[java-identity-provider] 01/11: IDP-2039 - Add audit logging to login flows
Scott Cantor
cantor.2 at osu.edu
Tue Jan 3 22:01:41 UTC 2023
This is an automated email from the git hooks/post-receive script.
scantor pushed a commit to branch main
in repository java-identity-provider.
View the commit online:
http://git.shibboleth.net/view/?p=java-identity-provider.git;a=commit;h=62a0c3d9ddeda5fa108b5f08dfa363aee630d5ea
commit 62a0c3d9ddeda5fa108b5f08dfa363aee630d5ea
Author: Scott Cantor <cantor.2 at osu.edu>
AuthorDate: Tue Dec 6 12:00:19 2022 -0500
IDP-2039 - Add audit logging to login flows
https://shibboleth.atlassian.net/browse/IDP-2039
New abstract validator base class added with auditing support.
Beans added to authn.abstract flow for use by login flows.
Password flow adjusted to include audit logging.
---
.../net/shibboleth/idp/authn/AuthnAuditFields.java | 23 ++-
idp-authn-impl/pom.xml | 5 +
.../AttemptedAuthenticationFlowAuditExtractor.java | 40 ++---
.../impl/AttemptedUsernameAuditExtractor.java | 51 ++++++
.../impl/AuthenticationErrorAuditExtractor.java | 55 ++++++
.../impl/TransformedUsernameAuditExtractor.java | 51 ++++++
.../impl/AbstractAuditingValidationAction.java | 191 +++++++++++++++++++++
.../idp/authn/impl/ValidateCredentials.java | 38 ++--
.../idp/flows/authn/authn-abstract-beans.xml | 99 +++++++++++
.../idp/flows/authn/authn-abstract-flow.xml | 2 +
.../idp/flows/authn/password-authn-beans.xml | 52 +++++-
.../src/main/resources/conf/authn/authn.properties | 3 +
idp-conf/src/main/resources/conf/logback.xml | 24 +++
.../profile/audit/impl/PopulateAuditContext.java | 4 +-
14 files changed, 592 insertions(+), 46 deletions(-)
diff --git a/idp-authn-api/src/main/java/net/shibboleth/idp/authn/AuthnAuditFields.java b/idp-authn-api/src/main/java/net/shibboleth/idp/authn/AuthnAuditFields.java
index 906622e1c..a3ec311f0 100644
--- a/idp-authn-api/src/main/java/net/shibboleth/idp/authn/AuthnAuditFields.java
+++ b/idp-authn-api/src/main/java/net/shibboleth/idp/authn/AuthnAuditFields.java
@@ -37,7 +37,28 @@ public final class AuthnAuditFields {
/** SSO indicator signaling authentication was not "freshly" performed. */
@Nonnull @NotEmpty public static final String SSO = "SSO";
-
+
+ /**
+ * A username after undergoing transformation for input to validation.
+ *
+ * @since 4.3.0
+ */
+ @Nonnull @NotEmpty public static final String TRANSFORMED_USERNAME = "tu";
+
+ /**
+ * Identifies the {@link CredentialValidator} used.
+ *
+ * @since 4.3.0
+ */
+ @Nonnull @NotEmpty public static final String CREDENTIAL_VALIDATOR = "CV";
+
+ /**
+ * Authentication results, either "Success" or any classified error results.
+ *
+ * @since 4.3.0
+ */
+ @Nonnull @NotEmpty public static final String AUTHN_RESULT = "AR";
+
/** Constructor. */
private AuthnAuditFields() {
diff --git a/idp-authn-impl/pom.xml b/idp-authn-impl/pom.xml
index 6d4a88287..a19971159 100644
--- a/idp-authn-impl/pom.xml
+++ b/idp-authn-impl/pom.xml
@@ -42,6 +42,11 @@
<artifactId>idp-profile-api</artifactId>
<version>${project.version}</version>
</dependency>
+ <dependency>
+ <groupId>${project.groupId}</groupId>
+ <artifactId>idp-profile-impl</artifactId>
+ <version>${project.version}</version>
+ </dependency>
<dependency>
<groupId>${project.groupId}</groupId>
<artifactId>idp-ui</artifactId>
diff --git a/idp-authn-api/src/main/java/net/shibboleth/idp/authn/AuthnAuditFields.java b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AttemptedAuthenticationFlowAuditExtractor.java
similarity index 50%
copy from idp-authn-api/src/main/java/net/shibboleth/idp/authn/AuthnAuditFields.java
copy to idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AttemptedAuthenticationFlowAuditExtractor.java
index 906622e1c..be982c274 100644
--- a/idp-authn-api/src/main/java/net/shibboleth/idp/authn/AuthnAuditFields.java
+++ b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AttemptedAuthenticationFlowAuditExtractor.java
@@ -15,32 +15,32 @@
* limitations under the License.
