Class UserManagerImpl

java.lang.Object
ubic.gemma.core.security.authentication.UserManagerImpl
All Implemented Interfaces:
org.springframework.security.core.userdetails.UserDetailsPasswordService, org.springframework.security.core.userdetails.UserDetailsService, org.springframework.security.provisioning.GroupManager, org.springframework.security.provisioning.UserDetailsManager, GroupManager, UserDetailsManager, UserManager

@Service("userManager") public class UserManagerImpl extends Object implements UserManager, org.springframework.security.core.userdetails.UserDetailsPasswordService
Implementation for Spring Security, plus some other handy methods.
Author:
pavlidis
  • Constructor Details

    • UserManagerImpl

      public UserManagerImpl()
  • Method Details

    • changePasswordForUser

      @Transactional public String changePasswordForUser(String email, String username, String newPassword) throws org.springframework.security.core.AuthenticationException
      Specified by:
      changePasswordForUser in interface UserDetailsManager
      Specified by:
      changePasswordForUser in interface UserManager
      Parameters:
      email -
      username -
      newPassword - - encoded
      Returns:
      the confirmation token they will need to use.
      Throws:
      org.springframework.security.core.AuthenticationException
    • findAllUsers

      @Transactional(readOnly=true) public Collection<String> findAllUsers()
      Specified by:
      findAllUsers in interface UserDetailsManager
      Returns:
      list of all available usernames.
    • createUser

      @Transactional public UserDetailsImpl createUser(String username, String email, String password)
      Specified by:
      createUser in interface UserManager
    • findByEmail

      @Transactional(readOnly=true) public User findByEmail(String emailAddress)
      Specified by:
      findByEmail in interface UserManager
    • findByUserName

      @Transactional(readOnly=true) public User findByUserName(String userName)
      Specified by:
      findByUserName in interface UserManager
    • findGroupsForUser

      @Transactional(readOnly=true) public Collection<String> findGroupsForUser(String userName)
      Description copied from interface: GroupManager
      Find all the group a user is in.
      Specified by:
      findGroupsForUser in interface GroupManager
      Specified by:
      findGroupsForUser in interface UserManager
    • generateSignupToken

      public String generateSignupToken(String username)
      Description copied from interface: UserDetailsManager
      Generate a token that can be used to check if the user's email is valid.
      Specified by:
      generateSignupToken in interface UserDetailsManager
      Parameters:
      username -
      Returns:
    • getCurrentUser

      @Transactional(readOnly=true) public User getCurrentUser()
      Description copied from interface: UserManager
      Obtain the User corresponding to the currently logged in user.
      Specified by:
      getCurrentUser in interface UserManager
      Returns:
      the user, or null if no user is logged in
    • getCurrentUsername

      public String getCurrentUsername()
      Description copied from interface: UserManager
      Obtain the username of the currently logged in user.

      If no user is logged in, the principal of the anonymous authentication token is returned.

      Specified by:
      getCurrentUsername in interface UserDetailsManager
      Specified by:
      getCurrentUsername in interface UserManager
    • groupExists

      @Transactional(readOnly=true) public boolean groupExists(String groupName)
      Description copied from interface: GroupManager
      Check if a group with a given name exists.
      Specified by:
      groupExists in interface GroupManager
    • loadAll

      @Transactional(readOnly=true) public Collection<User> loadAll()
      Specified by:
      loadAll in interface UserManager
    • loggedIn

      public boolean loggedIn()
      Specified by:
      loggedIn in interface UserDetailsManager
    • reauthenticate

      public void reauthenticate(String username, String password)
      Description copied from interface: UserDetailsManager
      Sign in the user identified
      Specified by:
      reauthenticate in interface UserDetailsManager
      Parameters:
      username -
      password -
    • userWithEmailExists

      @Transactional(readOnly=true) public boolean userWithEmailExists(String emailAddress)
      Specified by:
      userWithEmailExists in interface UserDetailsManager
      Specified by:
      userWithEmailExists in interface UserManager
      Parameters:
      emailAddress -
      Returns:
    • validateSignupToken

      @Transactional public boolean validateSignupToken(String username, String key)
      Description copied from interface: UserDetailsManager
      Validate the token previously generated by UserDetailsManager.generateSignupToken(String).
      Specified by:
      validateSignupToken in interface UserDetailsManager
      Specified by:
      validateSignupToken in interface UserManager
      Parameters:
      username -
      key -
      Returns:
      true if okay, false otherwise
    • createUser

      @Transactional public void createUser(org.springframework.security.core.userdetails.UserDetails user)
      Specified by:
      createUser in interface org.springframework.security.provisioning.UserDetailsManager
      Specified by:
      createUser in interface UserManager
    • updateUser

      @Transactional public void updateUser(org.springframework.security.core.userdetails.UserDetails user)
      Specified by:
      updateUser in interface org.springframework.security.provisioning.UserDetailsManager
      Specified by:
      updateUser in interface UserManager
    • updateUserGroups

      @Transactional public void updateUserGroups(org.springframework.security.core.userdetails.UserDetails userDetails, Collection<String> groups)
      Description copied from interface: UserManager
      Update the groups a user belong to.
      Specified by:
      updateUserGroups in interface UserManager
    • softDeleteUser

      @Transactional public void softDeleteUser(String username, String deletedByUsername)
      Description copied from interface: UserManager
      Mark the named user as deleted without removing the row. Sets deletedAt = now, deletedBy = the supplied admin username, and enabled = false. ACL sids, audit-event authorship FKs, and other references to the row are preserved. Hard delete remains available via UserManager.deleteUser(String) for the rare cases where the row truly has no dependents.
      Specified by:
      softDeleteUser in interface UserManager
    • deleteUser

