CachingRevocationChecker

class CachingRevocationChecker(storage: Storage, httpClient: HttpClient = HttpClient(), httpTimeout: Duration = 10.seconds, cachingDuration: Duration = 60.days, useETag: Boolean = true, useLastModified: Boolean = true) : RevocationChecker

Storage-backed implementation of RevocationChecker that caches downloaded data (status and identifier lists) in a StorageTable.

Revocation data is validated at download time, when loaded from cache it is not re-validated. When revocation data is found in cache, it is checked for freshness in the following manner:

  • if revocation data server has used ETag or Last-Modified headers, a conditional HTTP GET request is sent to the server; HTTP status 304 Not Modified means that cached data is fresh to be used, otherwise fresh data is sent from the server and replaces cached one.

  • if revocation data server has not sent these headers, cached data is assumed fresh for its specified TTL time, or, absent that, expiration time.

  • if HTTP update fails, cached data is used, even if it is expired; stale data is assumed to be better than no data; cache entries are purged after the time specified by cachingDuration, which should be longer than a typical credential validity period.

Parameters

storage

Storage instance used to persist revocation list caches.

httpClient

Ktor HttpClient used to fetch revocation status and identifier lists over HTTP/HTTPS.

httpTimeout

Timeout duration for network requests fetching revocation lists.

cachingDuration

how long to keep revocation data in cache

useETag

allow Last-Modified header use, mostly exposed for testing only

Constructors

Link copied to clipboard
constructor(storage: Storage, httpClient: HttpClient = HttpClient(), httpTimeout: Duration = 10.seconds, cachingDuration: Duration = 60.days, useETag: Boolean = true, useLastModified: Boolean = true)

Types

Link copied to clipboard
object Companion

Functions

Link copied to clipboard
open suspend override fun check(revocationStatus: RevocationStatus, issuerCert: X509Cert?, onlyTrusted: Boolean, atTime: Instant, bypassCache: Boolean, preferJwt: Boolean): RevocationCheckResult

Checks the revocation state for a given non-null RevocationStatus payload.

Link copied to clipboard
suspend fun RevocationChecker.check(credential: Credential, trustManager: TrustManagerInterface, onlyTrusted: Boolean = true, atTime: Instant = Clock.System.now(), bypassCache: Boolean = false, preferJwt: Boolean = false): RevocationCheckResult

Convenience extension to check the revocation state for a given Credential.

Link copied to clipboard
open suspend override fun clearCache()

Clears all cached revocation status and identifier list entries from storage.