[java-idp-plugin-oidc-rp] branch main updated: Move Encrypt and Sign message handlers to commons
Phil Smart
philip.smart at jisc.ac.uk
Tue Jan 3 15:42:40 UTC 2023
This is an automated email from the git hooks/post-receive script.
philsmart pushed a commit to branch main
in repository java-idp-plugin-oidc-rp.
View the commit online:
http://git.shibboleth.net/view/?p=java-idp-plugin-oidc-rp.git;a=commit;h=18014efbb76270e07246ac78cf178f972b7436e9
The following commit(s) were added to refs/heads/main by this push:
new 18014ef Move Encrypt and Sign message handlers to commons
18014ef is described below
commit 18014efbb76270e07246ac78cf178f972b7436e9
Author: Phil Smart <philip.smart at jisc.ac.uk>
AuthorDate: Tue Jan 3 15:42:38 2023 +0000
Move Encrypt and Sign message handlers to commons
---
.../oidc/rp/messaging/impl/EncryptJWTHandler.java | 287 ---------------------
.../oidc/rp/messaging/impl/SignJWTHandler.java | 282 --------------------
.../oidc-relying-party-authn-beans.xml | 4 +-
3 files changed, 2 insertions(+), 571 deletions(-)
diff --git a/idp-oidc-rp-impl/src/main/java/net/shibboleth/idp/plugin/authn/oidc/rp/messaging/impl/EncryptJWTHandler.java b/idp-oidc-rp-impl/src/main/java/net/shibboleth/idp/plugin/authn/oidc/rp/messaging/impl/EncryptJWTHandler.java
deleted file mode 100644
index 392bef0..0000000
--- a/idp-oidc-rp-impl/src/main/java/net/shibboleth/idp/plugin/authn/oidc/rp/messaging/impl/EncryptJWTHandler.java
+++ /dev/null
@@ -1,287 +0,0 @@
-/*
- * Licensed to the University Corporation for Advanced Internet Development,
- * Inc. (UCAID) under one or more contributor license agreements. See the
- * NOTICE file distributed with this work for additional information regarding
- * copyright ownership. The UCAID licenses this file to You under the Apache
- * License, Version 2.0 (the "License"); you may not use this file except in
- * compliance with the License. You may obtain a copy of the License at
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
- * Unless required by applicable law or agreed to in writing, software
- * distributed under the License is distributed on an "AS IS" BASIS,
- * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- * See the License for the specific language governing permissions and
- * limitations under the License.
- */
-
-
-package net.shibboleth.idp.plugin.authn.oidc.rp.messaging.impl;
-
-import java.security.interfaces.ECPublicKey;
-import java.security.interfaces.RSAPublicKey;
-import java.util.function.BiConsumer;
-import java.util.function.Function;
-
-import javax.annotation.Nonnull;
-import javax.annotation.Nullable;
-
-import org.opensaml.messaging.context.MessageContext;
-import org.opensaml.messaging.context.navigate.ChildContextLookup;
-import org.opensaml.messaging.handler.AbstractMessageHandler;
-import org.opensaml.messaging.handler.MessageHandler;
-import org.opensaml.messaging.handler.MessageHandlerException;
-import org.opensaml.security.credential.Credential;
-import org.opensaml.xmlsec.EncryptionParameters;
-import org.opensaml.xmlsec.context.SecurityParametersContext;
-import org.slf4j.Logger;
-import org.slf4j.LoggerFactory;
-
-import com.nimbusds.jose.EncryptionMethod;
-import com.nimbusds.jose.JWEAlgorithm;
-import com.nimbusds.jose.JWEHeader;
-import com.nimbusds.jose.JWEObject;
-import com.nimbusds.jose.Payload;
-import com.nimbusds.jose.crypto.AESEncrypter;
-import com.nimbusds.jose.crypto.DirectEncrypter;
-import com.nimbusds.jose.crypto.ECDHEncrypter;
-import com.nimbusds.jose.crypto.RSAEncrypter;
-import com.nimbusds.jwt.EncryptedJWT;
-import com.nimbusds.jwt.JWT;
-
-import net.shibboleth.oidc.security.JWTEncryptionParameters;
-import net.shibboleth.oidc.security.context.JWTSecurityParametersContext;
-import net.shibboleth.oidc.security.impl.CredentialConversionUtil;
-import net.shibboleth.utilities.java.support.annotation.constraint.NonnullAfterInit;
-import net.shibboleth.utilities.java.support.annotation.constraint.NotEmpty;
-import net.shibboleth.utilities.java.support.component.ComponentInitializationException;
-import net.shibboleth.utilities.java.support.component.ComponentSupport;
-import net.shibboleth.utilities.java.support.logic.Constraint;
-import net.shibboleth.utilities.java.support.primitive.StringSupport;
-
-/**
- * A {@link MessageHandler} that encrypts a JWT using the {@link EncryptionParameters} found in the
- * {@link JWTSecurityParametersContext}. The {@link Payload} to encrypt is determined by lookup strategy.
