Class TwoFactorAuthenticationSuccessHandler
java.lang.Object
springboot.bg.harisauto.twofactor.TwoFactorAuthenticationSuccessHandler
- All Implemented Interfaces:
org.springframework.security.web.authentication.AuthenticationSuccessHandler
@Component
public class TwoFactorAuthenticationSuccessHandler
extends Object
implements org.springframework.security.web.authentication.AuthenticationSuccessHandler
TwoFactorAuthenticationSuccessHandler.java - Holds a password sign-in back until an
emailed code is confirmed.
The password check has already passed by the time this runs. Rather than letting the
session become authenticated, the security context is cleared and the user id is parked
on the session under PENDING_USER_ID. Only TwoFactorController can turn
that into a real authentication, and only against a correct code - so a half-finished
sign-in carries no authority anywhere in the application.
- Author:
- Kristian Popov
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringSession attribute holding the user awaiting code verification. -
Constructor Summary
ConstructorsConstructorDescriptionTwoFactorAuthenticationSuccessHandler(TwoFactorService twoFactorService, TwoFactorProperties properties, UserService userService) Constructor. -
Method Summary
Modifier and TypeMethodDescriptionvoidonAuthenticationSuccess(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, org.springframework.security.core.Authentication authentication) Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.springframework.security.web.authentication.AuthenticationSuccessHandler
onAuthenticationSuccess
-
Field Details
-
PENDING_USER_ID
Session attribute holding the user awaiting code verification.- See Also:
-
-
Constructor Details
-
TwoFactorAuthenticationSuccessHandler
public TwoFactorAuthenticationSuccessHandler(TwoFactorService twoFactorService, TwoFactorProperties properties, UserService userService) Constructor.
-
-
Method Details
-
onAuthenticationSuccess
public void onAuthenticationSuccess(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response, org.springframework.security.core.Authentication authentication) throws IOException - Specified by:
onAuthenticationSuccessin interfaceorg.springframework.security.web.authentication.AuthenticationSuccessHandler- Throws:
IOException
-