*/
-package net.shibboleth.idp.authn;
+package net.shibboleth.idp.authn.audit.impl;
-import javax.annotation.Nonnull;
+import java.util.function.Function;
-import net.shibboleth.shared.annotation.constraint.NotEmpty;
+import javax.annotation.Nullable;
-/**
- * Constants to use for audit logging fields stored in an {@link net.shibboleth.idp.profile.context.AuditContext}.
- */
-public final class AuthnAuditFields {
+import org.opensaml.profile.context.ProfileRequestContext;
- /** Requested principal(s) operator field. @since 4.0.0 */
- @Nonnull @NotEmpty public static final String REQ_PRINC_OP = "ROP";
+import net.shibboleth.idp.authn.context.AuthenticationContext;
- /** Requested principal(s) field. @since 4.0.0 */
- @Nonnull @NotEmpty public static final String REQ_PRINC = "RPRIN";
-
- /** Authentication flow ID field. */
- @Nonnull @NotEmpty public static final String AUTHN_FLOW_ID = "AF";
+/**
+ * {@link Function} that returns the latest attempted authentication flow ID.
+ *
+ * @since 4.3.0
+ */
+public class AttemptedAuthenticationFlowAuditExtractor implements Function<ProfileRequestContext,String> {
- /** SSO indicator signaling authentication was not "freshly" performed. */
- @Nonnull @NotEmpty public static final String SSO = "SSO";
-
- /** Constructor. */
- private AuthnAuditFields() {
+ /** {@inheritDoc} */
+ @Nullable public String apply(@Nullable final ProfileRequestContext input) {
+ final AuthenticationContext authnCtx = input.getSubcontext(AuthenticationContext.class);
+ if (authnCtx != null && authnCtx.getAttemptedFlow() != null) {
+ return authnCtx.getAttemptedFlow().getId();
+ }
+
+ return null;
}
-
+
}
\ No newline at end of file
diff --git a/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AttemptedUsernameAuditExtractor.java b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AttemptedUsernameAuditExtractor.java
new file mode 100644
index 000000000..8bba75c16
--- /dev/null
+++ b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AttemptedUsernameAuditExtractor.java
@@ -0,0 +1,51 @@
+/*
+ * Licensed to the University Corporation for Advanced Internet Development,
+ * Inc. (UCAID) under one or more contributor license agreements. See the
+ * NOTICE file distributed with this work for additional information regarding
+ * copyright ownership. The UCAID licenses this file to You under the Apache
+ * License, Version 2.0 (the "License"); you may not use this file except in
+ * compliance with the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package net.shibboleth.idp.authn.audit.impl;
+
+import java.util.function.Function;
+
+import javax.annotation.Nullable;
+
+import org.opensaml.profile.context.ProfileRequestContext;
+
+import net.shibboleth.idp.authn.context.AuthenticationContext;
+import net.shibboleth.idp.authn.context.UsernamePasswordContext;
+
+/**
+ * {@link Function} that returns the username in a subordinate {@link UsernamePasswordContext},
+ * if any.
+ *
+ * @since 4.3.0
+ */
+public class AttemptedUsernameAuditExtractor implements Function<ProfileRequestContext,String> {
+
+ /** {@inheritDoc} */
+ @Nullable public String apply(@Nullable final ProfileRequestContext input) {
+
+ final AuthenticationContext authnCtx = input.getSubcontext(AuthenticationContext.class);
+ if (authnCtx != null) {
+ final UsernamePasswordContext upContext = authnCtx.getSubcontext(UsernamePasswordContext.class);
+ if (upContext != null) {
+ return upContext.getUsername();
+ }
+ }
+
+ return null;
+ }
+
+}
\ No newline at end of file
diff --git a/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AuthenticationErrorAuditExtractor.java b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AuthenticationErrorAuditExtractor.java
new file mode 100644
index 000000000..9901ccb05
--- /dev/null
+++ b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/AuthenticationErrorAuditExtractor.java
@@ -0,0 +1,55 @@
+/*
+ * Licensed to the University Corporation for Advanced Internet Development,
+ * Inc. (UCAID) under one or more contributor license agreements. See the
+ * NOTICE file distributed with this work for additional information regarding
+ * copyright ownership. The UCAID licenses this file to You under the Apache
+ * License, Version 2.0 (the "License"); you may not use this file except in
+ * compliance with the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package net.shibboleth.idp.authn.audit.impl;
+
+import java.util.Collection;
+import java.util.Collections;
+import java.util.function.Function;
+
+import javax.annotation.Nullable;
+
+import org.opensaml.profile.context.ProfileRequestContext;
+
+import net.shibboleth.idp.authn.context.AuthenticationContext;
+import net.shibboleth.idp.authn.context.AuthenticationErrorContext;
+
+/**
+ * {@link Function} that returns any classified errors found in a subordinate {@link AuthenticationErrorContext},
+ * or "Success" if none.
