Interface NonceDataAccessProvider

All Superinterfaces:
DataAccessProvider

public interface NonceDataAccessProvider extends DataAccessProvider
This data source is responsible for storing one time tokens (Nonce). These are only allowed to be used once. The data source must maintain a state in which the nonce can be treated to be
  1. ISSUED
  2. CONSUMED
  3. EXPIRED
When a nonce is consumed it should not be retrievable again.
  • Method Summary

    Modifier and Type
    Method
    Description
    void
    consume(String nonce, long consumedAt)
    After reading a nonce, the client will 'consume' the nonce.
    get(String nonce)
    Retrieve a valid nonce from the backend.
    void
    save(String nonce, String value, long createdAt, long ttl)
    Store a new Nonce value in the data source.

    Methods inherited from interface se.curity.identityserver.sdk.datasource.DataAccessProvider

    isThreadSafe
  • Method Details

    • get

      Retrieve a valid nonce from the backend. A nonce is valid when its status is 'issued' and it has not expired (created + ttl < now). If the nonce exists but does not meet the above criteria, it should not be returned.
      Parameters:
      nonce - Nonce value to lookup
      Returns:
      The data that is referenced by the nonce
    • save

      void save(String nonce, String value, long createdAt, long ttl)
      Store a new Nonce value in the data source.
      Parameters:
      nonce - The ID of the nonce (the actual nonce token)
      value - The data tied to the nonce ID
      createdAt - The epoch second the nonce was created
      ttl - The number of seconds from createdAt that the nonce is allowed to be active.
    • consume

      void consume(String nonce, long consumedAt)
      After reading a nonce, the client will 'consume' the nonce. This should set the entry in a CONSUMED state. After this, it should not be returned when get(java.lang.String) is called. This essentially has the same effect as when the nonce is expired, however for auditing purposes it is recommended to keep the state CONSUMED in the data store rather than expiring the entry.
      Parameters:
      nonce - The nonce (ID) to be consumed
      consumedAt - The epoch time in seconds when it was consumed.