Class AuthzCommandHandler

java.lang.Object
com.sankcrm.erp.auth.application.authz.command.create.AuthzCommandHandler
All Implemented Interfaces:
com.sankcrm.erp.bus.CommandHandler<AuthzResult,AuthzCommand>

@Component("userinfoAuthCommandHandler") @Transactional(timeout=60, rollbackFor=java.lang.Exception.class) public class AuthzCommandHandler extends Object implements com.sankcrm.erp.bus.CommandHandler<AuthzResult,AuthzCommand>
认证处理
Since:
2.1.0
Author:
zhsxin
  • Constructor Details

    • AuthzCommandHandler

      public AuthzCommandHandler()
  • Method Details

    • handle

      public AuthzResult handle(AuthzCommand command) throws com.sankcrm.erp.common.exception.CoreException
      执行单因子登录:限流、验证码、账号查询、凭证校验,最后完成一次授权。
      Specified by:
      handle in interface com.sankcrm.erp.bus.CommandHandler<AuthzResult,AuthzCommand>
      Parameters:
      command - 登录命令;验证码答案为敏感字段,不记录明文
      Returns:
      授权结果
      Throws:
      com.sankcrm.erp.common.exception.CoreException - 认证、验证码、授权或后置副作用失败时抛出
    • checkCaptchaLoginAttempt

      protected void checkCaptchaLoginAttempt(App app, String authType, String account) throws com.sankcrm.erp.common.exception.CoreException
      登录凭证校验前执行独立登录限流;启用策略且 Redis 不可用时拒绝登录。
      Throws:
      com.sankcrm.erp.common.exception.CoreException
    • verifyCaptcha

      protected void verifyCaptcha(App app, String authType, String account, com.sankcrm.erp.auth.sdk.authz.command.CaptchaAnswer answer) throws com.sankcrm.erp.common.exception.CoreException
      将验证码校验经 Bus 分发到独立命令处理器,避免登录编排直接依赖基础设施。
      Throws:
      com.sankcrm.erp.common.exception.CoreException
    • recordCredentialFailure

      protected void recordCredentialFailure(App app, String authType, String account) throws com.sankcrm.erp.common.exception.CoreException
      仅在密码凭证错误或密码账号不存在时累计失败。
      Throws:
      com.sankcrm.erp.common.exception.CoreException
    • clearCredentialFailure

      protected void clearCredentialFailure(App app, String authType, String account) throws com.sankcrm.erp.common.exception.CoreException
      Throws:
      com.sankcrm.erp.common.exception.CoreException
    • findUser

      protected UserInfo findUser(AuthzHandler.UserInfoQuery<?> query) throws com.sankcrm.erp.common.exception.CoreException
      Throws:
      com.sankcrm.erp.common.exception.CoreException
    • verifyCredentials

      protected boolean verifyCredentials(AuthzHandler.AuthzCommand<?> command) throws com.sankcrm.erp.common.exception.CoreException
      Throws:
      com.sankcrm.erp.common.exception.CoreException
    • authzInfo

      protected AuthzInfo authzInfo(String authType)
    • prepareAuthorizationContext

      protected void prepareAuthorizationContext()
    • createUserQuery

      protected AuthzHandler.UserInfoQuery<?> createUserQuery(AuthzCommand command, AuthzInfo authz)
    • createCredentialCommand

      protected AuthzHandler.AuthzCommand<?> createCredentialCommand(AuthzCommand command, AuthzInfo authz)
    • saveExtra

      protected void saveExtra(UserInfo userInfo, AuthzCommand command)
      保存额外的信息
      Parameters:
      userInfo - 账号
      command - 授权参数
      Since:
      2.3.0
    • createLog

      protected void createLog(String type, AuthzHandler.UserInfoQuery<?> query, Token token, UserInfo user, Exception e)
      创建登录日志
      Parameters:
      token - 令牌
      Since:
      2.2.0