+ *
+ * @since 4.3.0
+ */
+public class AuthenticationErrorAuditExtractor implements Function<ProfileRequestContext,Collection<String>> {
+
+ /** {@inheritDoc} */
+ @Nullable public Collection<String> apply(@Nullable final ProfileRequestContext input) {
+
+ final AuthenticationContext authnCtx = input.getSubcontext(AuthenticationContext.class);
+ if (authnCtx != null) {
+ final AuthenticationErrorContext errorCtx = authnCtx.getSubcontext(AuthenticationErrorContext.class);
+ if (errorCtx != null) {
+ return errorCtx.getClassifiedErrors();
+ }
+
+ return Collections.singletonList("Success");
+ }
+
+ return null;
+ }
+
+}
\ No newline at end of file
diff --git a/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/TransformedUsernameAuditExtractor.java b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/TransformedUsernameAuditExtractor.java
new file mode 100644
index 000000000..8263f1b70
--- /dev/null
+++ b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/audit/impl/TransformedUsernameAuditExtractor.java
@@ -0,0 +1,51 @@
+/*
+ * Licensed to the University Corporation for Advanced Internet Development,
+ * Inc. (UCAID) under one or more contributor license agreements. See the
+ * NOTICE file distributed with this work for additional information regarding
+ * copyright ownership. The UCAID licenses this file to You under the Apache
+ * License, Version 2.0 (the "License"); you may not use this file except in
+ * compliance with the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package net.shibboleth.idp.authn.audit.impl;
+
+import java.util.function.Function;
+
+import javax.annotation.Nullable;
+
+import org.opensaml.profile.context.ProfileRequestContext;
+
+import net.shibboleth.idp.authn.context.AuthenticationContext;
+import net.shibboleth.idp.authn.context.UsernamePasswordContext;
+
+/**
+ * {@link Function} that returns the transformed username in a subordinate {@link UsernamePasswordContext},
+ * if any.
+ *
+ * @since 4.3.0
+ */
+public class TransformedUsernameAuditExtractor implements Function<ProfileRequestContext,String> {
+
+ /** {@inheritDoc} */
+ @Nullable public String apply(@Nullable final ProfileRequestContext input) {
+
+ final AuthenticationContext authnCtx = input.getSubcontext(AuthenticationContext.class);
+ if (authnCtx != null) {
+ final UsernamePasswordContext upContext = authnCtx.getSubcontext(UsernamePasswordContext.class);
+ if (upContext != null) {
+ return upContext.getTransformedUsername();
+ }
+ }
+
+ return null;
+ }
+
+}
\ No newline at end of file
diff --git a/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/impl/AbstractAuditingValidationAction.java b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/impl/AbstractAuditingValidationAction.java
new file mode 100644
index 000000000..e6a68bc08
--- /dev/null
+++ b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/impl/AbstractAuditingValidationAction.java
@@ -0,0 +1,191 @@
+/*
+ * Licensed to the University Corporation for Advanced Internet Development,
+ * Inc. (UCAID) under one or more contributor license agreements. See the
+ * NOTICE file distributed with this work for additional information regarding
+ * copyright ownership. The UCAID licenses this file to You under the Apache
+ * License, Version 2.0 (the "License"); you may not use this file except in
+ * compliance with the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package net.shibboleth.idp.authn.impl;
+
+import java.util.Map;
+import java.util.function.Function;
+
+import javax.annotation.Nonnull;
+import javax.annotation.Nullable;
+
+import org.opensaml.messaging.context.navigate.ChildContextLookup;
+import org.opensaml.profile.context.EventContext;
+import org.opensaml.profile.context.ProfileRequestContext;
+import org.springframework.webflow.execution.Event;
+import org.springframework.webflow.execution.RequestContext;
+
+import net.shibboleth.idp.authn.AbstractValidationAction;
+import net.shibboleth.idp.authn.context.AuthenticationContext;
+import net.shibboleth.idp.profile.audit.impl.PopulateAuditContext;
+import net.shibboleth.idp.profile.audit.impl.WriteAuditLog;
+import net.shibboleth.idp.profile.context.AuditContext;
+import net.shibboleth.utilities.java.support.annotation.constraint.NonnullElements;
+import net.shibboleth.utilities.java.support.component.ComponentSupport;
+import net.shibboleth.utilities.java.support.logic.Constraint;
+
+/**
+ * Base class for validation actions that includes new audit logging support.
