Package com.illumon.iris.auth
Class GrpcAuthenticationService
java.lang.Object
io.deephaven.proto.auth.grpc.AuthApiGrpc.AuthApiImplBase
com.illumon.iris.auth.GrpcAuthenticationService
- All Implemented Interfaces:
AuthApiGrpc.AsyncService,io.grpc.BindableService,AutoCloseable
gRPC implementation of the Auth service API
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final longstatic final intstatic final longfinal Threadstatic final booleanstatic final long -
Constructor Summary
ConstructorsConstructorDescriptionGrpcAuthenticationService(AuthenticationServerBase server, io.deephaven.shadow.jetcd.io.etcd.jetcd.Client etcdClient, int cookieRefreshDurationSeconds, long kvDeadlinePeriodMillis, String kvKeyPrefix) Creates a new GrpcAuthenticationService. -
Method Summary
Modifier and TypeMethodDescriptionvoidauthenticateByCookie(AuthenticateByCookieRequest request, io.grpc.stub.StreamObserver<AuthenticateByCookieResponse> responseObserver) Authenticate by providing an already existing cookie and the user context that cookie should be associated with.voidauthenticateByDelegateToken(AuthenticateByDelegateTokenRequest request, io.grpc.stub.StreamObserver<AuthenticateByDelegateTokenResponse> responseObserver) Authenticate by delegate token; should have obtained a token earlier from another service that created it and forwarded it.voidauthenticateByExternal(AuthenticateByExternalRequest request, io.grpc.stub.StreamObserver<AuthenticateByExternalResponse> responseObserver) Authenticate by an external method (eg, active directory).voidauthenticateByPassword(AuthenticateByPasswordRequest request, io.grpc.stub.StreamObserver<AuthenticateByPasswordResponse> responseObserver) Authenticate by password.voidauthenticateByPublicKey(AuthenticateByPublicKeyRequest request, io.grpc.stub.StreamObserver<AuthenticateByPublicKeyResponse> responseObserver) Authenticate by public key challenge; should have obtained a nonce earlier via getNonce rpc.voidclose()voidgetNonce(GetNonceRequest request, io.grpc.stub.StreamObserver<GetNonceResponse> responseObserver) Get a nonce for public key authentication.voidgetToken(GetTokenRequest request, io.grpc.stub.StreamObserver<GetTokenResponse> responseObserver) Get a token for a three-way handshake.voidgetTokenAs(GetTokenAsRequest request, io.grpc.stub.StreamObserver<GetTokenAsResponse> responseObserver) Get a token for a three-way handshake as a particular user.voidinvalidateCookie(InvalidateCookieRequest request, io.grpc.stub.StreamObserver<InvalidateCookieResponse> responseObserver) Clients that are about to terminate are expected to invalidate their credentials before going away.voidping(PingRequest request, io.grpc.stub.StreamObserver<PingResponse> responseObserver) Implementation for the ping method in the proto service API.voidrefreshCookie(RefreshCookieRequest request, io.grpc.stub.StreamObserver<RefreshCookieResponse> responseObserver) Refresh a cookie to maintain credentials.voidreload(ReloadRequest request, io.grpc.stub.StreamObserver<ReloadResponse> responseObserver) Request this server to reload its configuration.voidverifyChallenge(VerifyChallengeRequest request, io.grpc.stub.StreamObserver<VerifyChallengeResponse> responseObserver) Verify a nonce challenge response for another server (not used directly by clients, only server-server)voidverifyToken(VerifyTokenRequest request, io.grpc.stub.StreamObserver<VerifyTokenResponse> responseObserver) Verify a token provided by another service.Methods inherited from class io.deephaven.proto.auth.grpc.AuthApiGrpc.AuthApiImplBase
bindService
-
Field Details
-
EXPIRED_CLIENTS_PURGE_PERIOD_MILLIS
public static final long EXPIRED_CLIENTS_PURGE_PERIOD_MILLIS -
EXPIRED_CLIENTS_MAX_CLIENTS_CHECKED_PER_PERIOD
public static final int EXPIRED_CLIENTS_MAX_CLIENTS_CHECKED_PER_PERIOD -
AUTH_FORWARD_DEFAULT_DEADLINE_MILLIS
public static final long AUTH_FORWARD_DEFAULT_DEADLINE_MILLIS -
VERIFY_TOKEN_FORWARD_DEFAULT_DEADLINE_MILLIS
public static final long VERIFY_TOKEN_FORWARD_DEFAULT_DEADLINE_MILLIS -
LOG_REQUEST_ENTRY_EXIT
public static final boolean LOG_REQUEST_ENTRY_EXIT- See Also:
-
expiredClientsPurgeThread
-
-
Constructor Details
-
GrpcAuthenticationService
public GrpcAuthenticationService(AuthenticationServerBase server, io.deephaven.shadow.jetcd.io.etcd.jetcd.Client etcdClient, int cookieRefreshDurationSeconds, long kvDeadlinePeriodMillis, String kvKeyPrefix) Creates a new GrpcAuthenticationService.- Parameters:
server- The underlying authentication server implementation.etcdClient- The etcdClient for persistence of cookie state and for name resolution in the auth forwardercookieRefreshDurationSeconds- How long each cookie refresh lasts, in seconds.kvDeadlinePeriodMillis- RPC deadline in seconds for etcd-related RPCskvKeyPrefix- String prefix for storage of cookie state keys in etcd.