- * A consumer takes the {@link EncryptedJWT} and updates the correct object in the {@link MessageContext}.
- */
-//TODO encrypt action is unpleasent to look at
-public class EncryptJWTHandler extends AbstractMessageHandler {
-
- /** Class logger. */
- @Nonnull private final Logger log = LoggerFactory.getLogger(EncryptJWTHandler.class);
-
- /** Strategy used to locate the {@link SecurityParametersContext} to use for signing. */
- @Nonnull private Function<MessageContext, JWTSecurityParametersContext> securityParametersLookupStrategy;
-
- /** Strategy used to locate the payload to encrypt.*/
- @NonnullAfterInit private Function<MessageContext, Payload> payloadToEncryptLookupStrategy;
-
- /** A consumer that takes the EncryptedJWT and updates the correct object inside the MessageContext.*/
- @NonnullAfterInit private BiConsumer<JWT, MessageContext> jwtUpdateConsumer;
-
- /** The signature signing parameters. */
- @Nullable private JWTEncryptionParameters encryptionParameters;
-
- /** A friendly name to log as the subject of encryption.*/
- @Nonnull private String logName;
-
-
- /** Constructor.*/
- public EncryptJWTHandler() {
- logName = "not-specified";
- securityParametersLookupStrategy = new ChildContextLookup<>(JWTSecurityParametersContext.class);
- }
-
- /**
- * Set the friendly name to log as the subject of encryption.
- *
- * @param name the friendly name
- */
- public void setLogName(@Nonnull @NotEmpty final String name) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
- ComponentSupport.ifDestroyedThrowDestroyedComponentException(this);
-
- logName = Constraint.isNotEmpty(name, "ForFriendlyName can not be null or empty");
- }
-
- /**
- * Set the consumer used to update the MessageContext with the supplied EncryptedJWT.
- *
- * @param consumer the consumer
- */
- public void setJwtUpdateConsumer(final BiConsumer<JWT, MessageContext> consumer) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
- ComponentSupport.ifDestroyedThrowDestroyedComponentException(this);
-
- jwtUpdateConsumer = Constraint.isNotNull(consumer, "JwtUpdateConsumer can not be null");
- }
-
- /**
- * Set the strategy used to locate the {@link Payload} to encrypt.
- *
- * @param strategy the strategy
- */
- public void setPayloadToEncryptLookupStrategy(@Nonnull final Function<MessageContext, Payload> strategy) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
- ComponentSupport.ifDestroyedThrowDestroyedComponentException(this);
-
- payloadToEncryptLookupStrategy =
- Constraint.isNotNull(strategy, "payloadToEncryptLookupStrategy can not be null");
- }
-
- /**
- * Set the strategy used to locate the {@link SecurityParametersContext} to use.