+ *
+ * <p>This is not great design, but embedding the existing audit action classes
+ * as fields is by far the simplest way to reuse that logic without getting caught up
+ * in the vagaries of the individual validator's logic.</p>
+ *
+ * @since 4.3.0
+ */
+public abstract class AbstractAuditingValidationAction extends AbstractValidationAction {
+
+ /** Strategy used to locate or create the {@link AuditContext} to populate. */
+ @Nonnull private Function<ProfileRequestContext,AuditContext> auditContextCreationStrategy;
+
+ /** Optional audit extraction action. */
+ @Nullable private PopulateAuditContext populateAuditContextAction;
+
+ /** Optional audit output action. */
+ @Nullable private WriteAuditLog writeAuditLogAction;
+
+ /** The Spring RequestContext to operate on. */
+ @Nullable private RequestContext requestContext;
+
+ /** Constructor. */
+ public AbstractAuditingValidationAction() {
+ auditContextCreationStrategy =
+ new ChildContextLookup<>(AuditContext.class, true).compose(
+ new ChildContextLookup<>(AuthenticationContext.class));
+ }
+
+ /**
+ * Set the strategy used to locate the {@link AuditContext} associated with a given
+ * {@link ProfileRequestContext}.
+ *
+ * @param strategy lookup strategy
+ */
+ public void setAuditContextCreationStrategy(@Nonnull final Function<ProfileRequestContext,AuditContext> strategy) {
+ ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
+
+ auditContextCreationStrategy = Constraint.isNotNull(strategy, "AuditContext creation strategy cannot be null");
+ }
+
+ /**
+ * Sets an audit context population action to run.
+ *
+ * @param action optional action to use to populate audit context
+ *
+ * @since 4.3.0
+ */
+ public void setPopulateAuditContextAction(@Nullable final PopulateAuditContext action) {
+ ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
+
+ populateAuditContextAction = action;
+ }
+
+ /**
+ * Sets an audit output action to run.
+ *
+ * @param action optional action to use to write to audit log
+ *
+ * @since 4.3.0
+ */
+ public void setWriteAuditLogAction(@Nullable final WriteAuditLog action) {
+ ComponentSupport.ifInitializedThrowUnmodifiabledComponentException(this);
+
+ writeAuditLogAction = action;
+ }
+
+ /** {@inheritDoc} */
+ @Override
+ protected Event doExecute(@Nonnull final RequestContext springRequestContext,
+ @Nonnull final ProfileRequestContext profileRequestContext) {
+
+ requestContext = springRequestContext;
+ return super.doExecute(springRequestContext, profileRequestContext);
+ }
+
+ /** {@inheritDoc} */
+ @Override
+ protected void recordSuccess(@Nonnull final ProfileRequestContext profileRequestContext) {
+ doAudit(profileRequestContext);
+ super.recordSuccess(profileRequestContext);
+ }
+
+ /** {@inheritDoc} */
+ @Override
+ protected void recordFailure(@Nonnull final ProfileRequestContext profileRequestContext) {
+ doAudit(profileRequestContext);
+ super.recordFailure(profileRequestContext);
+ }
+
+ /**
+ * Create or locate the {@link AuditContext} via the defined strategy.
+ *
+ * @param profileRequestContext profile request context
+ *
+ * @return the audit context
+ */
+ @Nullable protected AuditContext getAuditContext(@Nonnull final ProfileRequestContext profileRequestContext) {
+ return auditContextCreationStrategy.apply(profileRequestContext);
+ }
+
+ /**
+ * Do audit extraction and output.
+ *
+ * @param profileRequestContext profile request context
+ */
+ protected void doAudit(@Nonnull final ProfileRequestContext profileRequestContext) {
+ if (populateAuditContextAction != null && writeAuditLogAction != null) {
+ final EventContext existingEvent = profileRequestContext.getSubcontext(EventContext.class);
+
+ try {
+ populateAuditContextAction.execute(requestContext);
+
+ final Map<String,String> fields = getAuditFields(profileRequestContext);
+ if (fields != null) {
+ final AuditContext ac = getAuditContext(profileRequestContext);
+ if (ac != null) {
+ for (final Map.Entry<String,String> field : fields.entrySet()) {
+ ac.getFieldValues(field.getKey()).add(field.getValue());
+ }
+ }
+ }
+ } finally {
+ if (existingEvent != null) {
+ profileRequestContext.addSubcontext(existingEvent);
+ }
+ }
+
+ try {
+ writeAuditLogAction.execute(requestContext);
+ } finally {
+ if (existingEvent != null) {
+ profileRequestContext.addSubcontext(existingEvent);
+ }
+ }
+ }
+ }
+
+ /**
+ * Subclasses can override this method to supply additional audit fields to store.
