Class UserManagerImpl
java.lang.Object
ubic.gemma.core.security.authentication.UserManagerImpl
- All Implemented Interfaces:
org.springframework.security.core.userdetails.UserDetailsPasswordService, org.springframework.security.core.userdetails.UserDetailsService, org.springframework.security.provisioning.GroupManager, org.springframework.security.provisioning.UserDetailsManager, GroupManager, UserDetailsManager, UserManager
@Service("userManager")
public class UserManagerImpl
extends Object
implements UserManager, org.springframework.security.core.userdetails.UserDetailsPasswordService
Implementation for Spring Security, plus some other handy methods.
- Author:
- pavlidis
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidaddGroupAuthority(String groupName, org.springframework.security.core.GrantedAuthority authority) voidaddUserToGroup(String username, String groupName) voidadminChangePassword(String username, String newPassword) Administrative password reset: set a new password for the named user without requiring their current password.voidchangePassword(String oldPassword, String newPassword) changePasswordForUser(String email, String username, String newPassword) voidcreateGroup(String groupName, List<org.springframework.security.core.GrantedAuthority> authorities) createUser(String username, String email, String password) voidcreateUser(org.springframework.security.core.userdetails.UserDetails user) voiddeleteGroup(String groupName) voiddeleteUser(String username) findByEmail(String emailAddress) findByUserName(String userName) List<org.springframework.security.core.GrantedAuthority> findGroupAuthorities(String groupName) findGroupsForUser(String userName) Find all the group a user is in.findUsersInGroup(String groupName) generateSignupToken(String username) Generate a token that can be used to check if the user's email is valid.Obtain theUsercorresponding to the currently logged in user.Obtain the username of the currently logged in user.booleangroupExists(String groupName) Check if a group with a given name exists.booleanbooleanloadAll()org.springframework.security.core.userdetails.UserDetailsloadUserByUsername(String username) protected List<org.springframework.security.core.userdetails.UserDetails> loadUsersByUsername(String username) booleanloggedIn()voidreauthenticate(String username, String password) Sign in the user identifiedvoidremoveGroupAuthority(String groupName, org.springframework.security.core.GrantedAuthority authority) voidremoveUserFromGroup(String username, String groupName) voidrenameGroup(String oldName, String newName) voidsetEnableAuthorities(boolean enableAuthorities) voidsetEnableGroups(boolean enableGroups) voidsetGroupDescription(String groupName, String description) Update the human-readable description of a group.voidsoftDeleteUser(String username, String deletedByUsername) Mark the named user as deleted without removing the row.org.springframework.security.core.userdetails.UserDetailsupdatePassword(org.springframework.security.core.userdetails.UserDetails user, String newPassword) Spring Security 6's password-upgrade hook.voidupdateUser(org.springframework.security.core.userdetails.UserDetails user) voidupdateUserGroups(org.springframework.security.core.userdetails.UserDetails userDetails, Collection<String> groups) Update the groups a user belong to.booleanuserExists(String username) booleanuserWithEmailExists(String emailAddress) booleanvalidateSignupToken(String username, String key) Validate the token previously generated byUserDetailsManager.generateSignupToken(String).
-
Constructor Details
-
UserManagerImpl
public UserManagerImpl()
-
-
Method Details
-
changePasswordForUser
@Transactional public String changePasswordForUser(String email, String username, String newPassword) throws org.springframework.security.core.AuthenticationException - Specified by:
changePasswordForUserin interfaceUserDetailsManager- Specified by:
changePasswordForUserin interfaceUserManager- Parameters:
email-username-newPassword- - encoded- Returns:
- the confirmation token they will need to use.
- Throws:
org.springframework.security.core.AuthenticationException
-
findAllUsers
- Specified by:
findAllUsersin interfaceUserDetailsManager- Returns:
- list of all available usernames.
-
createUser
- Specified by:
createUserin interfaceUserManager
-
findByEmail
- Specified by:
findByEmailin interfaceUserManager
-
findByUserName
- Specified by:
findByUserNamein interfaceUserManager
-
findGroupsForUser
Description copied from interface:GroupManagerFind all the group a user is in.- Specified by:
findGroupsForUserin interfaceGroupManager- Specified by:
findGroupsForUserin interfaceUserManager
-
generateSignupToken
Description copied from interface:UserDetailsManagerGenerate a token that can be used to check if the user's email is valid.- Specified by:
generateSignupTokenin interfaceUserDetailsManager- Parameters:
username-- Returns:
-
getCurrentUser
Description copied from interface:UserManagerObtain theUsercorresponding to the currently logged in user.- Specified by:
getCurrentUserin interfaceUserManager- Returns:
- the user, or null if no user is logged in
-
getCurrentUsername
Description copied from interface:UserManagerObtain the username of the currently logged in user.If no user is logged in, the principal of the anonymous authentication token is returned.