- *
- * @param strategy lookup strategy
- */
- public void setSecurityParametersLookupStrategy(
- @Nonnull final Function<MessageContext, JWTSecurityParametersContext> strategy) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
-
- securityParametersLookupStrategy =
- Constraint.isNotNull(strategy, "SecurityParameterContext lookup strategy cannot be null");
- }
-
- @Override
- protected void doInitialize() throws ComponentInitializationException {
- if (payloadToEncryptLookupStrategy == null) {
- throw new ComponentInitializationException("payloadToEncryptLookupStrategy can not be null");
- }
- if (jwtUpdateConsumer == null) {
- throw new ComponentInitializationException("jwtUpdateConsumer can not be null");
- }
- super.doInitialize();
- }
-
-
- @Override
- protected boolean doPreInvoke(@Nonnull final MessageContext messageContext) throws MessageHandlerException {
-
- if (!super.doPreInvoke(messageContext)) {
- return false;
- }
-
- final JWTSecurityParametersContext secParamCtx =
- securityParametersLookupStrategy.apply(messageContext);
- if (secParamCtx == null) {
- log.trace("{} Message context did not contain encryption parameters context, "
- + "request object will not be encrypted", getLogPrefix());
- return false;
- }
-
- encryptionParameters = secParamCtx.getEncryptionParameters();
- if (encryptionParameters == null) {
- log.debug("{} Message context did not contain encryption parameters, "
- + "request object will not be encrypted", getLogPrefix());
- return false;
- }
-
- // If we have parameters (so encryption is enabled), but the parameters are not in the correct state,
- // throw an exception as opposed to skipping encryption
- if (StringSupport.trimOrNull(encryptionParameters.getKeyTransportEncryptionAlgorithm()) == null ||
- StringSupport.trimOrNull(encryptionParameters.getDataEncryptionAlgorithm()) == null ||
- (encryptionParameters.getKeyTransportEncryptionCredential() == null &&
- encryptionParameters.getDataEncryptionCredential() == null)) {
- throw new MessageHandlerException("Message context did not contain all required encryption parameters");
- }
- if (encryptionParameters.getKeyTransportEncryptionCredential() != null &&
- encryptionParameters.getDataEncryptionCredential() != null) {
- throw new MessageHandlerException("Message context contained both a content encryption and "
- + "key transport credential. Only one required.");
- }
-
- return true;
- }
-
- @Override
- protected void doInvoke(@Nonnull final MessageContext messageContext) throws MessageHandlerException {
-
- final Payload payload = payloadToEncryptLookupStrategy.apply(messageContext);
- if (payload == null) {
- log.trace("{} No plain text source provided to encrypt", getLogPrefix());
- return;
- }
-
- final JWEAlgorithm encAlg = JWEAlgorithm.parse(encryptionParameters.getKeyTransportEncryptionAlgorithm());
- final EncryptionMethod encEnc = EncryptionMethod.parse(encryptionParameters.getDataEncryptionAlgorithm());
-
-
- final Credential keyTransportCredential = encryptionParameters.getKeyTransportEncryptionCredential();
- final Credential dataEncryptionCredential = encryptionParameters.getDataEncryptionCredential();
-
- final String keyTransportKid = keyTransportCredential == null ? null :
- CredentialConversionUtil.resolveKid(keyTransportCredential);
- final String dataEncryptionKid = dataEncryptionCredential == null ? null :
- CredentialConversionUtil.resolveKid(dataEncryptionCredential);
-
- JWEObject jweObject = null;
- try {
- if (JWEAlgorithm.Family.RSA.contains(encAlg) && keyTransportCredential != null &&
- keyTransportCredential.getPublicKey() != null) {
-
- jweObject = new JWEObject(new JWEHeader.Builder(encAlg, encEnc).contentType("JWT")
- .keyID(keyTransportKid).build(), payload);
- logEncryption(keyTransportKid, encAlg.getName(), encEnc.getName());
- jweObject.encrypt(new RSAEncrypter((RSAPublicKey) keyTransportCredential.getPublicKey()));