+ *
+ * @param profileRequestContext profile request context
+ * @return audit fields
+ */
+ @Nullable @NonnullElements protected Map<String,String> getAuditFields(
+ @Nonnull final ProfileRequestContext profileRequestContext) {
+ return null;
+ }
+
+}
\ No newline at end of file
diff --git a/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/impl/ValidateCredentials.java b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/impl/ValidateCredentials.java
index 4d7696b48..0e727c19b 100644
--- a/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/impl/ValidateCredentials.java
+++ b/idp-authn-impl/src/main/java/net/shibboleth/idp/authn/impl/ValidateCredentials.java
@@ -21,6 +21,7 @@ import java.util.ArrayList;
import java.util.Collection;
import java.util.Collections;
import java.util.List;
+import java.util.Map;
import java.util.function.Consumer;
import javax.annotation.Nonnull;
@@ -33,9 +34,9 @@ import org.opensaml.profile.context.ProfileRequestContext;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
-import net.shibboleth.idp.authn.AbstractValidationAction;
import net.shibboleth.idp.authn.AccountLockoutManager;
import net.shibboleth.idp.authn.AuthenticationResult;
+import net.shibboleth.idp.authn.AuthnAuditFields;
import net.shibboleth.idp.authn.AuthnEventIds;
import net.shibboleth.idp.authn.CredentialValidator;
import net.shibboleth.idp.authn.CredentialValidator.ErrorHandler;
@@ -54,7 +55,7 @@ import net.shibboleth.shared.annotation.constraint.NotEmpty;
*
* @since 4.0.0
*/
-public class ValidateCredentials extends AbstractValidationAction implements WarningHandler, ErrorHandler {
+public class ValidateCredentials extends AbstractAuditingValidationAction implements WarningHandler, ErrorHandler {
/** Default prefix for metrics. */
@Nonnull @NotEmpty private static final String DEFAULT_METRIC_NAME = "net.shibboleth.idp.authn";
@@ -64,13 +65,13 @@ public class ValidateCredentials extends AbstractValidationAction implements War
/** Ordered list of validators. */
@Nonnull @NonnullElements private List<CredentialValidator> credentialValidators;
-
+
/** Whether all validators must succeed. */
private boolean requireAll;
/** Optional lockout management interface. */
@Nullable private AccountLockoutManager lockoutManager;
-
+
/** Results from successful validators. */
@Nonnull @NonnullElements private Collection<Subject> results;
@@ -196,14 +197,15 @@ public class ValidateCredentials extends AbstractValidationAction implements War
return;
}
} catch (final Exception e) {
- recordFailure(profileRequestContext);
- if (requireAll) {
+ if (requireAll || !errorSignaled) {
super.handleError(profileRequestContext, authenticationContext, e, AuthnEventIds.AUTHN_EXCEPTION);
errorSignaled = true;
+ }
+
+ recordFailure(profileRequestContext);
+
+ if (requireAll) {
break;
- } else if (!errorSignaled) {
- super.handleError(profileRequestContext, authenticationContext, e, AuthnEventIds.AUTHN_EXCEPTION);
- errorSignaled = true;
}
}
}
@@ -247,11 +249,11 @@ public class ValidateCredentials extends AbstractValidationAction implements War
}
/**
- * Record a successful authentication attempt against the configured counter,
- * optionally clearing account lockout state.
+ * {@inheritDoc}
*
- * @param profileRequestContext current profile request context
+ * <p>Also optionally clears account lockout state.</p>
*/
+ @Override
protected void recordSuccess(@Nonnull final ProfileRequestContext profileRequestContext) {
// Need to do this first because the superclass's method will call the cleanup hook.
if (lockoutManager != null) {
@@ -259,9 +261,17 @@ public class ValidateCredentials extends AbstractValidationAction implements War
log.warn("{} Failed to clear lockout state", getLogPrefix());
}
}
+
super.recordSuccess(profileRequestContext);
}
-
+
+ /** {@inheritDoc} */
+ @Override
+ @Nullable @NonnullElements protected Map<String,String> getAuditFields(
+ @Nonnull final ProfileRequestContext profileRequestContext) {
+ return Map.of(AuthnAuditFields.CREDENTIAL_VALIDATOR, currentValidator.getId());
+ }
+
/**
* A default cleanup hook that removes the {@link UsernamePasswordContext} from the tree.
