blob: 1e35ab9862c350ebe390b58b3a43ec1582331af3 [file] [log] [blame]
<!DOCTYPE HTML>
<html lang="en">
<head>
<title>Source code</title>
<link rel="stylesheet" type="text/css" href="../../../../../../../stylesheet.css" title="Style">
</head>
<body>
<main role="main">
<div class="sourceContainer">
<pre><span class="sourceLineNo">001</span><a id="line.1">/*</a>
<span class="sourceLineNo">002</span><a id="line.2"> * Licensed to the Apache Software Foundation (ASF) under one</a>
<span class="sourceLineNo">003</span><a id="line.3"> * or more contributor license agreements. See the NOTICE file</a>
<span class="sourceLineNo">004</span><a id="line.4"> * distributed with this work for additional information</a>
<span class="sourceLineNo">005</span><a id="line.5"> * regarding copyright ownership. The ASF licenses this file</a>
<span class="sourceLineNo">006</span><a id="line.6"> * to you under the Apache License, Version 2.0 (the</a>
<span class="sourceLineNo">007</span><a id="line.7"> * "License"); you may not use this file except in compliance</a>
<span class="sourceLineNo">008</span><a id="line.8"> * with the License. You may obtain a copy of the License at</a>
<span class="sourceLineNo">009</span><a id="line.9"> *</a>
<span class="sourceLineNo">010</span><a id="line.10"> * http://www.apache.org/licenses/LICENSE-2.0</a>
<span class="sourceLineNo">011</span><a id="line.11"> *</a>
<span class="sourceLineNo">012</span><a id="line.12"> * Unless required by applicable law or agreed to in writing,</a>
<span class="sourceLineNo">013</span><a id="line.13"> * software distributed under the License is distributed on an</a>
<span class="sourceLineNo">014</span><a id="line.14"> * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY</a>
<span class="sourceLineNo">015</span><a id="line.15"> * KIND, either express or implied. See the License for the</a>
<span class="sourceLineNo">016</span><a id="line.16"> * specific language governing permissions and limitations</a>
<span class="sourceLineNo">017</span><a id="line.17"> * under the License.</a>
<span class="sourceLineNo">018</span><a id="line.18"> */</a>
<span class="sourceLineNo">019</span><a id="line.19">package org.apache.shiro.session.mgt.eis;</a>
<span class="sourceLineNo">020</span><a id="line.20"></a>
<span class="sourceLineNo">021</span><a id="line.21">import org.apache.shiro.session.Session;</a>
<span class="sourceLineNo">022</span><a id="line.22">import org.apache.shiro.session.UnknownSessionException;</a>
<span class="sourceLineNo">023</span><a id="line.23">import org.apache.shiro.session.mgt.SimpleSession;</a>
<span class="sourceLineNo">024</span><a id="line.24"></a>
<span class="sourceLineNo">025</span><a id="line.25">import java.io.Serializable;</a>
<span class="sourceLineNo">026</span><a id="line.26"></a>
<span class="sourceLineNo">027</span><a id="line.27"></a>
<span class="sourceLineNo">028</span><a id="line.28">/**</a>
<span class="sourceLineNo">029</span><a id="line.29"> * An abstract {@code SessionDAO} implementation that performs some sanity checks on session creation and reading and</a>
<span class="sourceLineNo">030</span><a id="line.30"> * allows for pluggable Session ID generation strategies if desired. The {@code SessionDAO}</a>
<span class="sourceLineNo">031</span><a id="line.31"> * {@link SessionDAO#update update} and {@link SessionDAO#delete delete} methods are left to</a>
<span class="sourceLineNo">032</span><a id="line.32"> * subclasses.</a>
<span class="sourceLineNo">033</span><a id="line.33"> * &lt;h3&gt;Session ID Generation&lt;/h3&gt;</a>
<span class="sourceLineNo">034</span><a id="line.34"> * This class also allows for plugging in a {@link SessionIdGenerator} for custom ID generation strategies. This is</a>
<span class="sourceLineNo">035</span><a id="line.35"> * optional, as the default generator is probably sufficient for most cases. Subclass implementations that do use a</a>
