Package io.jans.casa.service
Interface SndFactorAuthenticationUtils
public interface SndFactorAuthenticationUtils
Contains methods to facilitate certain operations related to strong authentication
-
Method Summary
Modifier and TypeMethodDescriptionvoidnotifyEnrollment(User user, String credentialType) This method should be called after the user has successfully a enrolled a credential.org.zkoss.util.Pair<CredentialRemovalConflict,String> removalConflict(String credentialType, int nCredsOfType, User user) Method to support removal of credentials for a user.booleanturn2faOff(User user) Turns second factor authentication off for a user.booleanTurns second factor authentication on for a user.booleanTurns second factor authentication on for a user and sets his preferred authentication method.
-
Method Details
-
turn2faOn
Turns second factor authentication on for a user. A call to this method provokes changes in the underlying database.- Parameters:
user- Object representing the user. If the return value of this method is true, this object's member preferredMethod is set to a non-null value.- Returns:
- Whether the operation was successful or not
-
turn2faOn
Turns second factor authentication on for a user and sets his preferred authentication method. A call to this method provokes changes in the underlying database.- Parameters:
user- Object representing the user. If the return value of this method is true, this object's member preferredMethod is set to the value of preferredMethod param.preferredMethod- Preferred authentication method for the user. When null, the call is equivalent to turn2faOn(user). This method does not validate if preferredMethod is semantically correct (ie. a valid acr)- Returns:
- Whether the operation was successful or not
-
turn2faOff
Turns second factor authentication off for a user. A call to this method provokes changes in the underlying database.- Parameters:
user- Object representing the user. It is altered if the operation outcome is true: member preferredMethod is set to null.- Returns:
- Whether the operation was successful or not
-
removalConflict
org.zkoss.util.Pair<CredentialRemovalConflict,String> removalConflict(String credentialType, int nCredsOfType, User user) Method to support removal of credentials for a user. It helps simulate what would happen in case a credential of a certain type is removed. This method does not change any actual data.- Parameters:
credentialType- The type of credential to be removed (an ACR value)nCredsOfType- Number of credentials of this type the user has already enrolleduser- Object representing the user upon which the operation would take place- Returns:
- A 2-tuple. The first, a value from
CredentialRemovalConflict(null if there would not be any conflict in case of removal). The second, a String containing a suitable end-user message to be displayed so the user can easily understand the effect of the removal operation (null if there is no conflict)
-
notifyEnrollment
This method should be called after the user has successfully a enrolled a credential. While not mandatory, plugin writers are encouraged to invoke this method to keep some internals of the application up-to-date. This is specially relevant for auto enablement of 2FA to take effect.- Parameters:
user- Object representing the user that the enrollment belongs to. The instance must have been obtained from the SessionContextcredentialType- The type of credential to added (an ACR value)
-