*
@@ -286,4 +296,4 @@ public class ValidateCredentials extends AbstractValidationAction implements War
}
}
-}
\ No newline at end of file
+}
diff --git a/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/authn-abstract-beans.xml b/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/authn-abstract-beans.xml
new file mode 100644
index 000000000..cd9636ff8
--- /dev/null
+++ b/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/authn-abstract-beans.xml
@@ -0,0 +1,99 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<beans xmlns="http://www.springframework.org/schema/beans"
+ xmlns:context="http://www.springframework.org/schema/context"
+ xmlns:util="http://www.springframework.org/schema/util"
+ xmlns:p="http://www.springframework.org/schema/p"
+ xmlns:c="http://www.springframework.org/schema/c"
+ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
+ xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd
+ http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context.xsd
+ http://www.springframework.org/schema/util http://www.springframework.org/schema/util/spring-util.xsd"
+
+ default-init-method="initialize"
+ default-destroy-method="destroy">
+
+ <!-- The actual abstract-authn flow doesn't use anything in here so far but child flows do. -->
+
+ <bean class="org.springframework.context.support.PropertySourcesPlaceholderConfigurer"
+ p:placeholderPrefix="%{" p:placeholderSuffix="}" />
+
+ <bean class="net.shibboleth.ext.spring.config.IdentifiableBeanPostProcessor" />
+ <bean class="net.shibboleth.idp.profile.impl.ProfileActionBeanPostProcessor" />
+
+ <!-- Most/all of this is for login flow auditing right now. -->
+
+ <!-- Private copy of AuditContext for login flows. -->
+ <bean id="AuthenticationAuditContextLookup"
+ parent="shibboleth.Functions.Compose">
+ <constructor-arg name="g">
+ <bean id="shibboleth.ChildLookup.AuditContext"
+ class="org.opensaml.messaging.context.navigate.ChildContextLookup"
+ c:type="#{ T(net.shibboleth.idp.profile.context.AuditContext) }"
+ c:createContext="true" />
+ </constructor-arg>
+ <constructor-arg name="f">
+ <ref bean="shibboleth.ChildLookup.AuthenticationContext" />
+ </constructor-arg>
+ </bean>
+
+ <bean id="shibboleth.authn.AbstractPopulateAuditContext" abstract="true"
+ class="net.shibboleth.idp.profile.audit.impl.PopulateAuditContext" scope="prototype"
+ p:auditContextCreationStrategy-ref="AuthenticationAuditContextLookup"
+ p:formattingMapParser-ref="shibboleth.authn.AuditFormattingMapParser"
+ p:dateTimeFormat="#{getObject('shibboleth.AuditDateTimeFormat')}"
+ p:useDefaultTimeZone="#{getObject('shibboleth.AuditDefaultTimeZone') ?: false}"
+ p:fieldReplacements="#{getObject('shibboleth.AuditFieldReplacementMap')}" />
+
+ <bean id="shibboleth.authn.AuditFormattingMapParser" scope="prototype" lazy-init="true"
+ class="net.shibboleth.idp.profile.audit.impl.PopulateAuditContext.FormattingMapParser"
+ c:_0-ref="shibboleth.authn.AuditFormattingMap" />
+
+ <bean id="WriteAuditLog" class="net.shibboleth.idp.profile.audit.impl.WriteAuditLog" scope="prototype" lazy-init="true"
+ p:formattingMap-ref="shibboleth.authn.AuditFormattingMap"
+ p:dateTimeFormat="#{getObject('shibboleth.AuditDateTimeFormat')}"
+ p:useDefaultTimeZone="#{getObject('shibboleth.AuditDefaultTimeZone') ?: false}"
+ p:includeProfileLoggingId="false"
+ p:httpServletRequestSupplier-ref="shibboleth.HttpServletRequestSupplier"
+ p:activationCondition="%{idp.authn.audit.enabled:false}"
+ p:auditContextLookupStrategy-ref="AuthenticationAuditContextLookup"/>
+
+ <bean id="shibboleth.authn.DefaulAuditExtractors" lazy-init="true"
+ class="org.springframework.beans.factory.config.MapFactoryBean">
+ <property name="sourceMap">
+ <map>
+ <entry>
+ <key>
+ <util:constant static-field="net.shibboleth.idp.authn.AuthnAuditFields.AUTHN_FLOW_ID"/>
+ </key>
+ <bean class="net.shibboleth.idp.authn.audit.impl.AttemptedAuthenticationFlowAuditExtractor" />
+ </entry>
+ <entry>
+ <key>
+ <util:constant static-field="net.shibboleth.idp.authn.AuthnAuditFields.AUTHN_RESULT"/>
+ </key>
+ <bean class="net.shibboleth.idp.authn.audit.impl.AuthenticationErrorAuditExtractor" />
+ </entry>
+ <entry>
+ <key>
+ <util:constant static-field="net.shibboleth.idp.saml.profile.SAMLAuditFields.SERVICE_PROVIDER"/>
+ </key>
+ <ref bean="shibboleth.RelyingPartyIdLookup.Simple" />
+ </entry>
+ <entry>
+ <key>
+ <util:constant static-field="net.shibboleth.idp.profile.IdPAuditFields.SESSION_ID"/>
+ </key>
+ <bean parent="shibboleth.Functions.Compose">
+ <constructor-arg name="g">
+ <bean class="net.shibboleth.idp.session.context.navigate.SessionContextIDLookupFunction" />
+ </constructor-arg>
+ <constructor-arg name="f">
+ <ref bean="shibboleth.ChildLookup.SessionContext" />
+ </constructor-arg>
+ </bean>
+ </entry>
+ </map>
+ </property>
+ </bean>
+
+</beans>