<span class="sourceLineNo">036</span><a id="line.36"> * generator (default or custom) will want to call the</a>
<span class="sourceLineNo">037</span><a id="line.37"> * {@link #generateSessionId(org.apache.shiro.session.Session)} method from within their {@link #doCreate}</a>
<span class="sourceLineNo">038</span><a id="line.38"> * implementations.</a>
<span class="sourceLineNo">039</span><a id="line.39"> * &lt;p/&gt;</a>
<span class="sourceLineNo">040</span><a id="line.40"> * Subclass implementations that rely on the EIS data store to generate the ID automatically (e.g. when the session</a>
<span class="sourceLineNo">041</span><a id="line.41"> * ID is also an auto-generated primary key), they can simply ignore the {@code SessionIdGenerator} concept</a>
<span class="sourceLineNo">042</span><a id="line.42"> * entirely and just return the data store's ID from the {@link #doCreate} implementation.</a>
<span class="sourceLineNo">043</span><a id="line.43"> *</a>
<span class="sourceLineNo">044</span><a id="line.44"> * @since 1.0</a>
<span class="sourceLineNo">045</span><a id="line.45"> */</a>
<span class="sourceLineNo">046</span><a id="line.46">public abstract class AbstractSessionDAO implements SessionDAO {</a>
<span class="sourceLineNo">047</span><a id="line.47"></a>
<span class="sourceLineNo">048</span><a id="line.48"> /**</a>
<span class="sourceLineNo">049</span><a id="line.49"> * Optional SessionIdGenerator instance available to subclasses via the</a>
<span class="sourceLineNo">050</span><a id="line.50"> * {@link #generateSessionId(org.apache.shiro.session.Session)} method.</a>
<span class="sourceLineNo">051</span><a id="line.51"> */</a>
<span class="sourceLineNo">052</span><a id="line.52"> private SessionIdGenerator sessionIdGenerator;</a>
<span class="sourceLineNo">053</span><a id="line.53"></a>
<span class="sourceLineNo">054</span><a id="line.54"> /**</a>
<span class="sourceLineNo">055</span><a id="line.55"> * Default no-arg constructor that defaults the {@link #setSessionIdGenerator sessionIdGenerator} to be a</a>
<span class="sourceLineNo">056</span><a id="line.56"> * {@link org.apache.shiro.session.mgt.eis.JavaUuidSessionIdGenerator}.</a>
<span class="sourceLineNo">057</span><a id="line.57"> */</a>
<span class="sourceLineNo">058</span><a id="line.58"> public AbstractSessionDAO() {</a>
<span class="sourceLineNo">059</span><a id="line.59"> this.sessionIdGenerator = new JavaUuidSessionIdGenerator();</a>
<span class="sourceLineNo">060</span><a id="line.60"> }</a>
<span class="sourceLineNo">061</span><a id="line.61"></a>
<span class="sourceLineNo">062</span><a id="line.62"> /**</a>
<span class="sourceLineNo">063</span><a id="line.63"> * Returns the {@code SessionIdGenerator} used by the {@link #generateSessionId(org.apache.shiro.session.Session)}</a>
<span class="sourceLineNo">064</span><a id="line.64"> * method. Unless overridden by the {@link #setSessionIdGenerator(SessionIdGenerator)} method, the default instance</a>
<span class="sourceLineNo">065</span><a id="line.65"> * is a {@link JavaUuidSessionIdGenerator}.</a>
<span class="sourceLineNo">066</span><a id="line.66"> *</a>
<span class="sourceLineNo">067</span><a id="line.67"> * @return the {@code SessionIdGenerator} used by the {@link #generateSessionId(org.apache.shiro.session.Session)}</a>
<span class="sourceLineNo">068</span><a id="line.68"> * method.</a>
<span class="sourceLineNo">069</span><a id="line.69"> */</a>
<span class="sourceLineNo">070</span><a id="line.70"> public SessionIdGenerator getSessionIdGenerator() {</a>
<span class="sourceLineNo">071</span><a id="line.71"> return sessionIdGenerator;</a>
<span class="sourceLineNo">072</span><a id="line.72"> }</a>
<span class="sourceLineNo">073</span><a id="line.73"></a>
