Interface CredentialDataAccessProvider

All Superinterfaces:
DataAccessProvider

public interface CredentialDataAccessProvider extends DataAccessProvider
Interface for UserDataAccessProvider implementations.
  • Field Details

  • Method Details

    • updatePassword

      void updatePassword(AccountAttributes account)
      Update the data store with the new password for the user. The subject and password are available in the Account object. Note: The Account is not a complete account, it may be partial If the backend does not support patch/update operations, it is the responsibility of the plugin to take care of this.
      Parameters:
      account - The (partial) account.
    • verifyPassword

      @Nullable @Nullable AuthenticationAttributes verifyPassword(String userName, String password)
      Execute the credential query to obtain the authentication attributes.

      If the password is not verified as part of the query it should be returned in the return value using the key CLAIM_PASSWORD. To know if the password is verified by the query, see customQueryVerifiesPassword()

      Parameters:
      userName - Identity of the subject to look up in account backend.
      password - Password credential used to verify for the account
      Returns:
      Claims. In case the userName could not be found, null is returned.
    • verifyCredentials

      @Nullable default @Nullable AuthenticationAttributes verifyCredentials(SubjectAttributes subject)
      Execute the credential query to obtain the authentication attributes.

      If a password attribute is included in the subject attributes, it will have a String value and the key CLAIM_PASSWORD

      If the password is not verified as part of the query it should be returned in the return value using the key CLAIM_PASSWORD. To know if the password is verified by the query, see customQueryVerifiesPassword()

      Parameters:
      subject - the attributes containing the subject to look up and credentials to verify
      Returns:
      authentication attributes. In case the subjectId could not be found, null is returned.
      Since:
      2.3.0
    • customQueryVerifiesPassword

      boolean customQueryVerifiesPassword()
      Indicates whether the custom credentials query will verify the password or not. If not, the password should be returned by the query and verified in the credential manager.
      Returns:
      True if the Data Source verifies the password in verifyPassword().