diff --git a/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/authn-abstract-flow.xml b/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/authn-abstract-flow.xml
index 5fa91b3d2..94ebcc96e 100644
--- a/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/authn-abstract-flow.xml
+++ b/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/authn-abstract-flow.xml
@@ -92,4 +92,6 @@
<transition on="SubjectCanonicalizationError" to="SubjectCanonicalizationError" />
</global-transitions>
+ <bean-import resource="classpath:/net/shibboleth/idp/flows/authn/authn-abstract-beans.xml" />
+
</flow>
diff --git a/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/password-authn-beans.xml b/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/password-authn-beans.xml
index 4cb020d13..0ffad443a 100644
--- a/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/password-authn-beans.xml
+++ b/idp-conf-impl/src/main/resources/net/shibboleth/idp/flows/authn/password-authn-beans.xml
@@ -80,7 +80,9 @@
p:classifiedMessages="#{getObject('shibboleth.authn.Password.ClassifiedMessageMap')}"
p:resultCachingPredicate="#{getObject('shibboleth.authn.Password.resultCachingPredicate')}"
p:cleanupHook="#{getObject('shibboleth.authn.Password.RemoveAfterValidation') == true ? getObject('DefaultCleanupHook') : null}"
- p:lockoutManager="#{getObject('shibboleth.authn.Password.AccountLockoutManager')}" />
+ p:lockoutManager="#{getObject('shibboleth.authn.Password.AccountLockoutManager')}"
+ p:populateAuditContextAction="#{%{idp.authn.Password.audit.enabled:%{idp.authn.audit.enabled:false}} ? getObject('shibboleth.authn.Password.PopulateAuditContext') : null}"
+ p:writeAuditLogAction="#{%{idp.authn.Password.audit.enabled:%{idp.authn.audit.enabled:false}} ? getObject('WriteAuditLog') : null}" />
<!-- New parent bean for defining validators. -->
@@ -107,14 +109,14 @@
<!-- Legacy validators defined under V3 action bean names. -->
<bean id="ValidateUsernamePasswordAgainstJAAS" parent="shibboleth.CredentialValidator" lazy-init="true"
- class="net.shibboleth.idp.authn.impl.JAASCredentialValidator"
- p:id="jaas"
- p:loginConfigStrategy="#{getObject('shibboleth.authn.JAAS.LoginConfigStrategy')}"
- p:loginConfigNames-ref="shibboleth.authn.JAAS.LoginConfigNames"
- p:loginConfigurations="#{getObject('shibboleth.authn.JAAS.LoginConfigurations')}"
- p:loginConfigType="JavaLoginConfig"
- p:loginConfigResource="#{'%{idp.authn.JAAS.loginConfig:%{idp.home}/conf/authn/jaas.config}'.trim()}"
- p:loginConfigParameters="#{getObject('shibboleth.authn.JAAS.JAASConfigURI')}" />
+ class="net.shibboleth.idp.authn.impl.JAASCredentialValidator"
+ p:id="jaas"
+ p:loginConfigStrategy="#{getObject('shibboleth.authn.JAAS.LoginConfigStrategy')}"
+ p:loginConfigNames-ref="shibboleth.authn.JAAS.LoginConfigNames"
+ p:loginConfigurations="#{getObject('shibboleth.authn.JAAS.LoginConfigurations')}"
+ p:loginConfigType="JavaLoginConfig"
+ p:loginConfigResource="#{'%{idp.authn.JAAS.loginConfig:%{idp.home}/conf/authn/jaas.config}'.trim()}"
+ p:loginConfigParameters="#{getObject('shibboleth.authn.JAAS.JAASConfigURI')}" />
<bean id="shibboleth.authn.JAAS.LoginConfigStrategy.RelyingPartyMap" abstract="true"
class="net.shibboleth.idp.authn.impl.RelyingPartyMapJAASLoginConfigStrategy" />
@@ -176,4 +178,36 @@
p:accountStateWarningPeriod="%{idp.authn.LDAP.accountStateWarningPeriod:#{null}}"
p:accountStateLoginFailures="%{idp.authn.LDAP.accountStateLoginFailures:0}" />
+ <!-- Audit logging beans. -->
+
+ <!-- Default audit format and extractors -->
+ <util:map id="shibboleth.authn.AuditFormattingMap">
+ <entry key="#{'%{idp.authn.Password.audit.category:Shibboleth-Audit.Password}'.trim()}"
+ value="#{'%{idp.authn.Password.audit.format:%a|%T|%SP|%s|%AF|%CV|%u|%tu|%AR|%UA}'.trim()}" />
+ </util:map>
+
+ <bean id="shibboleth.authn.Password.DefaulAuditExtractors" parent="shibboleth.authn.DefaulAuditExtractors" lazy-init="true"
+ class="org.springframework.beans.factory.config.MapFactoryBean">
+ <property name="sourceMap">
+ <map merge="true">
+ <entry>
+ <key>
+ <util:constant static-field="net.shibboleth.idp.profile.IdPAuditFields.USERNAME"/>
+ </key>
+ <bean class="net.shibboleth.idp.authn.audit.impl.AttemptedUsernameAuditExtractor" />
+ </entry>
+ <entry>
+ <key>
+ <util:constant static-field="net.shibboleth.idp.authn.AuthnAuditFields.TRANSFORMED_USERNAME"/>
+ </key>
+ <bean class="net.shibboleth.idp.authn.audit.impl.TransformedUsernameAuditExtractor" />
+ </entry>
+ </map>
+ </property>
+ </bean>
+
+ <bean id="shibboleth.authn.Password.PopulateAuditContext" parent="shibboleth.authn.AbstractPopulateAuditContext" lazy-init="true"
+ p:fieldExtractors="#{getObject('shibboleth.authn.Password.AuditExtractors') ?: getObject('shibboleth.authn.Password.DefaulAuditExtractors')}"
+ p:clearAuditContext="true" />
+
</beans>
diff --git a/idp-conf/src/main/resources/conf/authn/authn.properties b/idp-conf/src/main/resources/conf/authn/authn.properties