-
- } else if (JWEAlgorithm.Family.ECDH_ES.contains(encAlg) && keyTransportCredential != null &&
- keyTransportCredential.getPublicKey() != null) {
-
- jweObject = new JWEObject(new JWEHeader.Builder(encAlg, encEnc).contentType("JWT")
- .keyID(keyTransportKid).build(), payload);
- logEncryption(keyTransportKid, encAlg.getName(), encEnc.getName());
- jweObject.encrypt(new ECDHEncrypter((ECPublicKey) keyTransportCredential.getPublicKey()));
-
- } else if ((JWEAlgorithm.Family.AES_KW.contains(encAlg) || JWEAlgorithm.Family.AES_GCM_KW.contains(encAlg))
- && keyTransportCredential != null && keyTransportCredential.getSecretKey() != null) {
-
- jweObject = new JWEObject(new JWEHeader.Builder(encAlg, encEnc).contentType("JWT")
- .keyID(keyTransportKid).build(), payload);
- logEncryption(keyTransportKid, encAlg.getName(), encEnc.getName());
- jweObject.encrypt(new AESEncrypter(keyTransportCredential.getSecretKey()));
-
- } else if (JWEAlgorithm.DIR.equals(encAlg) && dataEncryptionCredential != null &&
- dataEncryptionCredential.getSecretKey() != null){
-
- jweObject = new JWEObject(new JWEHeader.Builder(encAlg, encEnc).contentType("JWT")
- .keyID(dataEncryptionKid).build(), payload);
- logEncryption(dataEncryptionKid, encAlg.getName(), encEnc.getName());
- jweObject.encrypt(new DirectEncrypter(dataEncryptionCredential.getSecretKey()));
-
- } else {
- log.error("{} Unsupported algorithm {} or key '{}'", getLogPrefix(), encAlg.getName(),
- keyTransportKid);
- throw new MessageHandlerException("Unsupported algorithm "+encAlg.getName());
- }
-
- final EncryptedJWT encryptedJWT = EncryptedJWT.parse(jweObject.serialize());
- jwtUpdateConsumer.accept(encryptedJWT, messageContext);
-
- if (log.isDebugEnabled() && !log.isTraceEnabled()) {
- log.debug("{} Encrypted '{}' JWT", getLogPrefix(), logName);
- } else if (log.isTraceEnabled()) {
- log.debug("{} Encrypted '{}' JWT: {}", getLogPrefix(), logName, encryptedJWT.serialize());
- }
-
- } catch (final Exception e) {
- log.error("{} Encryption failed", getLogPrefix(), e);
- throw new MessageHandlerException("Encryption failed", e);
- }
-
- }
-
- /**
- * A convince method to log encryption parameters. Avoids some of the clutter in the calling
- * methods.
- *
- * @param keyID the keyID
- * @param enc the content encryption algorithm
- * @param alg the key management algorithm
- */
- private void logEncryption(@Nullable final String keyID,
- @Nullable final String enc, @Nullable final String alg) {
- log.debug("{} Encrypting '{}' with kid '{}' and params alg: {} enc: {}",
- getLogPrefix(), logName, keyID, alg, enc);
- }
-
-}
diff --git a/idp-oidc-rp-impl/src/main/java/net/shibboleth/idp/plugin/authn/oidc/rp/messaging/impl/SignJWTHandler.java b/idp-oidc-rp-impl/src/main/java/net/shibboleth/idp/plugin/authn/oidc/rp/messaging/impl/SignJWTHandler.java
deleted file mode 100644
index c20e288..0000000
--- a/idp-oidc-rp-impl/src/main/java/net/shibboleth/idp/plugin/authn/oidc/rp/messaging/impl/SignJWTHandler.java
+++ /dev/null
@@ -1,282 +0,0 @@
-/*
- * Licensed to the University Corporation for Advanced Internet Development,
- * Inc. (UCAID) under one or more contributor license agreements. See the
- * NOTICE file distributed with this work for additional information regarding
- * copyright ownership. The UCAID licenses this file to You under the Apache
- * License, Version 2.0 (the "License"); you may not use this file except in
- * compliance with the License. You may obtain a copy of the License at
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
- * Unless required by applicable law or agreed to in writing, software
- * distributed under the License is distributed on an "AS IS" BASIS,
- * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- * See the License for the specific language governing permissions and
- * limitations under the License.