- Specified by:
getCurrentUsernamein interfaceUserDetailsManager- Specified by:
getCurrentUsernamein interfaceUserManager
-
groupExists
Description copied from interface:GroupManagerCheck if a group with a given name exists.- Specified by:
groupExistsin interfaceGroupManager
-
loadAll
- Specified by:
loadAllin interfaceUserManager
-
loggedIn
public boolean loggedIn()- Specified by:
loggedInin interfaceUserDetailsManager
-
reauthenticate
Description copied from interface:UserDetailsManagerSign in the user identified- Specified by:
reauthenticatein interfaceUserDetailsManager- Parameters:
username-password-
-
userWithEmailExists
- Specified by:
userWithEmailExistsin interfaceUserDetailsManager- Specified by:
userWithEmailExistsin interfaceUserManager- Parameters:
emailAddress-- Returns:
-
validateSignupToken
Description copied from interface:UserDetailsManagerValidate the token previously generated byUserDetailsManager.generateSignupToken(String).- Specified by:
validateSignupTokenin interfaceUserDetailsManager- Specified by:
validateSignupTokenin interfaceUserManager- Parameters:
username-key-- Returns:
- true if okay, false otherwise
-
createUser
@Transactional public void createUser(org.springframework.security.core.userdetails.UserDetails user) - Specified by:
createUserin interfaceorg.springframework.security.provisioning.UserDetailsManager- Specified by:
createUserin interfaceUserManager
-
updateUser
@Transactional public void updateUser(org.springframework.security.core.userdetails.UserDetails user) - Specified by:
updateUserin interfaceorg.springframework.security.provisioning.UserDetailsManager- Specified by:
updateUserin interfaceUserManager
-
updateUserGroups
@Transactional public void updateUserGroups(org.springframework.security.core.userdetails.UserDetails userDetails, Collection<String> groups) Description copied from interface:UserManagerUpdate the groups a user belong to.- Specified by:
updateUserGroupsin interfaceUserManager
-
softDeleteUser
Description copied from interface:UserManagerMark the named user as deleted without removing the row. SetsdeletedAt= now,deletedBy= the supplied admin username, andenabled= false. ACL sids, audit-event authorship FKs, and other references to the row are preserved. Hard delete remains available viaUserManager.deleteUser(String)for the rare cases where the row truly has no dependents.- Specified by:
softDeleteUserin interfaceUserManager
-
deleteUser
- Specified by:
deleteUserin interfaceorg.springframework.security.provisioning.UserDetailsManager- Specified by:
deleteUserin interfaceUserManager
-
changePassword
@Transactional public void changePassword(String oldPassword, String newPassword) throws org.springframework.security.core.AuthenticationException - Specified by:
changePasswordin interfaceorg.springframework.security.provisioning.UserDetailsManager- Specified by:
changePasswordin interfaceUserManager- Throws:
org.springframework.security.core.AuthenticationException
-
adminChangePassword
Description copied from interface:UserManagerAdministrative password reset: set a new password for the named user without requiring their current password. Distinct fromUserManager.changePasswordForUser(String, String, String)(the email-confirmation reset flow, which disables the account and issues a signup token) — this leaves the account enabled and immediately usable. The new password is encoded before storage.- Specified by:
adminChangePasswordin interfaceUserManager
-
userExists
- Specified by:
userExistsin interfaceorg.springframework.security.provisioning.UserDetailsManager- Specified by:
userExistsin interfaceUserManager
-
findAllGroups
-
findUsersInGroup
-
createGroup
-
deleteGroup
- Specified by:
deleteGroupin interfaceorg.springframework.security.provisioning.GroupManager
-
renameGroup
-
setGroupDescription
Description copied from interface:GroupManagerUpdate the human-readable description of a group. Spring'sGroupManagerhas no equivalent — the description field is Gemma-specific (on theUserGroupentity).- Specified by:
setGroupDescriptionin interfaceGroupManager- Parameters:
groupName- the group to update (looked up by name).description- new description;nullclears the field.
-
addUserToGroup
-
removeUserFromGroup
-
findGroupAuthorities
-
addGroupAuthority
@Transactional public void addGroupAuthority(String groupName, org.springframework.security.core.GrantedAuthority authority) - Specified by:
addGroupAuthorityin interfaceorg.springframework.security.provisioning.GroupManager
-
removeGroupAuthority
@Transactional public void removeGroupAuthority(String groupName, org.springframework.security.core.GrantedAuthority authority) - Specified by:
removeGroupAuthorityin interfaceorg.springframework.security.provisioning.GroupManager
-
isEnableAuthorities
public boolean isEnableAuthorities() -
setEnableAuthorities
public void setEnableAuthorities(boolean enableAuthorities) -
isEnableGroups
public boolean isEnableGroups() -
setEnableGroups
public void setEnableGroups(boolean enableGroups) -
loadUserByUsername
@Transactional(readOnly=true) public org.springframework.security.core.userdetails.UserDetails loadUserByUsername(String username) throws org.springframework.security.core.userdetails.UsernameNotFoundException - Specified by:
loadUserByUsernamein interfaceorg.springframework.security.core.userdetails.UserDetailsService- Throws:
org.springframework.security.core.userdetails.UsernameNotFoundException
-
updatePassword
@Transactional public org.springframework.security.core.userdetails.UserDetails updatePassword(org.springframework.security.core.userdetails.UserDetails user, String newPassword) Spring Security 6's password-upgrade hook. Called byDaoAuthenticationProvider.authenticate(...)when the configuredPasswordEncoderreportsupgradeEncoding(storedHash) == trueafter a successful auth — i.e., when a user logs in with a legacy SHA-1 password that should be re-encoded as{bcrypt}. The framework supplies the already-encoded new hash; this implementation just persists it.This replaces the prior ThreadLocal-based upgrade scheme (see
LegacyAwareDaoAuthenticationProviderclass javadoc): no thread-bound state, works under async / reactive flows.- Specified by:
updatePasswordin interfaceorg.springframework.security.core.userdetails.UserDetailsPasswordService
-
loadUsersByUsername
-