
base.jee.api.sql.ExpireTokens Maven / Gradle / Ivy
Go to download
Show more of this group Show more artifacts with this name
Show all versions of base Show documentation
Show all versions of base Show documentation
A collection of basic java utility classes that provide basic features for a standalone/simple JEE application. Backed by a Cassandra, MySQL, or SQLite database, it provides, web page templates, user and group management, and a searchable online audit log of all user activity.
The newest version!
/*
This is free and unencumbered software released into the public domain.
Anyone is free to copy, modify, publish, use, compile, sell, or
distribute this software, either in source code form or as a compiled
binary, for any purpose, commercial or non-commercial, and by any
means.
In jurisdictions that recognize copyright laws, the author or authors
of this software dedicate any and all copyright interest in the
software to the public domain. We make this dedication for the benefit
of the public at large and to the detriment of our heirs and
successors. We intend this dedication to be an overt act of
relinquishment in perpetuity of all present and future rights to this
software under copyright law.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR
OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR
OTHER DEALINGS IN THE SOFTWARE.
*/
package base.jee.api.sql;
import base.Command;
import base.jee.Constants;
import base.jee.api.Settings;
import javax.sql.DataSource;
import java.io.IOException;
import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.SQLException;
import java.util.Date;
/**
* Expire session cookies, and other tokens, that have passed their expiry
* dates. This prevents tables that hold tokens from growing too large over
* time. Note that code that uses these tokens also checks for expiry dates
* so this code plays no role in security of the system, only cleaning up old data.
*/
public class ExpireTokens extends Command {
private DataSource ds;
private Settings settings;
public ExpireTokens(DataSource ds, Settings settings) {
this.ds = ds;
this.settings = settings;
}
public ExpireTokens() {
}
@Override
protected void execute() throws IOException {
Connection c = null;
PreparedStatement q = null;
try {
c = ds.getConnection();
c.setAutoCommit(false);
long now = (new Date().getTime())/1000;
q = c.prepareStatement("delete from token where expiry or created");
q.setLong(1, now);
//TODO: Why is this default to 300? cf Constants.DEFAULT_SESSION_MAX_AGE. Is expiring of this and next token type actually working?
q.setLong(2, now - Long.parseLong(settings.get("session.max_age", "300")));
q.executeUpdate();
q.close();
q = null;
// Remove any expired throttles associated with authentication
q = c.prepareStatement("delete from throttle where updated < (? - " + Long.parseLong(settings.get("throttle.auth.lockout", "" + Constants.DEFAULT_THROTTLE_AUTH_LOCKOUT)) + ")");
q.setLong(1, new Date().getTime()/1000);
q.executeUpdate();
q.close();
q = null;
c.commit();
c.close();
c = null;
} catch(SQLException e) {
throw new IOException(e);
} finally {
if(q != null) { try { q.close(); } catch(SQLException e) {} }
if(c != null) {
try { c.rollback(); } catch (SQLException e) { }
try { c.close(); } catch (SQLException e) { }
}
}
}
@Override
public String getJsonParameters() {
return "{}";
}
}
© 2015 - 2025 Weber Informatics LLC | Privacy Policy