<span class="sourceLineNo">074</span><a id="line.74"> /**</a>
<span class="sourceLineNo">075</span><a id="line.75"> * Sets the {@code SessionIdGenerator} used by the {@link #generateSessionId(org.apache.shiro.session.Session)}</a>
<span class="sourceLineNo">076</span><a id="line.76"> * method. Unless overridden by this method, the default instance ss a {@link JavaUuidSessionIdGenerator}.</a>
<span class="sourceLineNo">077</span><a id="line.77"> *</a>
<span class="sourceLineNo">078</span><a id="line.78"> * @param sessionIdGenerator the {@code SessionIdGenerator} to use in the</a>
<span class="sourceLineNo">079</span><a id="line.79"> * {@link #generateSessionId(org.apache.shiro.session.Session)} method.</a>
<span class="sourceLineNo">080</span><a id="line.80"> */</a>
<span class="sourceLineNo">081</span><a id="line.81"> public void setSessionIdGenerator(SessionIdGenerator sessionIdGenerator) {</a>
<span class="sourceLineNo">082</span><a id="line.82"> this.sessionIdGenerator = sessionIdGenerator;</a>
<span class="sourceLineNo">083</span><a id="line.83"> }</a>
<span class="sourceLineNo">084</span><a id="line.84"></a>
<span class="sourceLineNo">085</span><a id="line.85"> /**</a>
<span class="sourceLineNo">086</span><a id="line.86"> * Generates a new ID to be applied to the specified {@code session} instance. This method is usually called</a>
<span class="sourceLineNo">087</span><a id="line.87"> * from within a subclass's {@link #doCreate} implementation where they assign the returned id to the session</a>
<span class="sourceLineNo">088</span><a id="line.88"> * instance and then create a record with this ID in the EIS data store.</a>
<span class="sourceLineNo">089</span><a id="line.89"> * &lt;p/&gt;</a>
<span class="sourceLineNo">090</span><a id="line.90"> * Subclass implementations backed by EIS data stores that auto-generate IDs during record creation, such as</a>
<span class="sourceLineNo">091</span><a id="line.91"> * relational databases, don't need to use this method or the {@link #getSessionIdGenerator() sessionIdGenerator}</a>
<span class="sourceLineNo">092</span><a id="line.92"> * attribute - they can simply return the data store's generated ID from the {@link #doCreate} implementation</a>
<span class="sourceLineNo">093</span><a id="line.93"> * if desired.</a>
<span class="sourceLineNo">094</span><a id="line.94"> * &lt;p/&gt;</a>
<span class="sourceLineNo">095</span><a id="line.95"> * This implementation uses the {@link #setSessionIdGenerator configured} {@link SessionIdGenerator} to create</a>
<span class="sourceLineNo">096</span><a id="line.96"> * the ID.</a>
<span class="sourceLineNo">097</span><a id="line.97"> *</a>
<span class="sourceLineNo">098</span><a id="line.98"> * @param session the new session instance for which an ID will be generated and then assigned</a>
<span class="sourceLineNo">099</span><a id="line.99"> * @return the generated ID to assign</a>
<span class="sourceLineNo">100</span><a id="line.100"> */</a>
<span class="sourceLineNo">101</span><a id="line.101"> protected Serializable generateSessionId(Session session) {</a>
<span class="sourceLineNo">102</span><a id="line.102"> if (this.sessionIdGenerator == null) {</a>
<span class="sourceLineNo">103</span><a id="line.103"> String msg = "sessionIdGenerator attribute has not been configured.";</a>
<span class="sourceLineNo">104</span><a id="line.104"> throw new IllegalStateException(msg);</a>
<span class="sourceLineNo">105</span><a id="line.105"> }</a>
<span class="sourceLineNo">106</span><a id="line.106"> return this.sessionIdGenerator.generateId(session);</a>
<span class="sourceLineNo">107</span><a id="line.107"> }</a>
<span class="sourceLineNo">108</span><a id="line.108"></a>
<span class="sourceLineNo">109</span><a id="line.109"> /**</a>
