Class TwoFactorAuthenticationSuccessHandler

java.lang.Object
springboot.bg.harisauto.twofactor.TwoFactorAuthenticationSuccessHandler
All Implemented Interfaces:
org.springframework.security.web.authentication.AuthenticationSuccessHandler

@Component public class TwoFactorAuthenticationSuccessHandler extends Object implements org.springframework.security.web.authentication.AuthenticationSuccessHandler
TwoFactorAuthenticationSuccessHandler.java - Holds a password sign-in back until an emailed code is confirmed.

The password check has already passed by the time this runs. Rather than letting the session become authenticated, the security context is cleared and the user id is parked on the session under PENDING_USER_ID. Only TwoFactorController can turn that into a real authentication, and only against a correct code - so a half-finished sign-in carries no authority anywhere in the application.

Author:
Kristian Popov
  • Field Details

    • PENDING_USER_ID

      public static final String PENDING_USER_ID
      Session attribute holding the user awaiting code verification.
      See Also:
  • Constructor Details

  • Method Details

    • onAuthenticationSuccess

      public void onAuthenticationSuccess(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, org.springframework.security.core.Authentication authentication) throws IOException
      Specified by:
      onAuthenticationSuccess in interface org.springframework.security.web.authentication.AuthenticationSuccessHandler
      Throws:
      IOException