Interface CredentialManager


public interface CredentialManager
Since:
2.1.0
  • Field Details

  • Method Details

    • verifyPassword

      boolean verifyPassword(String subjectId, @Nullable String providedPassword) throws CredentialManagerException
      Verify a password.
      Parameters:
      subjectId - subject to verify
      providedPassword - password to verify for subject
      Returns:
      true when verification succeeded, false if not.
      Throws:
      CredentialManagerException
    • verifyPassword

      @Nullable default @Nullable AuthenticationAttributes verifyPassword(String subjectId, @Nullable String providedPassword, @Nullable String context)
      Verify a password, with an optional context to use.

      This optional context could contain (an encoded) salt or other properties that might be used to do the verification.

      Parameters:
      subjectId - subject to verify
      providedPassword - password to verify for subject
      context - optional context
      Returns:
      when verification succeeded, returns AuthenticationAttributes, otherwise null is returned.
    • verifyCredentials

      Verify the credentials of a given subject.

      If a password attribute is included in the subject attributes, it should have a String value and the key CredentialDataAccessProvider.CLAIM_PASSWORD

      Parameters:
      subject - the subject attributes to verify
      Returns:
      when verification succeeded, returns AuthenticationAttributes, otherwise null is returned.
      Since:
      2.3.0
    • transform

      default String transform(String subjectId, String providedPassword, @Nullable Comparable<?> password)
      Transform the provided providedPassword to the format that can be stored in a backend. The transformation is done using the same procedure that is used to verify a provided providedPassword using any of the verify() methods.

      When this method is not implemented, the default behavior is to return the provided providedPassword unmodified.

      Parameters:
      subjectId - Id of the subject
      providedPassword - Password credential to transform
      password - Optional, the stored password that is compared against. Might be required because it could contain hints to settings on how to transform the provided password like salt, etc.
      Returns:
      The transformed providedPassword credential for the provided subject
    • updatePassword

      void updatePassword(AccountAttributes account)
      Update the password attribute of the account.

      The password will be hashed using a PasswordTransformer.

      Parameters:
      account - The account with the hashed password.
      Throws:
      CredentialManagerException - if the password is not accepted by the backing service