<span class="sourceLineNo">110</span><a id="line.110"> * Creates the session by delegating EIS creation to subclasses via the {@link #doCreate} method, and then</a>
<span class="sourceLineNo">111</span><a id="line.111"> * asserting that the returned sessionId is not null.</a>
<span class="sourceLineNo">112</span><a id="line.112"> *</a>
<span class="sourceLineNo">113</span><a id="line.113"> * @param session Session object to create in the EIS and associate with an ID.</a>
<span class="sourceLineNo">114</span><a id="line.114"> */</a>
<span class="sourceLineNo">115</span><a id="line.115"> public Serializable create(Session session) {</a>
<span class="sourceLineNo">116</span><a id="line.116"> Serializable sessionId = doCreate(session);</a>
<span class="sourceLineNo">117</span><a id="line.117"> verifySessionId(sessionId);</a>
<span class="sourceLineNo">118</span><a id="line.118"> return sessionId;</a>
<span class="sourceLineNo">119</span><a id="line.119"> }</a>
<span class="sourceLineNo">120</span><a id="line.120"></a>
<span class="sourceLineNo">121</span><a id="line.121"> /**</a>
<span class="sourceLineNo">122</span><a id="line.122"> * Ensures the sessionId returned from the subclass implementation of {@link #doCreate} is not null and not</a>
<span class="sourceLineNo">123</span><a id="line.123"> * already in use.</a>
<span class="sourceLineNo">124</span><a id="line.124"> *</a>
<span class="sourceLineNo">125</span><a id="line.125"> * @param sessionId session id returned from the subclass implementation of {@link #doCreate}</a>
<span class="sourceLineNo">126</span><a id="line.126"> */</a>
<span class="sourceLineNo">127</span><a id="line.127"> private void verifySessionId(Serializable sessionId) {</a>
<span class="sourceLineNo">128</span><a id="line.128"> if (sessionId == null) {</a>
<span class="sourceLineNo">129</span><a id="line.129"> String msg = "sessionId returned from doCreate implementation is null. Please verify the implementation.";</a>
<span class="sourceLineNo">130</span><a id="line.130"> throw new IllegalStateException(msg);</a>
<span class="sourceLineNo">131</span><a id="line.131"> }</a>
<span class="sourceLineNo">132</span><a id="line.132"> }</a>
<span class="sourceLineNo">133</span><a id="line.133"></a>
<span class="sourceLineNo">134</span><a id="line.134"> /**</a>
<span class="sourceLineNo">135</span><a id="line.135"> * Utility method available to subclasses that wish to</a>
<span class="sourceLineNo">136</span><a id="line.136"> * assign a generated session ID to the session instance directly. This method is not used by the</a>
<span class="sourceLineNo">137</span><a id="line.137"> * {@code AbstractSessionDAO} implementation directly, but it is provided so subclasses don't</a>
<span class="sourceLineNo">138</span><a id="line.138"> * need to know the {@code Session} implementation if they don't need to.</a>
<span class="sourceLineNo">139</span><a id="line.139"> * &lt;p/&gt;</a>
<span class="sourceLineNo">140</span><a id="line.140"> * This default implementation casts the argument to a {@link SimpleSession}, Shiro's default EIS implementation.</a>
<span class="sourceLineNo">141</span><a id="line.141"> *</a>
<span class="sourceLineNo">142</span><a id="line.142"> * @param session the session instance to which the sessionId will be applied</a>
<span class="sourceLineNo">143</span><a id="line.143"> * @param sessionId the id to assign to the specified session instance.</a>
<span class="sourceLineNo">144</span><a id="line.144"> */</a>
<span class="sourceLineNo">145</span><a id="line.145"> protected void assignSessionId(Session session, Serializable sessionId) {</a>
<span class="sourceLineNo">146</span><a id="line.146"> ((SimpleSession) session).setId(sessionId);</a>
<span class="sourceLineNo">147</span><a id="line.147"> }</a>
<span class="sourceLineNo">148</span><a id="line.148"></a>
<span class="sourceLineNo">149</span><a id="line.149"> /**</a>