index 7d5b6fe86..e6fc04fde 100644
--- a/idp-conf/src/main/resources/conf/authn/authn.properties
+++ b/idp-conf/src/main/resources/conf/authn/authn.properties
@@ -24,6 +24,9 @@
# If using IdP discovery feature, provides a discovery location to use.
#idp.authn.discoveryURL = https://ds.example.org/shibboleth-ds/index.html
+# Login flow audit logging (defaults false for compatibility)
+#idp.authn.audit.enabled = false
+
# Revocation (administrative logout)
#idp.authn.revocation = false
#idp.authn.revocation.lifetime = %{idp.authn.defaultAuthnLifetime:PT12H}
diff --git a/idp-conf/src/main/resources/conf/logback.xml b/idp-conf/src/main/resources/conf/logback.xml
index 50450db24..a4c94d11f 100644
--- a/idp-conf/src/main/resources/conf/logback.xml
+++ b/idp-conf/src/main/resources/conf/logback.xml
@@ -172,6 +172,8 @@
<suffixPattern>[%thread] %logger %msg</suffixPattern>
</appender>
+ <!-- Top level loggers. -->
+
<logger name="Shibboleth-Audit" level="ALL">
<appender-ref ref="${idp.audit.appender:-IDP_AUDIT}"/>
</logger>
@@ -189,4 +191,26 @@
<appender-ref ref="${idp.warn.appender:-IDP_WARN}" />
</root>
+ <!-- Example routing Password flow auditing to separate location (extend to other flows as needed). -->
+
+ <!--
+ <appender name="IDP_PASSWORD_AUDIT" class="ch.qos.logback.core.rolling.RollingFileAppender">
+ <File>${idp.logfiles}/idp-password-audit.log</File>
+
+ <rollingPolicy class="ch.qos.logback.core.rolling.TimeBasedRollingPolicy">
+ <fileNamePattern>${idp.logfiles}/idp-password-audit-%d{yyyy-MM-dd}.log.gz</fileNamePattern>
+ <maxHistory>${idp.loghistory}</maxHistory>
+ </rollingPolicy>
+
+ <encoder class="ch.qos.logback.classic.encoder.PatternLayoutEncoder">
+ <charset>UTF-8</charset>
+ <Pattern>%msg%n</Pattern>
+ </encoder>
+ </appender>
+
+ <logger name="Shibboleth-Audit.Password" level="ALL" additivity="false">
+ <appender-ref ref="IDP_PASSWORD_AUDIT"/>
+ </logger>
+ -->
+
</configuration>
diff --git a/idp-profile-impl/src/main/java/net/shibboleth/idp/profile/audit/impl/PopulateAuditContext.java b/idp-profile-impl/src/main/java/net/shibboleth/idp/profile/audit/impl/PopulateAuditContext.java
index d7ee424cf..4b07ad038 100644
--- a/idp-profile-impl/src/main/java/net/shibboleth/idp/profile/audit/impl/PopulateAuditContext.java
+++ b/idp-profile-impl/src/main/java/net/shibboleth/idp/profile/audit/impl/PopulateAuditContext.java
@@ -110,7 +110,7 @@ public class PopulateAuditContext extends AbstractProfileAction {
*/
public void setAuditContextCreationStrategy(@Nonnull final Function<ProfileRequestContext,AuditContext> strategy) {
checkSetterPreconditions();
- auditContextCreationStrategy = Constraint.isNotNull(strategy, "AuditContext lookup strategy cannot be null");
+ auditContextCreationStrategy = Constraint.isNotNull(strategy, "AuditContext creation strategy cannot be null");
}
/**
@@ -343,4 +343,4 @@ public class PopulateAuditContext extends AbstractProfileAction {
}
}
-}
\ No newline at end of file
+}
--
To stop receiving notification emails like this one, please contact
the administrator of this repository.
More information about the commits
mailing list