-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Add Support JDBC Repositories For WebAuthn #16282
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
40 changes: 40 additions & 0 deletions
40
.../org/springframework/security/web/aot/hint/PublicKeyCredentialUserEntityRuntimeHints.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,40 @@ | ||
/* | ||
* Copyright 2002-2024 the original author or authors. | ||
* | ||
* Licensed under the Apache License, Version 2.0 (the "License"); | ||
* you may not use this file except in compliance with the License. | ||
* You may obtain a copy of the License at | ||
* | ||
* https://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, software | ||
* distributed under the License is distributed on an "AS IS" BASIS, | ||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
* See the License for the specific language governing permissions and | ||
* limitations under the License. | ||
*/ | ||
|
||
package org.springframework.security.web.aot.hint; | ||
|
||
import org.springframework.aot.hint.RuntimeHints; | ||
import org.springframework.aot.hint.RuntimeHintsRegistrar; | ||
import org.springframework.jdbc.core.JdbcOperations; | ||
import org.springframework.security.web.webauthn.api.PublicKeyCredentialUserEntity; | ||
import org.springframework.security.web.webauthn.management.PublicKeyCredentialUserEntityRepository; | ||
|
||
/** | ||
* | ||
* A JDBC implementation of an {@link PublicKeyCredentialUserEntityRepository} that uses a | ||
* {@link JdbcOperations} for {@link PublicKeyCredentialUserEntity} persistence. | ||
* | ||
* @author Max Batischev | ||
* @since 6.5 | ||
*/ | ||
class PublicKeyCredentialUserEntityRuntimeHints implements RuntimeHintsRegistrar { | ||
|
||
@Override | ||
public void registerHints(RuntimeHints hints, ClassLoader classLoader) { | ||
hints.resources().registerPattern("org/springframework/security/user-entities-schema.sql"); | ||
} | ||
|
||
} |
40 changes: 40 additions & 0 deletions
40
web/src/main/java/org/springframework/security/web/aot/hint/UserCredentialRuntimeHints.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,40 @@ | ||
/* | ||
* Copyright 2002-2024 the original author or authors. | ||
* | ||
* Licensed under the Apache License, Version 2.0 (the "License"); | ||
* you may not use this file except in compliance with the License. | ||
* You may obtain a copy of the License at | ||
* | ||
* https://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, software | ||
* distributed under the License is distributed on an "AS IS" BASIS, | ||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
* See the License for the specific language governing permissions and | ||
* limitations under the License. | ||
*/ | ||
|
||
package org.springframework.security.web.aot.hint; | ||
|
||
import org.springframework.aot.hint.RuntimeHints; | ||
import org.springframework.aot.hint.RuntimeHintsRegistrar; | ||
import org.springframework.jdbc.core.JdbcOperations; | ||
import org.springframework.security.web.webauthn.api.CredentialRecord; | ||
import org.springframework.security.web.webauthn.management.UserCredentialRepository; | ||
|
||
/** | ||
* | ||
* A JDBC implementation of an {@link UserCredentialRepository} that uses a | ||
* {@link JdbcOperations} for {@link CredentialRecord} persistence. | ||
* | ||
* @author Max Batischev | ||
* @since 6.5 | ||
*/ | ||
class UserCredentialRuntimeHints implements RuntimeHintsRegistrar { | ||
|
||
@Override | ||
public void registerHints(RuntimeHints hints, ClassLoader classLoader) { | ||
hints.resources().registerPattern("org/springframework/security/user-credentials-schema.sql"); | ||
} | ||
|
||
} |
193 changes: 193 additions & 0 deletions
193
...amework/security/web/webauthn/management/JdbcPublicKeyCredentialUserEntityRepository.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,193 @@ | ||
/* | ||
* Copyright 2002-2024 the original author or authors. | ||