<span class="sourceLineNo">150</span><a id="line.150"> * Subclass hook to actually persist the given &lt;tt&gt;Session&lt;/tt&gt; instance to the underlying EIS.</a>
<span class="sourceLineNo">151</span><a id="line.151"> *</a>
<span class="sourceLineNo">152</span><a id="line.152"> * @param session the Session instance to persist to the EIS.</a>
<span class="sourceLineNo">153</span><a id="line.153"> * @return the id of the session created in the EIS (i.e. this is almost always a primary key and should be the</a>
<span class="sourceLineNo">154</span><a id="line.154"> * value returned from {@link org.apache.shiro.session.Session#getId() Session.getId()}.</a>
<span class="sourceLineNo">155</span><a id="line.155"> */</a>
<span class="sourceLineNo">156</span><a id="line.156"> protected abstract Serializable doCreate(Session session);</a>
<span class="sourceLineNo">157</span><a id="line.157"></a>
<span class="sourceLineNo">158</span><a id="line.158"> /**</a>
<span class="sourceLineNo">159</span><a id="line.159"> * Retrieves the Session object from the underlying EIS identified by &lt;tt&gt;sessionId&lt;/tt&gt; by delegating to</a>
<span class="sourceLineNo">160</span><a id="line.160"> * the {@link #doReadSession(java.io.Serializable)} method. If {@code null} is returned from that method, an</a>
<span class="sourceLineNo">161</span><a id="line.161"> * {@link UnknownSessionException} will be thrown.</a>
<span class="sourceLineNo">162</span><a id="line.162"> *</a>
<span class="sourceLineNo">163</span><a id="line.163"> * @param sessionId the id of the session to retrieve from the EIS.</a>
<span class="sourceLineNo">164</span><a id="line.164"> * @return the session identified by &lt;tt&gt;sessionId&lt;/tt&gt; in the EIS.</a>
<span class="sourceLineNo">165</span><a id="line.165"> * @throws UnknownSessionException if the id specified does not correspond to any session in the EIS.</a>
<span class="sourceLineNo">166</span><a id="line.166"> */</a>
<span class="sourceLineNo">167</span><a id="line.167"> public Session readSession(Serializable sessionId) throws UnknownSessionException {</a>
<span class="sourceLineNo">168</span><a id="line.168"> Session s = doReadSession(sessionId);</a>
<span class="sourceLineNo">169</span><a id="line.169"> if (s == null) {</a>
<span class="sourceLineNo">170</span><a id="line.170"> throw new UnknownSessionException("There is no session with id [" + sessionId + "]");</a>
<span class="sourceLineNo">171</span><a id="line.171"> }</a>
<span class="sourceLineNo">172</span><a id="line.172"> return s;</a>
<span class="sourceLineNo">173</span><a id="line.173"> }</a>
<span class="sourceLineNo">174</span><a id="line.174"></a>
<span class="sourceLineNo">175</span><a id="line.175"> /**</a>
<span class="sourceLineNo">176</span><a id="line.176"> * Subclass implementation hook that retrieves the Session object from the underlying EIS or {@code null} if a</a>
<span class="sourceLineNo">177</span><a id="line.177"> * session with that ID could not be found.</a>
<span class="sourceLineNo">178</span><a id="line.178"> *</a>
<span class="sourceLineNo">179</span><a id="line.179"> * @param sessionId the id of the &lt;tt&gt;Session&lt;/tt&gt; to retrieve.</a>
<span class="sourceLineNo">180</span><a id="line.180"> * @return the Session in the EIS identified by &lt;tt&gt;sessionId&lt;/tt&gt; or {@code null} if a</a>
<span class="sourceLineNo">181</span><a id="line.181"> * session with that ID could not be found.</a>
<span class="sourceLineNo">182</span><a id="line.182"> */</a>
<span class="sourceLineNo">183</span><a id="line.183"> protected abstract Session doReadSession(Serializable sessionId);</a>
<span class="sourceLineNo">184</span><a id="line.184"></a>
<span class="sourceLineNo">185</span><a id="line.185">}</a>
</pre>
</div>
</main>
</body>
</html>