      @Transactional public void deleteUser(String username)
      Specified by:
      deleteUser in interface org.springframework.security.provisioning.UserDetailsManager
      Specified by:
      deleteUser in interface UserManager
    • changePassword

      @Transactional public void changePassword(String oldPassword, String newPassword) throws org.springframework.security.core.AuthenticationException
      Specified by:
      changePassword in interface org.springframework.security.provisioning.UserDetailsManager
      Specified by:
      changePassword in interface UserManager
      Throws:
      org.springframework.security.core.AuthenticationException
    • adminChangePassword

      @Transactional public void adminChangePassword(String username, String newPassword)
      Description copied from interface: UserManager
      Administrative password reset: set a new password for the named user without requiring their current password. Distinct from UserManager.changePasswordForUser(String, String, String) (the email-confirmation reset flow, which disables the account and issues a signup token) — this leaves the account enabled and immediately usable. The new password is encoded before storage.
      Specified by:
      adminChangePassword in interface UserManager
    • userExists

      @Transactional(readOnly=true) public boolean userExists(String username)
      Specified by:
      userExists in interface org.springframework.security.provisioning.UserDetailsManager
      Specified by:
      userExists in interface UserManager
    • findAllGroups

      @Transactional(readOnly=true) public List<String> findAllGroups()
      Specified by:
      findAllGroups in interface org.springframework.security.provisioning.GroupManager
    • findUsersInGroup

      @Transactional(readOnly=true) public List<String> findUsersInGroup(String groupName)
      Specified by:
      findUsersInGroup in interface org.springframework.security.provisioning.GroupManager
    • createGroup

      @Transactional public void createGroup(String groupName, List<org.springframework.security.core.GrantedAuthority> authorities)
      Specified by:
      createGroup in interface org.springframework.security.provisioning.GroupManager
    • deleteGroup

      @Transactional public void deleteGroup(String groupName)
      Specified by:
      deleteGroup in interface org.springframework.security.provisioning.GroupManager
    • renameGroup

      @Transactional public void renameGroup(String oldName, String newName)
      Specified by:
      renameGroup in interface org.springframework.security.provisioning.GroupManager
    • setGroupDescription

      @Transactional public void setGroupDescription(String groupName, String description)
      Description copied from interface: GroupManager
      Update the human-readable description of a group. Spring's GroupManager has no equivalent — the description field is Gemma-specific (on the UserGroup entity).
      Specified by:
      setGroupDescription in interface GroupManager
      Parameters:
      groupName - the group to update (looked up by name).
      description - new description; null clears the field.
    • addUserToGroup

      @Transactional public void addUserToGroup(String username, String groupName)
      Specified by:
      addUserToGroup in interface org.springframework.security.provisioning.GroupManager
    • removeUserFromGroup

      @Transactional public void removeUserFromGroup(String username, String groupName)
      Specified by:
      removeUserFromGroup in interface org.springframework.security.provisioning.GroupManager
    • findGroupAuthorities

      @Transactional(readOnly=true) public List<org.springframework.security.core.GrantedAuthority> findGroupAuthorities(String groupName)
      Specified by:
      findGroupAuthorities in interface org.springframework.security.provisioning.GroupManager
    • addGroupAuthority

      @Transactional public void addGroupAuthority(String groupName, org.springframework.security.core.GrantedAuthority authority)
      Specified by:
      addGroupAuthority in interface org.springframework.security.provisioning.GroupManager
    • removeGroupAuthority

      @Transactional public void removeGroupAuthority(String groupName, org.springframework.security.core.GrantedAuthority authority)
      Specified by:
      removeGroupAuthority in interface org.springframework.security.provisioning.GroupManager
    • isEnableAuthorities

      public boolean isEnableAuthorities()
    • setEnableAuthorities

      public void setEnableAuthorities(boolean enableAuthorities)
    • isEnableGroups

      public boolean isEnableGroups()
    • setEnableGroups

      public void setEnableGroups(boolean enableGroups)
    • loadUserByUsername

      @Transactional(readOnly=true) public org.springframework.security.core.userdetails.UserDetails loadUserByUsername(String username) throws org.springframework.security.core.userdetails.UsernameNotFoundException
      Specified by:
      loadUserByUsername in interface org.springframework.security.core.userdetails.UserDetailsService
      Throws:
      org.springframework.security.core.userdetails.UsernameNotFoundException
    • updatePassword

      @Transactional public org.springframework.security.core.userdetails.UserDetails updatePassword(org.springframework.security.core.userdetails.UserDetails user, String newPassword)
      Spring Security 6's password-upgrade hook. Called by DaoAuthenticationProvider.authenticate(...) when the configured PasswordEncoder reports upgradeEncoding(storedHash) == true after a successful auth — i.e., when a user logs in with a legacy SHA-1 password that should be re-encoded as {bcrypt}. The framework supplies the already-encoded new hash; this implementation just persists it.

      This replaces the prior ThreadLocal-based upgrade scheme (see LegacyAwareDaoAuthenticationProvider class javadoc): no thread-bound state, works under async / reactive flows.

      Specified by:
      updatePassword in interface org.springframework.security.core.userdetails.UserDetailsPasswordService
    • loadUsersByUsername

      protected List<org.springframework.security.core.userdetails.UserDetails> loadUsersByUsername(String username)