Class AuthenticationInfo


  • @PublicAPI(stability=UNCOMMITTED,
               mayInstantiate=true,
               mayExtend=false,
               mayInvoke=true)
    public final class AuthenticationInfo
    extends Object
    This class defines a data structure that may be used to store information about an authenticated user. Note that structures in this class allow for multiple authentication types for the same user, which is not currently supported by LDAP but may be offered through some type of extension.
    • Constructor Summary

      Constructors 
      Constructor Description
      AuthenticationInfo()
      Creates a new set of authentication information to be used for unauthenticated clients.
      AuthenticationInfo​(Entry authenticationEntry, boolean isRoot)
      Creates a new set of authentication information to be used for clients that are authenticated internally.
      AuthenticationInfo​(Entry authenticationEntry, String saslMechanism, boolean isRoot)
      Creates a new set of authentication information to be used for clients that have authenticated using a SASL mechanism.
      AuthenticationInfo​(Entry authenticationEntry, DN simpleBindDN, boolean isRoot)
      Creates a new set of authentication information to be used for clients that have successfully performed simple authentication.
      AuthenticationInfo​(Entry authenticationEntry, Entry authorizationEntry, String saslMechanism, ByteString saslCredentials, boolean isRoot)
      Creates a new set of authentication information to be used for clients that have authenticated using a SASL mechanism.
    • Method Summary

      All Methods Instance Methods Concrete Methods 
      Modifier and Type Method Description
      AuthenticationInfo duplicate​(Entry newAuthenticationEntry, Entry newAuthorizationEntry)
      Creates a duplicate of this AuthenticationInfo object with the new authentication and authorization entries.
      DN getAuthenticationDN()
      Retrieves the DN of the user as whom the client is authenticated.
      Entry getAuthenticationEntry()
      Retrieves the entry for the user as whom the client is authenticated.
      DN getAuthorizationDN()
      Retrieves the DN for the user that should be used as the default authorization identity.
      Entry getAuthorizationEntry()
      Retrieves the entry for the user that should be used as the default authorization identity.
      DN getSimpleBindDN()
      Retrieves the bind DN that the client used for simple authentication.
      boolean hasAuthenticationType​(AuthenticationType authenticationType)
      Indicates whether this client has authenticated using the specified authentication type.
      boolean hasSASLMechanism​(String saslMechanism)
      Indicates whether the client is currently authenticated using the specified SASL mechanism.
      boolean isAuthenticated()
      Indicates whether this client has successfully authenticated to the server.
      boolean isRoot()
      Indicates whether this client should be considered a root user.
      boolean mustChangePassword()
      Indicates whether the authenticated user must change his/her password before any other operation will be allowed.
      void setAuthenticationDN​(DN dn)
      Sets the DN of the user as whom the client is authenticated, does nothing if the client is unauthenticated.
      void setAuthorizationDN​(DN dn)
      Sets the DN for the user that should be used as the default authorization identity, does nothing if the client is unauthorized.
      void setMustChangePassword​(boolean mustChangePassword)
      Specifies whether the authenticated user must change his/her password before any other operation will be allowed.
      String toString()
      Retrieves a string representation of this authentication info structure.
    • Constructor Detail

      • AuthenticationInfo

        public AuthenticationInfo()
        Creates a new set of authentication information to be used for unauthenticated clients.
      • AuthenticationInfo

        public AuthenticationInfo​(Entry authenticationEntry,
                                  boolean isRoot)
        Creates a new set of authentication information to be used for clients that are authenticated internally.
        Parameters:
        authenticationEntry - The entry of the user that has authenticated, or null to indicate an unauthenticated user.
        isRoot - Indicates whether the authenticated user is a root user.
      • AuthenticationInfo

        public AuthenticationInfo​(Entry authenticationEntry,
                                  DN simpleBindDN,
                                  boolean isRoot)
        Creates a new set of authentication information to be used for clients that have successfully performed simple authentication.
        Parameters:
        authenticationEntry - The entry of the user that has authenticated. It must not be null.
        simpleBindDN - The bind DN that was used to perform the simple authentication.
        isRoot - Indicates whether the authenticated
      • AuthenticationInfo

        public AuthenticationInfo​(Entry authenticationEntry,
                                  String saslMechanism,
                                  boolean isRoot)
        Creates a new set of authentication information to be used for clients that have authenticated using a SASL mechanism.
        Parameters:
        authenticationEntry - The entry of the user that has authenticated. It must not be null.
        saslMechanism - The SASL mechanism used to authenticate. This must be provided in all-uppercase characters and must not be null.
        isRoot - Indicates whether the authenticated user is a root user.
      • AuthenticationInfo