* | ||
* Licensed under the Apache License, Version 2.0 (the "License"); | ||
* you may not use this file except in compliance with the License. | ||
* You may obtain a copy of the License at | ||
* | ||
* https://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, software | ||
* distributed under the License is distributed on an "AS IS" BASIS, | ||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
* See the License for the specific language governing permissions and | ||
* limitations under the License. | ||
*/ | ||
|
||
package org.springframework.security.web.webauthn.management; | ||
|
||
import java.sql.ResultSet; | ||
import java.sql.SQLException; | ||
import java.sql.Types; | ||
import java.util.ArrayList; | ||
import java.util.List; | ||
import java.util.function.Function; | ||
|
||
import org.springframework.dao.DuplicateKeyException; | ||
import org.springframework.jdbc.core.ArgumentPreparedStatementSetter; | ||
import org.springframework.jdbc.core.JdbcOperations; | ||
import org.springframework.jdbc.core.PreparedStatementSetter; | ||
import org.springframework.jdbc.core.RowMapper; | ||
import org.springframework.jdbc.core.SqlParameterValue; | ||
import org.springframework.security.web.webauthn.api.Bytes; | ||
import org.springframework.security.web.webauthn.api.ImmutablePublicKeyCredentialUserEntity; | ||
import org.springframework.security.web.webauthn.api.PublicKeyCredentialUserEntity; | ||
import org.springframework.util.Assert; | ||
|
||
/** | ||
* A JDBC implementation of an {@link PublicKeyCredentialUserEntityRepository} that uses a | ||
* {@link JdbcOperations} for {@link PublicKeyCredentialUserEntity} persistence. | ||
* | ||
* <b>NOTE:</b> This {@code PublicKeyCredentialUserEntityRepository} depends on the table | ||
* definition described in | ||
* "classpath:org/springframework/security/user-entities-schema.sql" and therefore MUST be | ||
* defined in the database schema. | ||
* | ||
* @author Max Batischev | ||
* @since 6.5 | ||
* @see PublicKeyCredentialUserEntityRepository | ||
* @see PublicKeyCredentialUserEntity | ||
* @see JdbcOperations | ||
* @see RowMapper | ||
*/ | ||
public final class JdbcPublicKeyCredentialUserEntityRepository implements PublicKeyCredentialUserEntityRepository { | ||
|
||
private RowMapper<PublicKeyCredentialUserEntity> userEntityRowMapper = new UserEntityRecordRowMapper(); | ||
|
||
private Function<PublicKeyCredentialUserEntity, List<SqlParameterValue>> userEntityParametersMapper = new UserEntityParametersMapper(); | ||
|
||
private final JdbcOperations jdbcOperations; | ||
|
||
private static final String TABLE_NAME = "user_entities"; | ||
|
||
// @formatter:off | ||
private static final String COLUMN_NAMES = "id, " | ||
+ "name, " | ||
+ "display_name "; | ||
// @formatter:on | ||
|
||
// @formatter:off | ||
private static final String SAVE_USER_SQL = "INSERT INTO " + TABLE_NAME | ||
+ " (" + COLUMN_NAMES + ") VALUES (?, ?, ?)"; | ||
// @formatter:on | ||
|
||
private static final String ID_FILTER = "id = ? "; | ||
|
||
private static final String USER_NAME_FILTER = "name = ? "; | ||
|
||
// @formatter:off | ||
private static final String FIND_USER_BY_ID_SQL = "SELECT " + COLUMN_NAMES | ||
+ " FROM " + TABLE_NAME | ||
+ " WHERE " + ID_FILTER; | ||
// @formatter:on | ||
|
||
// @formatter:off | ||
private static final String FIND_USER_BY_NAME_SQL = "SELECT " + COLUMN_NAMES | ||
+ " FROM " + TABLE_NAME | ||
+ " WHERE " + USER_NAME_FILTER; | ||
// @formatter:on | ||
|
||
private static final String DELETE_USER_SQL = "DELETE FROM " + TABLE_NAME + " WHERE " + ID_FILTER; | ||
|
||
// @formatter:off | ||
private static final String UPDATE_USER_SQL = "UPDATE " + TABLE_NAME | ||
+ " SET name = ?, display_name = ? " | ||
+ " WHERE " + ID_FILTER; | ||
// @formatter:on | ||
|
||
/** | ||
* Constructs a {@code JdbcPublicKeyCredentialUserEntityRepository} using the provided | ||
