication action. In this case the authentication attributes are not yet committed, and the intermediate attributes represent the current state of the to be committed attributes.Note: It very much depends on what actions have run before the action that called the authenticator has done to the attributes. They may be transformed partly or entirely.
Important: If the actions fail at a later stage, these attributes will be discarded. Therefore they should not be persisted as source of truth.
- Returns:
- true if the attributes are intermediate attributes from an action
- Since:
- 4.0.0
-