-
-
Method Details
-
ping
Implementation for the ping method in the proto service API. This is a simple method allowing the client to sample the latency to the server.- Specified by:
pingin interfaceAuthApiGrpc.AsyncService- Parameters:
request- the request payloadresponseObserver- the response
-
authenticateByPassword
public void authenticateByPassword(AuthenticateByPasswordRequest request, io.grpc.stub.StreamObserver<AuthenticateByPasswordResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceAuthenticate by password.
- Specified by:
authenticateByPasswordin interfaceAuthApiGrpc.AsyncService
-
authenticateByPublicKey
public void authenticateByPublicKey(AuthenticateByPublicKeyRequest request, io.grpc.stub.StreamObserver<AuthenticateByPublicKeyResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceAuthenticate by public key challenge; should have obtained a nonce earlier via getNonce rpc.
- Specified by:
authenticateByPublicKeyin interfaceAuthApiGrpc.AsyncService
-
verifyChallenge
public void verifyChallenge(VerifyChallengeRequest request, io.grpc.stub.StreamObserver<VerifyChallengeResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceVerify a nonce challenge response for another server (not used directly by clients, only server-server)
- Specified by:
verifyChallengein interfaceAuthApiGrpc.AsyncService
-
authenticateByDelegateToken
public void authenticateByDelegateToken(AuthenticateByDelegateTokenRequest request, io.grpc.stub.StreamObserver<AuthenticateByDelegateTokenResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceAuthenticate by delegate token; should have obtained a token earlier from another service that created it and forwarded it.
- Specified by:
authenticateByDelegateTokenin interfaceAuthApiGrpc.AsyncService
-
authenticateByExternal
public void authenticateByExternal(AuthenticateByExternalRequest request, io.grpc.stub.StreamObserver<AuthenticateByExternalResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceAuthenticate by an external method (eg, active directory).
- Specified by:
authenticateByExternalin interfaceAuthApiGrpc.AsyncService
-
authenticateByCookie
public void authenticateByCookie(AuthenticateByCookieRequest request, io.grpc.stub.StreamObserver<AuthenticateByCookieResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceAuthenticate by providing an already existing cookie and the user context that cookie should be associated with.
- Specified by:
authenticateByCookiein interfaceAuthApiGrpc.AsyncService
-
refreshCookie
public void refreshCookie(RefreshCookieRequest request, io.grpc.stub.StreamObserver<RefreshCookieResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceRefresh a cookie to maintain credentials. Clients are expected to try to refresh cookies with enough time in advance before expiration; a reasonable default is half way through from the time the cookie was obtained with its deadline, and the actual deadline time.
- Specified by:
refreshCookiein interfaceAuthApiGrpc.AsyncService
-
invalidateCookie
public void invalidateCookie(InvalidateCookieRequest request, io.grpc.stub.StreamObserver<InvalidateCookieResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceClients that are about to terminate are expected to invalidate their credentials before going away.
- Specified by:
invalidateCookiein interfaceAuthApiGrpc.AsyncService
-
getNonce
public void getNonce(GetNonceRequest request, io.grpc.stub.StreamObserver<GetNonceResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceGet a nonce for public key authentication.
- Specified by:
getNoncein interfaceAuthApiGrpc.AsyncService
-
getToken
public void getToken(GetTokenRequest request, io.grpc.stub.StreamObserver<GetTokenResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceGet a token for a three-way handshake.
- Specified by:
getTokenin interfaceAuthApiGrpc.AsyncService
-
getTokenAs
public void getTokenAs(GetTokenAsRequest request, io.grpc.stub.StreamObserver<GetTokenAsResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceGet a token for a three-way handshake as a particular user.
- Specified by:
getTokenAsin interfaceAuthApiGrpc.AsyncService
-
verifyToken
public void verifyToken(VerifyTokenRequest request, io.grpc.stub.StreamObserver<VerifyTokenResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceVerify a token provided by another service.
- Specified by:
verifyTokenin interfaceAuthApiGrpc.AsyncService
-
reload
public void reload(ReloadRequest request, io.grpc.stub.StreamObserver<ReloadResponse> responseObserver) Description copied from interface:AuthApiGrpc.AsyncServiceRequest this server to reload its configuration.
- Specified by:
reloadin interfaceAuthApiGrpc.AsyncService
-
close
public void close()- Specified by:
closein interfaceAutoCloseable
-