Interface SndFactorAuthenticationUtils


public interface SndFactorAuthenticationUtils
Contains methods to facilitate certain operations related to strong authentication
  • Method Summary

    Modifier and Type
    Method
    Description
    void
    notifyEnrollment(User user, String credentialType)
    This method should be called after the user has successfully a enrolled a credential.
    org.zkoss.util.Pair<CredentialRemovalConflict,String>
    removalConflict(String credentialType, int nCredsOfType, User user)
    Method to support removal of credentials for a user.
    boolean
    Turns second factor authentication off for a user.
    boolean
    Turns second factor authentication on for a user.
    boolean
    turn2faOn(User user, String preferredMethod)
    Turns second factor authentication on for a user and sets his preferred authentication method.
  • Method Details

    • turn2faOn

      boolean turn2faOn(User user)
      Turns second factor authentication on for a user. A call to this method provokes changes in the underlying database.
      Parameters:
      user - Object representing the user. If the return value of this method is true, this object's member preferredMethod is set to a non-null value.
      Returns:
      Whether the operation was successful or not
    • turn2faOn

      boolean turn2faOn(User user, String preferredMethod)
      Turns second factor authentication on for a user and sets his preferred authentication method. A call to this method provokes changes in the underlying database.
      Parameters:
      user - Object representing the user. If the return value of this method is true, this object's member preferredMethod is set to the value of preferredMethod param.
      preferredMethod - Preferred authentication method for the user. When null, the call is equivalent to turn2faOn(user). This method does not validate if preferredMethod is semantically correct (ie. a valid acr)
      Returns:
      Whether the operation was successful or not
    • turn2faOff

      boolean turn2faOff(User user)
      Turns second factor authentication off for a user. A call to this method provokes changes in the underlying database.
      Parameters:
      user - Object representing the user. It is altered if the operation outcome is true: member preferredMethod is set to null.
      Returns:
      Whether the operation was successful or not
    • removalConflict

      org.zkoss.util.Pair<CredentialRemovalConflict,String> removalConflict(String credentialType, int nCredsOfType, User user)
      Method to support removal of credentials for a user. It helps simulate what would happen in case a credential of a certain type is removed. This method does not change any actual data.
      Parameters:
      credentialType - The type of credential to be removed (an ACR value)
      nCredsOfType - Number of credentials of this type the user has already enrolled
      user - Object representing the user upon which the operation would take place
      Returns:
      A 2-tuple. The first, a value from CredentialRemovalConflict (null if there would not be any conflict in case of removal). The second, a String containing a suitable end-user message to be displayed so the user can easily understand the effect of the removal operation (null if there is no conflict)
    • notifyEnrollment

      void notifyEnrollment(User user, String credentialType)
      This method should be called after the user has successfully a enrolled a credential. While not mandatory, plugin writers are encouraged to invoke this method to keep some internals of the application up-to-date. This is specially relevant for auto enablement of 2FA to take effect.
      Parameters:
      user - Object representing the user that the enrollment belongs to. The instance must have been obtained from the SessionContext
      credentialType - The type of credential to added (an ACR value)