- */
-
-package net.shibboleth.idp.plugin.authn.oidc.rp.messaging.impl;
-
-import java.security.interfaces.ECPrivateKey;
-import java.util.function.BiConsumer;
-import java.util.function.Function;
-
-import javax.annotation.Nonnull;
-import javax.annotation.Nullable;
-
-import org.opensaml.messaging.context.MessageContext;
-import org.opensaml.messaging.context.navigate.ChildContextLookup;
-import org.opensaml.messaging.handler.AbstractMessageHandler;
-import org.opensaml.messaging.handler.MessageHandlerException;
-import org.opensaml.security.credential.Credential;
-import org.opensaml.xmlsec.context.SecurityParametersContext;
-import org.slf4j.Logger;
-import org.slf4j.LoggerFactory;
-
-import com.nimbusds.jose.Algorithm;
-import com.nimbusds.jose.JOSEException;
-import com.nimbusds.jose.JOSEObjectType;
-import com.nimbusds.jose.JWSAlgorithm;
-import com.nimbusds.jose.JWSHeader;
-import com.nimbusds.jose.JWSObject.State;
-import com.nimbusds.jose.JWSSigner;
-import com.nimbusds.jose.crypto.ECDSASigner;
-import com.nimbusds.jose.crypto.MACSigner;
-import com.nimbusds.jose.crypto.RSASSASigner;
-import com.nimbusds.jwt.JWT;
-import com.nimbusds.jwt.JWTClaimsSet;
-import com.nimbusds.jwt.SignedJWT;
-
-import net.shibboleth.oidc.security.JWTSignatureSigningParameters;
-import net.shibboleth.oidc.security.context.JWTSecurityParametersContext;
-import net.shibboleth.oidc.security.credential.JWKCredential;
-import net.shibboleth.oidc.security.impl.CredentialConversionUtil;
-import net.shibboleth.utilities.java.support.annotation.constraint.NonnullAfterInit;
-import net.shibboleth.utilities.java.support.annotation.constraint.NotEmpty;
-import net.shibboleth.utilities.java.support.component.ComponentInitializationException;
-import net.shibboleth.utilities.java.support.component.ComponentSupport;
-import net.shibboleth.utilities.java.support.logic.Constraint;
-import net.shibboleth.utilities.java.support.primitive.StringSupport;
-
-/**
- * Action that signs a request object and sets it as the request object to the authentication request.
- */
-//TODO move to commons?
-public class SignJWTHandler extends AbstractMessageHandler {
-
- /** Class logger. */
- @Nonnull private final Logger log = LoggerFactory.getLogger(SignJWTHandler.class);
-
- /** Strategy used to locate the {@link SecurityParametersContext} to use for signing. */
- @Nonnull private Function<MessageContext, JWTSecurityParametersContext> securityParametersLookupStrategy;
-
- /** A consumer that takes the EncryptedJWT and updates the correct object inside the MessageContext.*/
- @NonnullAfterInit private BiConsumer<JWT, MessageContext> jwtUpdateConsumer;
-
- /** Strategy used to locate the payload to encrypt.*/
- @NonnullAfterInit private Function<MessageContext, JWTClaimsSet> claimsToSignLookupStrategy;
-
- /** The signature signing parameters. */
- @Nullable private JWTSignatureSigningParameters signatureSigningParameters;
-
- /** resolved credential. */
- @Nullable private Credential credential;
-
- /** The claims to sign.*/
- @Nullable private JWTClaimsSet jwtClaimSetToSign;
-
- /** "typ" header to insert while signing. */
- @Nullable @NotEmpty private String typeHeader;
-
- /** A friendly name to log as the subject of signing.*/
- @Nonnull private String logName;
-
- /** Constructor.*/
- public SignJWTHandler() {
- logName = "not-specified";
- securityParametersLookupStrategy = new ChildContextLookup<>(JWTSecurityParametersContext.class);
- }
-
- /**
- * Set the friendly name to log as the subject of signing.
- *
- * @param name the friendly name
- */
- public void setLogName(@Nonnull @NotEmpty final String name) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
- ComponentSupport.ifDestroyedThrowDestroyedComponentException(this);
-
- logName = Constraint.isNotEmpty(name, "ForFriendlyName can not be null or empty");
- }
-
- @Override
- protected void doInitialize() throws ComponentInitializationException {
- if (claimsToSignLookupStrategy == null) {
- throw new ComponentInitializationException("claimsToSignLookupStrategy can not be null");
- }
- if (jwtUpdateConsumer == null) {
- throw new ComponentInitializationException("jwtUpdateConsumer can not be null");
- }
- super.doInitialize();
- }
-
- /**
- * Set the strategy used to locate the {@link JWTClaimsSet} to sign.