        public AuthenticationInfo​(Entry authenticationEntry,
                                  Entry authorizationEntry,
                                  String saslMechanism,
                                  ByteString saslCredentials,
                                  boolean isRoot)
        Creates a new set of authentication information to be used for clients that have authenticated using a SASL mechanism.
        Parameters:
        authenticationEntry - The entry of the user that has authenticated. It must not be null.
        authorizationEntry - The entry of the user that will be used as the default authorization identity, or null to indicate that the authorization identity should be the unauthenticated user.
        saslMechanism - The SASL mechanism used to authenticate. This must be provided in all-uppercase characters and must not be null.
        saslCredentials - The SASL credentials used to authenticate. It must not be null.
        isRoot - Indicates whether the authenticated user is a root user.
    • Method Detail

      • isAuthenticated

        public boolean isAuthenticated()
        Indicates whether this client has successfully authenticated to the server.
        Returns:
        true if this client has successfully authenticated to the server, or false if not.
      • isRoot

        public boolean isRoot()
        Indicates whether this client should be considered a root user.
        Returns:
        true if this client should be considered a root user, or false if not.
      • mustChangePassword

        public boolean mustChangePassword()
        Indicates whether the authenticated user must change his/her password before any other operation will be allowed.
        Returns:
        true if the user must change his/her password before any other operation will be allowed, or false if not.
      • setMustChangePassword

        public void setMustChangePassword​(boolean mustChangePassword)
        Specifies whether the authenticated user must change his/her password before any other operation will be allowed.
        Parameters:
        mustChangePassword - Specifies whether the authenticated user must change his/her password before any other operation will be allowed.
      • hasAuthenticationType

        public boolean hasAuthenticationType​(AuthenticationType authenticationType)
        Indicates whether this client has authenticated using the specified authentication type.
        Parameters:
        authenticationType - The authentication type for which to make the determination.
        Returns:
        true if the client has authenticated using the specified authentication type, or false if not.
      • getAuthenticationEntry

        public Entry getAuthenticationEntry()
        Retrieves the entry for the user as whom the client is authenticated.
        Returns:
        The entry for the user as whom the client is authenticated, or null if the client is unauthenticated.
      • getAuthenticationDN

        public DN getAuthenticationDN()
        Retrieves the DN of the user as whom the client is authenticated.
        Returns:
        The DN of the user as whom the client is authenticated, or null if the client is unauthenticated.
      • setAuthenticationDN

        public void setAuthenticationDN​(DN dn)
        Sets the DN of the user as whom the client is authenticated, does nothing if the client is unauthenticated.
        Parameters:
        dn - authentication identity DN.
      • getAuthorizationEntry

        public Entry getAuthorizationEntry()
        Retrieves the entry for the user that should be used as the default authorization identity.
        Returns:
        The entry for the user that should be used as the default authorization identity, or null if the authorization identity should be the unauthenticated user.
      • getAuthorizationDN

        public DN getAuthorizationDN()
        Retrieves the DN for the user that should be used as the default authorization identity.
        Returns:
        The DN for the user that should be used as the default authorization identity, or null if the authorization identity should be the unauthenticated user.
      • setAuthorizationDN

        public void setAuthorizationDN​(DN dn)
        Sets the DN for the user that should be used as the default authorization identity, does nothing if the client is unauthorized.
        Parameters:
        dn - authorization identity DN.
      • getSimpleBindDN

        public DN getSimpleBindDN()
        Retrieves the bind DN that the client used for simple authentication.
        Returns:
        The bind DN that the client used for simple authentication, or null if the client is not authenticated using simple authentication.
      • hasSASLMechanism

        public boolean hasSASLMechanism​(String saslMechanism)
        Indicates whether the client is currently authenticated using the specified SASL mechanism.
        Parameters:
        saslMechanism - The SASL mechanism for which to make the determination. Note that this must be provided in all uppercase characters.
        Returns:
        true if the client is authenticated using the specified SASL mechanism, or false if not.
      • toString

        public String toString()
        Retrieves a string representation of this authentication info structure.
        Overrides:
        toString in class Object
        Returns:
        A string representation of this authentication info structure.
      • duplicate

        public AuthenticationInfo duplicate​(Entry newAuthenticationEntry,
                                            Entry newAuthorizationEntry)
        Creates a duplicate of this AuthenticationInfo object with the new authentication and authorization entries.
        Parameters:
        newAuthenticationEntry - The updated entry for the user as whom the associated client connection is authenticated.
        newAuthorizationEntry - The updated entry for the default authorization identity for the associated client connection.
        Returns:
        The duplicate of this AuthenticationInfo object with the specified authentication and authorization entries.