Class PasswordUtil

java.lang.Object
com.ssgllc.fish.service.util.registered.PasswordUtil

@Component public class PasswordUtil extends Object
Password-policy checks for password-validation expressions.

Each method returns a ValidationResult carrying the message to show when the check fails, so a policy is expressed by combining them - typically with checkMinValidations(Integer, ValidationResult, ValidationResult, ValidationResult, ValidationResult, String) for the "any N of four character classes" shape. A null result means "not checked", which is not the same as a pass.

  • Constructor Summary

    Constructors
    Constructor
    Description
    PasswordUtil(com.ssgllc.fish.service.cache.EntityConfigCacheService entityConfigCacheService)
     
  • Method Summary

    Modifier and Type
    Method
    Description
    static com.ssgllc.fish.validation.ValidationResult
    checkDictWord(String password, String errorMessage)
    Rejects a password containing a word from the commonWords TextTemplate.
    static com.ssgllc.fish.validation.ValidationResult
    checkMinValidations(Integer noOfValidationsToMatch, com.ssgllc.fish.validation.ValidationResult validation1, com.ssgllc.fish.validation.ValidationResult validation2, com.ssgllc.fish.validation.ValidationResult validation3, com.ssgllc.fish.validation.ValidationResult validation4, String errorMessage)
    Requires at least N of four supplied checks to pass - the "any 3 of 4 character classes" shape of password policy.
    static com.ssgllc.fish.validation.ValidationResult
    checkNumberOfDigits(Integer minDigitCount, String password, String errorMessage)
    Checks whether a password contains the required number of digits.
    static com.ssgllc.fish.validation.ValidationResult
    checkNumberOfLowercase(Integer minLowerCaseCount, String password, String errorMessage)
    Checks whether a password contains the required number of lowercase letters.
    static com.ssgllc.fish.validation.ValidationResult
    checkNumberOfSpecial(Integer minSepcialCharCount, String password, String errorMessage)
    Checks whether a password contains the required number of special characters.
    static com.ssgllc.fish.validation.ValidationResult
    checkNumberOfUppercase(Integer minUpperCaseCount, String password, String errorMessage)
    Checks whether a password contains the required number of uppercase letters.
    static com.ssgllc.fish.validation.ValidationResult
    checkPasswordHistory(Integer recentPassCount, String userId, String password, List<com.ssgllc.fish.domain.gen.User> userRevisions, String errorMessage)
    Rejects a password the user has recently used.
    static com.ssgllc.fish.validation.ValidationResult
    checkPasswordLength(Integer minLength, Integer maxLength, String password, String errorMessage)
    Checks whether a password meets the minimum length requirement.
    static com.ssgllc.fish.validation.ValidationResult
    checkRepeatCount(Integer length, Integer count, String password, String errorMessage)
    Checks whether a password contains the required number of repeated characters.
    static com.ssgllc.fish.validation.ValidationResult
    checkSequenceCount(Integer minAcceptableSeq, String password, String errorMessage)
    Checks whether a password contains the required number of sequential characters.
    static void
    Loads the common-words dictionary used by checkDictWord(String, String) from the commonWords TextTemplate, once per application run.

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • PasswordUtil

      public PasswordUtil(com.ssgllc.fish.service.cache.EntityConfigCacheService entityConfigCacheService) throws org.springframework.beans.BeansException
      Throws:
      org.springframework.beans.BeansException
  • Method Details

    • checkPasswordLength

      public static com.ssgllc.fish.validation.ValidationResult checkPasswordLength(Integer minLength, Integer maxLength, String password, String errorMessage)
      Checks whether a password meets the minimum length requirement.
      Parameters:
      minLength - The minimum length required for the password.
      maxLength - The maximum length allowed for the password.
      password - The password to check.
      errorMessage - The error message to display if the password is invalid.
      Returns:
      A ValidationResult object indicating whether the password meets the length requirement.
    • checkNumberOfUppercase

      public static com.ssgllc.fish.validation.ValidationResult checkNumberOfUppercase(Integer minUpperCaseCount, String password, String errorMessage)
      Checks whether a password contains the required number of uppercase letters.
      Parameters:
      minUpperCaseCount - The minimum number of uppercase letters required for the password.
      password - The password to check.
      errorMessage - The error message to display if the password is invalid.
      Returns:
      A ValidationResult object indicating whether the password meets the uppercase letter requirement.
    • checkNumberOfLowercase

