Class SessionStateSupport
java.lang.Object
org.sourceid.saml20.adapter.state.SessionStateSupport
- Direct Known Subclasses:
ApplicationSessionStateSupport
Provides functionality similar to using the HTTP Session. You can set, get and remove attributes associated with
a user's session.
The advantage of using this rather than the HttpSession object is that it uses the PingFederate server's underlying implementation of inter-request state management to replicate or share the data in a clustered environment.
Attributes must be added or updated using the
The advantage of using this rather than the HttpSession object is that it uses the PingFederate server's underlying implementation of inter-request state management to replicate or share the data in a clustered environment.
Attributes must be added or updated using the
setAttribute(String, Object, HttpServletRequest, HttpServletResponse, boolean)
or removeAttribute(String, HttpServletRequest, HttpServletResponse) methods before the associated
HttpServletResponse response is committed.-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptiongetAttribute(String name, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp) Retrieves a named attribute from the user session (as determined by the request)getAttribute(String name, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.removeAttribute(String name, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp) Removes a named attribute from the user session (as determined by the request)removeAttribute(String name, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.since 13.1, replaced byremoveAttribute(String, HttpServletRequest, HttpServletResponse)voidsetAttribute(String name, Object value, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.since 13.1, replaced bysetAttribute(String, Object, HttpServletRequest, HttpServletResponse, boolean)voidsetAttribute(String name, Object value, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp, boolean usedAsLoginCtx) Sets or associates a named attribute with the user session (as determined by the request)voidsetAttribute(String name, Object value, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.As of release 6.5, replaced bysetAttribute(String, Object, HttpServletRequest, HttpServletResponse, boolean)voidsetAttribute(String name, Object value, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp, boolean usedAsLoginCtx) Deprecated, for removal: This API element is subject to removal in a future version.since 13.1, replaced bysetAttribute(String, Object, HttpServletRequest, HttpServletResponse, boolean)
-
Constructor Details
-
SessionStateSupport
public SessionStateSupport()
-
-
Method Details
-
setAttribute
@Deprecated(forRemoval=true) public void setAttribute(String name, Object value, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.As of release 6.5, replaced bysetAttribute(String, Object, HttpServletRequest, HttpServletResponse, boolean)- Parameters:
name- the name of the attributevalue- the attribute valuereq- HTTP requestresp- HTTP response
-
setAttribute
@Deprecated(forRemoval=true) public void setAttribute(String name, Object value, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.since 13.1, replaced bysetAttribute(String, Object, HttpServletRequest, HttpServletResponse, boolean)- Parameters:
name- the name of the attributevalue- the attribute valuereq- HTTP requestresp- HTTP response- Since:
- 13.1
-
setAttribute
@Deprecated(since="13.1", forRemoval=true) public void setAttribute(String name, Object value, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp, boolean usedAsLoginCtx) Deprecated, for removal: This API element is subject to removal in a future version.since 13.1, replaced bysetAttribute(String, Object, HttpServletRequest, HttpServletResponse, boolean)Sets or associates a named attribute with the user session (as determined by the request)- Parameters:
name- the name of the attributevalue- the attribute valuereq- HTTP requestresp- HTTP responseusedAsLoginCtx- Instructs the underlying state mechanism (if appropriate) as to if certain mitigation steps against session fixation should be taken. Use true, if the attribute is used to maintain a security or login context, and false otherwise.- Since:
- 6.5
-
setAttribute
public void setAttribute(String name, Object value, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp, boolean usedAsLoginCtx) Sets or associates a named attribute with the user session (as determined by the request)- Parameters:
name- the name of the attributevalue- the attribute valuereq- HTTP requestresp- HTTP responseusedAsLoginCtx- Instructs the underlying state mechanism (if appropriate) as to if certain mitigation steps against session fixation should be taken. Use true, if the attribute is used to maintain a security or login context, and false otherwise.- Since:
- 13.1
-
getAttribute
@Deprecated(since="13.1", forRemoval=true) public Object getAttribute(String name, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.since 13.1, replaced bygetAttribute(String, HttpServletRequest, HttpServletResponse)Retrieves a named attribute from the user session (as determined by the request)- Parameters:
name- name the name of the attributereq- HTTP requestresp- HTTP response- Returns:
- the attribute value
-
getAttribute
public Object getAttribute(String name, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp) Retrieves a named attribute from the user session (as determined by the request)- Parameters:
name- name the name of the attributereq- HTTP requestresp- HTTP response- Returns:
- the attribute value
- Since:
- 13.1
-
removeAttribute
@Deprecated(since="13.1", forRemoval=true) public Object removeAttribute(String name, javax.servlet.http.HttpServletRequest req, javax.servlet.http.HttpServletResponse resp) Deprecated, for removal: This API element is subject to removal in a future version.since 13.1, replaced byremoveAttribute(String, HttpServletRequest, HttpServletResponse)Removes a named attribute from the user session (as determined by the request)- Parameters:
name- name the name of the attributereq- HTTP requestresp- HTTP response- Returns:
- the attribute value
-
removeAttribute
public Object removeAttribute(String name, jakarta.servlet.http.HttpServletRequest req, jakarta.servlet.http.HttpServletResponse resp) Removes a named attribute from the user session (as determined by the request)- Parameters:
name- name the name of the attributereq- HTTP requestresp- HTTP response- Returns:
- the attribute value
-
getAttribute(String, HttpServletRequest, HttpServletResponse)