* parameters. | ||
* @param jdbcOperations the JDBC operations | ||
*/ | ||
public JdbcPublicKeyCredentialUserEntityRepository(JdbcOperations jdbcOperations) { | ||
Assert.notNull(jdbcOperations, "jdbcOperations cannot be null"); | ||
this.jdbcOperations = jdbcOperations; | ||
} | ||
|
||
@Override | ||
public PublicKeyCredentialUserEntity findById(Bytes id) { | ||
Assert.notNull(id, "id cannot be null"); | ||
List<PublicKeyCredentialUserEntity> result = this.jdbcOperations.query(FIND_USER_BY_ID_SQL, | ||
this.userEntityRowMapper, id.toBase64UrlString()); | ||
return !result.isEmpty() ? result.get(0) : null; | ||
} | ||
|
||
@Override | ||
public PublicKeyCredentialUserEntity findByUsername(String username) { | ||
Assert.hasText(username, "name cannot be null or empty"); | ||
List<PublicKeyCredentialUserEntity> result = this.jdbcOperations.query(FIND_USER_BY_NAME_SQL, | ||
this.userEntityRowMapper, username); | ||
return !result.isEmpty() ? result.get(0) : null; | ||
} | ||
|
||
@Override | ||
public void save(PublicKeyCredentialUserEntity userEntity) { | ||
Assert.notNull(userEntity, "userEntity cannot be null"); | ||
boolean existsUserEntity = null != this.findById(userEntity.getId()); | ||
if (existsUserEntity) { | ||
updateUserEntity(userEntity); | ||
} | ||
else { | ||
try { | ||
insertUserEntity(userEntity); | ||
} | ||
catch (DuplicateKeyException ex) { | ||
updateUserEntity(userEntity); | ||
} | ||
} | ||
} | ||
|
||
private void insertUserEntity(PublicKeyCredentialUserEntity userEntity) { | ||
List<SqlParameterValue> parameters = this.userEntityParametersMapper.apply(userEntity); | ||
PreparedStatementSetter pss = new ArgumentPreparedStatementSetter(parameters.toArray()); | ||
this.jdbcOperations.update(SAVE_USER_SQL, pss); | ||
rwinch marked this conversation as resolved.
Show resolved
Hide resolved
|
||
} | ||
|
||
private void updateUserEntity(PublicKeyCredentialUserEntity userEntity) { | ||
List<SqlParameterValue> parameters = this.userEntityParametersMapper.apply(userEntity); | ||
SqlParameterValue userEntityId = parameters.remove(0); | ||
parameters.add(userEntityId); | ||
PreparedStatementSetter pss = new ArgumentPreparedStatementSetter(parameters.toArray()); | ||
this.jdbcOperations.update(UPDATE_USER_SQL, pss); | ||
} | ||
|
||
@Override | ||
public void delete(Bytes id) { | ||
Assert.notNull(id, "id cannot be null"); | ||
SqlParameterValue[] parameters = new SqlParameterValue[] { | ||
new SqlParameterValue(Types.VARCHAR, id.toBase64UrlString()), }; | ||
PreparedStatementSetter pss = new ArgumentPreparedStatementSetter(parameters); | ||
this.jdbcOperations.update(DELETE_USER_SQL, pss); | ||
} | ||
|
||
private static class UserEntityParametersMapper | ||
implements Function<PublicKeyCredentialUserEntity, List<SqlParameterValue>> { | ||
|
||
@Override | ||
public List<SqlParameterValue> apply(PublicKeyCredentialUserEntity userEntity) { | ||
List<SqlParameterValue> parameters = new ArrayList<>(); | ||
|
||
parameters.add(new SqlParameterValue(Types.VARCHAR, userEntity.getId().toBase64UrlString())); | ||
parameters.add(new SqlParameterValue(Types.VARCHAR, userEntity.getName())); | ||
parameters.add(new SqlParameterValue(Types.VARCHAR, userEntity.getDisplayName())); | ||
|
||
return parameters; | ||
} | ||
|
||
} | ||
|
||
private static class UserEntityRecordRowMapper implements RowMapper<PublicKeyCredentialUserEntity> { | ||
|
||
@Override | ||
public PublicKeyCredentialUserEntity mapRow(ResultSet rs, int rowNum) throws SQLException { | ||
Bytes id = Bytes.fromBase64(new String(rs.getString("id").getBytes())); | ||
String name = rs.getString("name"); | ||
String displayName = rs.getString("display_name"); | ||
|
||
return ImmutablePublicKeyCredentialUserEntity.builder().id(id).name(name).displayName(displayName).build(); | ||
} | ||
|
||
} | ||
|
||
} |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.