- *
- * @param strategy the strategy
- */
- public void setClaimsToSignLookupStrategy(@Nonnull final Function<MessageContext, JWTClaimsSet> strategy) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
- ComponentSupport.ifDestroyedThrowDestroyedComponentException(this);
-
- claimsToSignLookupStrategy =
- Constraint.isNotNull(strategy, "claimsToSignLookupStrategy can not be null");
- }
-
- /**
- * Set the consumer used to update the MessageContext with the supplied EncryptedJWT.
- *
- * @param consumer the consumer
- */
- public void setJwtUpdateConsumer(final BiConsumer<JWT, MessageContext> consumer) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
- ComponentSupport.ifDestroyedThrowDestroyedComponentException(this);
-
- jwtUpdateConsumer = Constraint.isNotNull(consumer, "JwtUpdateConsumer can not be null");
- }
-
- /**
- * Sets the value to be inserted as a "typ" header for the JWS.
- *
- * @param type header value
- */
- public void setTypeHeader(@Nullable @NotEmpty final String type) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
-
- typeHeader = StringSupport.trimOrNull(type);
- }
-
- /**
- * Set the strategy used to locate the {@link SecurityParametersContext} to use.
- *
- * @param strategy lookup strategy
- */
- public void setSecurityParametersLookupStrategy(
- @Nonnull final Function<MessageContext, JWTSecurityParametersContext> strategy) {
- ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
-
- securityParametersLookupStrategy =
- Constraint.isNotNull(strategy, "SecurityParameterContext lookup strategy cannot be null");
- }
-
- /** {@inheritDoc} */
- @Override
- protected boolean doPreInvoke(@Nonnull final MessageContext messageContext) throws MessageHandlerException {
-
- if (!super.doPreInvoke(messageContext)) {
- return false;
- }
-
- final JWTSecurityParametersContext secParamCtx =
- securityParametersLookupStrategy.apply(messageContext);
- if (secParamCtx == null) {
- log.debug("{} Message context did not contain signing parameters, "
- + "request object will not be signed", getLogPrefix());
- return false;
- }
-
- signatureSigningParameters = secParamCtx.getSignatureSigningParameters();
- if (signatureSigningParameters == null || signatureSigningParameters.getSigningCredential() == null) {
- log.debug("{} No signature signing credentials available", getLogPrefix());
- return false;
- }
-
- jwtClaimSetToSign = claimsToSignLookupStrategy.apply(messageContext);
- if (jwtClaimSetToSign == null) {
- log.debug("{} No JWT ClaimsSet, nothing to sign", getLogPrefix());
- return false;
- }
-
- credential = signatureSigningParameters.getSigningCredential();
-
- return true;
-
- }
-
- @Override
- protected void doInvoke(@Nonnull final MessageContext messageContext) throws MessageHandlerException {
-
- try {
- SignedJWT jwt = null;
- final Algorithm jwsAlgorithm = resolveAlgorithm();
- final JWSSigner signer = getSigner(jwsAlgorithm);
- final JWSHeader.Builder headerBuilder = new JWSHeader.Builder(new JWSAlgorithm(jwsAlgorithm.getName()))
- .keyID(CredentialConversionUtil.resolveKid(credential));
- if (typeHeader != null) {
- headerBuilder.type(new JOSEObjectType(typeHeader));
- }
- jwt = new SignedJWT(headerBuilder.build(), jwtClaimSetToSign);
- jwt.sign(signer);
- if (log.isDebugEnabled() && !log.isTraceEnabled()) {
- log.debug("{} Signed JWT '{}'", getLogPrefix(), logName);
- } else if (log.isTraceEnabled()) {
- log.trace("{} Signed JWT '{}': {}", getLogPrefix(), logName, jwt.serialize());
- }
-
- if (jwt.getState() != State.SIGNED) {
- // Should not really happen, as JOSEException should be thrown
- log.error("{} JWT '{}' was not signed", getLogPrefix(), logName);
- throw new MessageHandlerException("JWT was not signed, unknown cause");
- }
-
- // Update to the signed JWT
- jwtUpdateConsumer.accept(jwt, messageContext);
-
- } catch (final JOSEException e) {
- log.error("{} Error signing claim set: {}", getLogPrefix(), e.getMessage());
- throw new MessageHandlerException("Error signing claims set",e);
- }
-
-
- }
-
- /**
- * Returns correct implementation of signer based on algorithm type.
