Search in sources :

Example 1 with AuthToken

use of org.summerb.microservices.users.api.dto.AuthToken in project summerb by skarpushin.

the class PersistentTokenRepositoryDefaultImpl method removeUserTokens.

@Override
public void removeUserTokens(String username) {
    try {
        User user = userService.getUserByEmail(username);
        List<AuthToken> authTokens = authTokenService.findUserAuthTokens(user.getUuid());
        for (AuthToken authToken : authTokens) {
            authTokenService.deleteAuthToken(authToken.getUuid());
        }
    } catch (Throwable e) {
        throw new RuntimeException("Failed to delete user auth tokens", e);
    }
}
Also used : User(org.summerb.microservices.users.api.dto.User) AuthToken(org.summerb.microservices.users.api.dto.AuthToken)

Example 2 with AuthToken

use of org.summerb.microservices.users.api.dto.AuthToken in project summerb by skarpushin.

the class AuthTokenServiceImpl method updateToken.

@Override
@Transactional(rollbackFor = Throwable.class)
public void updateToken(String authTokenUuid, long lastVerifiedAt, String newTokenValue) throws AuthTokenNotFoundException, FieldValidationException {
    Preconditions.checkArgument(authTokenUuid != null);
    Preconditions.checkArgument(StringUtils.hasText(newTokenValue), "TokenValue is mandatory");
    try {
        // First - check token itself
        AuthToken authToken = getAuthTokenByUuid(authTokenUuid);
        if (newTokenValue.equals(authToken.getTokenValue())) {
            throw new FieldValidationException(new ValidationError("validation.newValueExpected", "newTokenValue"));
        }
        // Now we need to update time when token was checked
        authTokenDao.updateToken(authTokenUuid, lastVerifiedAt, newTokenValue);
    } catch (Throwable t) {
        Throwables.throwIfInstanceOf(t, FieldValidationException.class);
        Throwables.throwIfInstanceOf(t, AuthTokenNotFoundException.class);
        String msg = String.format("Failed to update token '%s'", authTokenUuid);
        throw new UserServiceUnexpectedException(msg, t);
    }
}
Also used : FieldValidationException(org.summerb.approaches.validation.FieldValidationException) UserServiceUnexpectedException(org.summerb.microservices.users.api.exceptions.UserServiceUnexpectedException) AuthToken(org.summerb.microservices.users.api.dto.AuthToken) AuthTokenNotFoundException(org.summerb.microservices.users.api.exceptions.AuthTokenNotFoundException) ValidationError(org.summerb.approaches.validation.ValidationError) Transactional(org.springframework.transaction.annotation.Transactional)

Example 3 with AuthToken

use of org.summerb.microservices.users.api.dto.AuthToken in project summerb by skarpushin.

the class AuthTokenServiceImpl method buildNewAuthToken.

private AuthToken buildNewAuthToken(User user, String clientIp, String tokenUuid, String tokenValueUuid) {
    long now = getNow();
    AuthToken ret = new AuthToken();
    ret.setClientIp(clientIp);
    ret.setCreatedAt(now);
    ret.setExpiresAt(calculateAuthTokenExpirationPoint(now));
    ret.setLastVerifiedAt(now);
    ret.setUserUuid(user.getUuid());
    ret.setUuid(tokenUuid);
    ret.setTokenValue(tokenValueUuid);
    return ret;
}
Also used : AuthToken(org.summerb.microservices.users.api.dto.AuthToken)

Example 4 with AuthToken

use of org.summerb.microservices.users.api.dto.AuthToken in project summerb by skarpushin.

the class AuthTokenServiceImpl method isAuthTokenValid.

@Override
@Transactional(rollbackFor = Throwable.class)
public AuthToken isAuthTokenValid(String userUuid, String authTokenUuid, String tokenValue) throws UserNotFoundException {
    Preconditions.checkArgument(userUuid != null);
    Preconditions.checkArgument(authTokenUuid != null);
    Preconditions.checkArgument(StringUtils.hasText(tokenValue), "TokenValue is mandatory");
    try {
        // First - check token itself
        AuthToken authToken = getAuthTokenByUuid(authTokenUuid);
        if (authToken.getExpiresAt() < getNow()) {
            authTokenDao.deleteAuthToken(authTokenUuid);
            return null;
        }
        if (!tokenValue.equals(authToken.getTokenValue())) {
            return null;
        }
        // Check reference to user
        User user = userService.getUserByUuid(userUuid);
        if (!authToken.getUserUuid().equals(user.getUuid())) {
            return null;
        }
        // Now we need to update time when token was checked
        authToken.setTokenValue(UUID.randomUUID().toString());
        authToken.setLastVerifiedAt(getNow());
        authTokenDao.updateToken(authTokenUuid, authToken.getLastVerifiedAt(), authToken.getTokenValue());
        return authToken;
    } catch (AuthTokenNotFoundException nfe) {
        return null;
    } catch (Throwable t) {
        Throwables.throwIfInstanceOf(t, UserNotFoundException.class);
        String msg = String.format("Failed to check auth token '%s' validity for user '%s'", authTokenUuid, userUuid);
        throw new UserServiceUnexpectedException(msg, t);
    }
}
Also used : UserNotFoundException(org.summerb.microservices.users.api.exceptions.UserNotFoundException) User(org.summerb.microservices.users.api.dto.User) UserServiceUnexpectedException(org.summerb.microservices.users.api.exceptions.UserServiceUnexpectedException) AuthToken(org.summerb.microservices.users.api.dto.AuthToken) AuthTokenNotFoundException(org.summerb.microservices.users.api.exceptions.AuthTokenNotFoundException) Transactional(org.springframework.transaction.annotation.Transactional)

Example 5 with AuthToken

use of org.summerb.microservices.users.api.dto.AuthToken in project summerb by skarpushin.

the class AuthTokenDaoInMemoryImpl method updateToken.

@Override
public synchronized void updateToken(String authTokenUuid, long now, String newTokenValue) {
    AuthToken token = tokens.get(authTokenUuid);
    if (token == null || token.getLastVerifiedAt() >= now) {
        return;
    }
    token.setLastVerifiedAt(now);
    token.setTokenValue(newTokenValue);
}
Also used : AuthToken(org.summerb.microservices.users.api.dto.AuthToken)

Aggregations

AuthToken (org.summerb.microservices.users.api.dto.AuthToken)28 Test (org.junit.Test)12 User (org.summerb.microservices.users.api.dto.User)11 Transactional (org.springframework.transaction.annotation.Transactional)3 FieldValidationException (org.summerb.approaches.validation.FieldValidationException)3 UserNotFoundException (org.summerb.microservices.users.api.exceptions.UserNotFoundException)3 UserServiceUnexpectedException (org.summerb.microservices.users.api.exceptions.UserServiceUnexpectedException)3 File (java.io.File)2 Date (java.util.Date)2 AuthTokenNotFoundException (org.summerb.microservices.users.api.exceptions.AuthTokenNotFoundException)2 BufferedReader (java.io.BufferedReader)1 FileReader (java.io.FileReader)1 FileWriter (java.io.FileWriter)1 PrintWriter (java.io.PrintWriter)1 ArrayList (java.util.ArrayList)1 LinkedList (java.util.LinkedList)1 UsernameNotFoundException (org.springframework.security.core.userdetails.UsernameNotFoundException)1 PersistentRememberMeToken (org.springframework.security.web.authentication.rememberme.PersistentRememberMeToken)1 PagerParams (org.summerb.approaches.jdbccrud.api.dto.PagerParams)1 PaginatedList (org.summerb.approaches.jdbccrud.api.dto.PaginatedList)1