Class SecureStorageTokenStore
- All Implemented Interfaces:
TokenStore
A TokenStore that keeps an OidcClient's tokens in the platform's secure storage -- the
iOS keychain, the Android keystore, and what each desktop and browser port provides -- instead
of the application's ordinary Storage.
client.setTokenStore(new SecureStorageTokenStore());
A refresh token is a long-lived credential: whoever reads it can keep a session alive without the user. That is the reason to prefer this store over the default one for any application that signs in to something that matters.
Quiet and gated
By default the store uses the non-prompting half of SecureStorage: entries are encrypted by
the operating system and read without asking the user, which is what a token attached to
every request needs. requireBiometrics(String) switches to the gated half, where reading
(and on Android writing) shows a biometric prompt. An application that does this should load
its tokens once, when it starts, and keep them in memory -- OidcRequestAuthorizer does.
Loading prompts only when this store saved something to read: before the first sign-in, and
after clear(String), it completes with null without asking the user anything.
A platform with no secure storage
Nothing is downgraded silently. On a port with no secure storage every operation fails with
an OidcException whose code is OidcException.STORAGE_UNAVAILABLE, so the application
finds out the first time it runs there rather than discovering later where its refresh tokens
went. allowPlainStorageFallback(boolean) is the explicit opt-in: with it, such a platform
gets TokenStore.DefaultStorageTokenStore instead. The fallback is only used where secure
storage cannot be reached at all, never because one write failed.
Both stores write the same document, so an entry can be copied from one to the other as is.
-
Nested Class Summary
Nested classes/interfaces inherited from interface TokenStore
TokenStore.DefaultStorageTokenStore -
Constructor Summary
ConstructorsConstructorDescriptionA store over the platform'sSecureStorage.getInstance().SecureStorageTokenStore(SecureStorage storage) A store over a particularSecureStorage. -
Method Summary
Modifier and TypeMethodDescriptionallowPlainStorageFallback(boolean allow) Whether a platform with no secure storage may keep the tokens in ordinaryStorageinstead.Removes the entry forkey.Reads previously-saved tokens forkey, or completes withnullif nothing is stored.requireBiometrics(String reason) Keeps the tokens behind a biometric prompt.save(String key, OidcTokens tokens) Persiststokensunderkey.
-
Constructor Details
-
SecureStorageTokenStore
public SecureStorageTokenStore()A store over the platform'sSecureStorage.getInstance(). -
SecureStorageTokenStore
A store over a particular
SecureStorage.Parameters
storage: the storage to keep entries in, or null for the platform's own, looked up on each use
-
-
Method Details
-
requireBiometrics
Keeps the tokens behind a biometric prompt.
Reading then asks the user to authenticate, and on Android so does writing. Entries are bound to the enrolled biometrics: after the user enrolls a new finger or face the stored entry is gone for good,
load(String)completes with null, and the user signs in again.An entry written quietly is not visible to the gated half and the other way around, so decide once per application.
Parameters
reason: the text of the prompt, or null to go back to quiet storage
Returns
this store
-
allowPlainStorageFallback
Whether a platform with no secure storage may keep the tokens in ordinary
Storageinstead. Off by default.Parameters
allow: true to fall back on such a platform, false to fail there
Returns
this store
-
load
Description copied from interface:TokenStoreReads previously-saved tokens forkey, or completes withnullif nothing is stored.- Specified by:
loadin interfaceTokenStore
-
save
Description copied from interface:TokenStorePersiststokensunderkey. Implementations should overwrite any existing entry atomically.- Specified by:
savein interfaceTokenStore
-
clear
Description copied from interface:TokenStoreRemoves the entry forkey. Completing withBoolean.FALSEmeans nothing was stored; completing with an error means the underlying store failed.- Specified by:
clearin interfaceTokenStore
-