- *
- * @param jwsAlgorithm JWS algorithm
- * @return signer for algorithm and private key
- * @throws JOSEException if algorithm cannot be supported
- */
- private JWSSigner getSigner(final Algorithm jwsAlgorithm) throws JOSEException {
- if (JWSAlgorithm.Family.EC.contains(jwsAlgorithm)) {
- return new ECDSASigner((ECPrivateKey) credential.getPrivateKey());
- }
- if (JWSAlgorithm.Family.RSA.contains(jwsAlgorithm)) {
- return new RSASSASigner(credential.getPrivateKey());
- }
- if (JWSAlgorithm.Family.HMAC_SHA.contains(jwsAlgorithm)) {
- return new MACSigner(credential.getSecretKey());
- }
- throw new JOSEException("Unsupported algorithm " + jwsAlgorithm.getName());
- }
-
- /**
- * Resolves JWS algorithm from signature signing parameters.
- *
- * @return JWS algorithm
- */
- protected JWSAlgorithm resolveAlgorithm() {
-
- final JWSAlgorithm algorithm = new JWSAlgorithm(signatureSigningParameters.getSignatureAlgorithm());
- if (credential instanceof JWKCredential && !algorithm.equals(((JWKCredential) credential).getAlgorithm())) {
- log.debug("{} Signature signing algorithm {} differs from JWK algorithm {}", getLogPrefix(),
- algorithm.getName(), (((JWKCredential) credential).getAlgorithm() != null ?
- ((JWKCredential) credential).getAlgorithm() : "not specified"));
- }
- log.trace("{} Algorithm resolved {}", getLogPrefix(), algorithm.getName());
- return algorithm;
- }
-
-
-
-}
diff --git a/idp-oidc-rp-impl/src/main/resources/META-INF/net/shibboleth/idp/flows/authn/OIDCRelyingParty/oidc-relying-party-authn-beans.xml b/idp-oidc-rp-impl/src/main/resources/META-INF/net/shibboleth/idp/flows/authn/OIDCRelyingParty/oidc-relying-party-authn-beans.xml
index 226e007..a3ae92e 100644
--- a/idp-oidc-rp-impl/src/main/resources/META-INF/net/shibboleth/idp/flows/authn/OIDCRelyingParty/oidc-relying-party-authn-beans.xml
+++ b/idp-oidc-rp-impl/src/main/resources/META-INF/net/shibboleth/idp/flows/authn/OIDCRelyingParty/oidc-relying-party-authn-beans.xml
@@ -270,7 +270,7 @@
class="net.shibboleth.idp.plugin.authn.oidc.rp.messaging.impl.BuildPlainRequestObjectJWT"
scope="prototype" />
- <bean id="SignRequestObject" class="net.shibboleth.idp.plugin.authn.oidc.rp.messaging.impl.SignJWTHandler"
+ <bean id="SignRequestObject" class="net.shibboleth.oidc.security.impl.SignJWTHandler"
scope="prototype" p:logName="RequestObject">
<property name="claimsToSignLookupStrategy">
<bean
@@ -283,7 +283,7 @@
</bean>
<bean id="EncryptRequestObject"
- class="net.shibboleth.idp.plugin.authn.oidc.rp.messaging.impl.EncryptJWTHandler" scope="prototype"
+ class="net.shibboleth.oidc.security.impl.EncryptJWTHandler" scope="prototype"
p:logName="RequestObject">
<property name="payloadToEncryptLookupStrategy">
<bean
--
To stop receiving notification emails like this one, please contact
the administrator of this repository.
More information about the commits
mailing list