Skip to content
Prev Previous commit
Next Next commit
Update JDBCDBTokenSample.java
  • Loading branch information
nsundara authored Jan 7, 2022
commit be6367e92a563da27095817df6ef21dcc3663e96
34 changes: 15 additions & 19 deletions java/jdbc/ConnectionSamples/JDBCDBTokenSample.java
Original file line number Diff line number Diff line change
Expand Up @@ -3,19 +3,16 @@
/*
DESCRIPTION
The code sample shows how to use the JDBC driver to establish a connection
to the Autonomous Database (ADB) using database token
to the Autonomous Database (ADB) using access token
issued by the OCI Identity service.

You need to use either JDBC driver to use
database token authenticatio.

Step 1: Enter the DB_URL to pointing to your Autonomous Database (ADB)
Step 2: Make sure to have either 21.4.0.0.1 or 19.13.0.0.1 JDBC driver
in the classpath.
Step 2: Compile and Run the sample JDBCDBTokenSample
Step 1: Enter the DB_URL to pointing to your Autonomous Database (ADB)
Step 2: Make sure to have either 21.4.0.0.1 or 19.13.0.0.1 JDBC driver
in the classpath.
Step 3: Compile and run the sample JDBCDBTokenSample

NOTES
Use JDK 1.7 and above
Use JDK8 and above
MODIFIED (MM/DD/YY)
nbsundar 1/7/21 - Creation
*/
Expand All @@ -38,26 +35,25 @@ public class JDBCDBTokenSample {
// Download the wallet zip file and provide the path to the zip file as TNS_ADMIN
// Note that you need to pass the property oracle.jdbc.tokenAuthentication=OCI_TOKEN for token authentication
final static String DB_URL="jdbc:oracle:thin:@dbname_high?TNS_ADMIN=/Users/user/wallet/Wallet_dbname&oracle.jdbc.tokenAuthentication=OCI_TOKEN";
// If mutla TLS(mTLS) is disabled then, ADB connection does not require wallets.
// If mutual TLS(mTLS) is disabled then, ADB connection does not require wallets.
// Copy the connection string from "DB Connection" tab from "Connection Strings" section choosing "TLS" in the dropdown
//final static String DB_URL="jdbc:oracle:thin:@(description= (retry_count=20)(retry_delay=3)(address=(protocol=tcps)(port=1521)(host=adb.us-phoenix-1.oraclecloud.com))(connect_data=(service_name=gebqqeredfsozhjbqbs_dbname_medium.adb.oraclecloud.com)))?oracle.jdbc.tokenAuthentication=OCI_TOKEN";
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this example URL, it is using a TNS descriptor format. The descriptor format supports a "TOKEN_AUTH" parameter that has the same effect as the "oracle.jdbc.tokenAuthentication" property.
It would be nice to show this TOKEN_AUTH parameter in the example, rather than the oracle.jdbc.tokenAuthentication property.

"jdbc:oracle:thin:@(description=" + "(retry_count=20)(retry_delay=3)" + "(address=(protocol=tcps)(port=1521)(host=adb.us-phoenix-1.oraclecloud.com))" + "(security=(token_auth=OCI_TOKEN))" + "(connect_data=(service_name=gebqqeredfsozhjbqbs_dbname_medium.adb.oraclecloud.com)))"

Note that I've added in line breaks as well, these will improve the readability of the long form descriptor string.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is good to know, but, I prefer not to use this as customers need to add in the middle of the connection string. It is easy to use EZConnect and pass this additional parameter. We can add it as a comment to show the possibility though.

// Another way to enable token authentication in the long form connection string.
final static String DB_URL="jdbc:oracle:thin:@(description="
+ "(retry_count=20)(retry_delay=3)(address=(protocol=tcps)(port=1521)(host=adb.us-phoenix-1.oraclecloud.com))"
+ "(security=(token_auth=OCI_TOKEN))"
+ "(connect_data=(service_name=gebqqeredfsozhjbqbs_dbname_medium.adb.oraclecloud.com)))?oracle.jdbc.tokenAuthentication=OCI_TOKEN";
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's remove the ?oracle.jdbc.tokenAuthentication=OCI_TOKEN from this URL. It has no effect. The descriptor parameter "TOKEN_AUTH=OCI_TOKEN" takes precedence over the connection property, so we can remove the connection property.



public static void main(String args[]) throws SQLException {

// For more connection related properties. Refer to
// the OracleConnection interface.
Properties properties = new Properties();

properties.put(OracleConnection.CONNECTION_PROPERTY_DEFAULT_ROW_PREFETCH, "20");
properties.put(OracleConnection.CONNECTION_PROPERTY_THIN_NET_CHECKSUM_TYPES,
"(MD5,SHA1,SHA256,SHA384,SHA512)");
properties.put(OracleConnection.CONNECTION_PROPERTY_THIN_NET_CHECKSUM_LEVEL,
"REQUIRED");
// Connection property to enable database token authentication.

//Connection property to enable IAM token authentication.
// properties.put(OracleConnection.CONNECTION_PROPERTY_TOKEN_AUTHENTICATION, "OCI_TOKEN");



OracleDataSource ods = new OracleDataSource();
ods.setURL(DB_URL);
ods.setConnectionProperties(properties);
Expand Down