      public static com.ssgllc.fish.validation.ValidationResult checkNumberOfLowercase(Integer minLowerCaseCount, String password, String errorMessage)
      Checks whether a password contains the required number of lowercase letters.
      Parameters:
      minLowerCaseCount - The minimum number of lowercase letters required for the password.
      password - The password to check.
      errorMessage - The error message to display if the password is invalid.
      Returns:
      A ValidationResult object indicating whether the password meets the lowercase letter requirement.
    • checkNumberOfDigits

      public static com.ssgllc.fish.validation.ValidationResult checkNumberOfDigits(Integer minDigitCount, String password, String errorMessage)
      Checks whether a password contains the required number of digits.
      Parameters:
      minDigitCount - The minimum number of digits required for the password.
      password - The password to check.
      errorMessage - The error message to display if the password is invalid.
      Returns:
      A ValidationResult object indicating whether the password meets the digit requirement.
    • checkNumberOfSpecial

      public static com.ssgllc.fish.validation.ValidationResult checkNumberOfSpecial(Integer minSepcialCharCount, String password, String errorMessage)
      Checks whether a password contains the required number of special characters.
      Parameters:
      minSepcialCharCount - The minimum number of special characters required for the password.
      password - The password to check.
      errorMessage - The error message to display if the password is invalid.
      Returns:
      A ValidationResult object indicating whether the password meets the special character requirement.
    • checkSequenceCount

      public static com.ssgllc.fish.validation.ValidationResult checkSequenceCount(Integer minAcceptableSeq, String password, String errorMessage)
      Checks whether a password contains the required number of sequential characters.
      Parameters:
      minAcceptableSeq - The minimum number of sequential characters allowed in the password.
      password - The password to check.
      errorMessage - The error message to display if the password is invalid.
      Returns:
      A ValidationResult object indicating whether the password meets the sequential character requirement.
    • checkRepeatCount

      public static com.ssgllc.fish.validation.ValidationResult checkRepeatCount(Integer length, Integer count, String password, String errorMessage)
      Checks whether a password contains the required number of repeated characters.
      Parameters:
      length - The length of the repeated character sequence.
      count - The maximum number of allowed repeated sequences.
      password - The password to check.
      errorMessage - The error message to display if the password is invalid.
      Returns:
      A ValidationResult object indicating whether the password meets the repeated character requirement.
    • checkPasswordHistory

      public static com.ssgllc.fish.validation.ValidationResult checkPasswordHistory(Integer recentPassCount, String userId, String password, List<com.ssgllc.fish.domain.gen.User> userRevisions, String errorMessage)
      Rejects a password the user has recently used. Intended for a password-validation expression, where the user's revision history is in scope.
      Parameters:
      recentPassCount - how many of the user's most recent passwords to compare against
      userId - the user whose history to check
      password - the proposed password
      userRevisions - the user's revision history, from which prior password hashes are read
      errorMessage - message to report when the password was used recently
      Returns:
      a passing result, or a failing one carrying errorMessage; a null password fails
    • createCommonWordsDictionary

      public static void createCommonWordsDictionary()
      Loads the common-words dictionary used by checkDictWord(String, String) from the commonWords TextTemplate, once per application run. Called for you by checkDictWord; there is no reason to call it from an expression. Silently leaves the dictionary unset when the TextTemplate is missing, which makes checkDictWord return null rather than fail.
    • checkDictWord

      public static com.ssgllc.fish.validation.ValidationResult checkDictWord(String password, String errorMessage)
      Rejects a password containing a word from the commonWords TextTemplate. Loads the dictionary on first use.
      Parameters:
      password - the proposed password
      errorMessage - message to report when a dictionary word is found
      Returns:
      a passing result, a failing one carrying errorMessage, or null when no commonWords TextTemplate is configured - treat null as "not checked", not as a pass
    • checkMinValidations

      public static com.ssgllc.fish.validation.ValidationResult checkMinValidations(Integer noOfValidationsToMatch, com.ssgllc.fish.validation.ValidationResult validation1, com.ssgllc.fish.validation.ValidationResult validation2, com.ssgllc.fish.validation.ValidationResult validation3, com.ssgllc.fish.validation.ValidationResult validation4, String errorMessage)
      Requires at least N of four supplied checks to pass - the "any 3 of 4 character classes" shape of password policy. Combine it with the individual character-class checks rather than requiring all of them.
      Parameters:
      noOfValidationsToMatch - how many of the four must pass; values outside 1-4 are treated as 2 rather than rejected
      validation1 - first check's result
      validation2 - second check's result
      validation3 - third check's result
      validation4 - fourth check's result
      errorMessage - message to report when too few checks passed
      Returns:
      a passing result, or a failing one carrying errorMessage