CachingRevocationChecker
Storage-backed implementation of RevocationChecker that caches downloaded data (status and identifier lists) in a StorageTable.
Revocation data is validated at download time, when loaded from cache it is not re-validated. When revocation data is found in cache, it is checked for freshness in the following manner:
if revocation data server has used
ETagorLast-Modifiedheaders, a conditional HTTP GET request is sent to the server; HTTP status304 Not Modifiedmeans that cached data is fresh to be used, otherwise fresh data is sent from the server and replaces cached one.if revocation data server has not sent these headers, cached data is assumed fresh for its specified TTL time, or, absent that, expiration time.
if HTTP update fails, cached data is used, even if it is expired; stale data is assumed to be better than no data; cache entries are purged after the time specified by cachingDuration, which should be longer than a typical credential validity period.
Parameters
Storage instance used to persist revocation list caches.
Ktor HttpClient used to fetch revocation status and identifier lists over HTTP/HTTPS.
Timeout duration for network requests fetching revocation lists.
how long to keep revocation data in cache
allow Last-Modified header use, mostly exposed for testing only
Constructors
Functions
Checks the revocation state for a given non-null RevocationStatus payload.
Convenience extension to check the revocation state for a given Credential.
Clears all cached revocation status and identifier list entries from storage.