Interface UserManager

All Superinterfaces:
org.springframework.security.provisioning.GroupManager, GroupManager, org.springframework.security.provisioning.UserDetailsManager, UserDetailsManager, org.springframework.security.core.userdetails.UserDetailsService
All Known Implementing Classes:
UserManagerImpl

public interface UserManager extends UserDetailsManager, GroupManager
Overrides gsec's UserManager to provide Gemma-specific types.
Author:
poirigui
  • Method Details

    • findByEmail

      @Secured({"GROUP_USER","RUN_AS_ADMIN"}) User findByEmail(String s) throws org.springframework.security.core.userdetails.UsernameNotFoundException
      Throws:
      org.springframework.security.core.userdetails.UsernameNotFoundException
    • findByUserName

      User findByUserName(String s) throws org.springframework.security.core.userdetails.UsernameNotFoundException
      Throws:
      org.springframework.security.core.userdetails.UsernameNotFoundException
    • findGroupsForUser

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_USER"}) Collection<String> findGroupsForUser(String username) throws org.springframework.security.core.userdetails.UsernameNotFoundException
      Description copied from interface: GroupManager
      Find all the group a user is in.
      Specified by:
      findGroupsForUser in interface GroupManager
      Throws:
      org.springframework.security.core.userdetails.UsernameNotFoundException
    • userWithEmailExists

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_ADMIN"}) boolean userWithEmailExists(String emailAddress)
      Specified by:
      userWithEmailExists in interface UserDetailsManager
      Parameters:
      emailAddress -
      Returns:
    • getCurrentUser

      @Nullable User getCurrentUser()
      Obtain the User corresponding to the currently logged in user.
      Returns:
      the user, or null if no user is logged in
    • getCurrentUsername

      String getCurrentUsername()
      Obtain the username of the currently logged in user.

      If no user is logged in, the principal of the anonymous authentication token is returned.

      Specified by:
      getCurrentUsername in interface UserDetailsManager
    • loadAll

      @Secured("GROUP_ADMIN") Collection<User> loadAll()
    • userExists

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_ADMIN"}) boolean userExists(String username)
      Specified by:
      userExists in interface org.springframework.security.provisioning.UserDetailsManager
    • createUser

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_ADMIN"}) UserDetailsImpl createUser(String username, String email, String password)
    • createUser

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_ADMIN"}) void createUser(org.springframework.security.core.userdetails.UserDetails user)
      Specified by:
      createUser in interface org.springframework.security.provisioning.UserDetailsManager
    • updateUser

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_ADMIN"}) void updateUser(org.springframework.security.core.userdetails.UserDetails user)
      Specified by:
      updateUser in interface org.springframework.security.provisioning.UserDetailsManager
    • updateUserGroups

      @Secured("GROUP_ADMIN") void updateUserGroups(org.springframework.security.core.userdetails.UserDetails user, Collection<String> groups)
      Update the groups a user belong to.
    • deleteUser

      @Secured("GROUP_ADMIN") void deleteUser(String username)
      Specified by:
      deleteUser in interface org.springframework.security.provisioning.UserDetailsManager
    • softDeleteUser

      @Secured("GROUP_ADMIN") void softDeleteUser(String username, String deletedByUsername)
      Mark the named user as deleted without removing the row. Sets deletedAt = now, deletedBy = the supplied admin username, and enabled = false. ACL sids, audit-event authorship FKs, and other references to the row are preserved. Hard delete remains available via deleteUser(String) for the rare cases where the row truly has no dependents.
    • changePasswordForUser

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_ADMIN"}) String changePasswordForUser(String email, String username, String newPassword)
      Specified by:
      changePasswordForUser in interface UserDetailsManager
      Parameters:
      email -
      username -
      newPassword - - encoded
      Returns:
      the confirmation token they will need to use.
    • changePassword

      @Secured("GROUP_USER") void changePassword(String oldPassword, String newPassword)
      Specified by:
      changePassword in interface org.springframework.security.provisioning.UserDetailsManager
    • adminChangePassword

      @Secured("GROUP_ADMIN") void adminChangePassword(String username, String newPassword)
      Administrative password reset: set a new password for the named user without requiring their current password. Distinct from changePasswordForUser(String, String, String) (the email-confirmation reset flow, which disables the account and issues a signup token) — this leaves the account enabled and immediately usable. The new password is encoded before storage.
    • validateSignupToken

      @Secured({"IS_AUTHENTICATED_ANONYMOUSLY","RUN_AS_ADMIN"}) boolean validateSignupToken(String username, String key)
      Description copied from interface: UserDetailsManager
      Validate the token previously generated by UserDetailsManager.generateSignupToken(String).
      Specified by:
      validateSignupToken in interface UserDetailsManager
      Parameters:
      username -
      key -
      Returns:
      true if okay, false otherwise