Class ValidateExternalAuthentication

    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Class logger.
      • metadataResolver

        @Nullable
        private MetadataResolver metadataResolver
        Optional supplemental metadata source for filtering.
      • matchExpression

        @Nullable
        private Pattern matchExpression
        A regular expression to apply for acceptance testing.
      • attributeContext

        @Nullable
        private AttributeContext attributeContext
        Context for externally supplied inbound attributes.
    • Constructor Detail

      • ValidateExternalAuthentication

        public ValidateExternalAuthentication()
        Constructor.
      • ValidateExternalAuthentication

        public ValidateExternalAuthentication​(@Nullable
                                              ReloadableService<AttributeFilter> filterService)
        Constructor.
        Parameters:
        filterService - optional filter service for inbound attributes
        Since:
        4.0.0
    • Method Detail

      • setMatchExpression

        public void setMatchExpression​(@Nullable
                                       Pattern expression)
        Set a matching expression to apply for username acceptance.
        Parameters:
        expression - a matching expression
      • setMetadataResolver

        public void setMetadataResolver​(@Nullable
                                        MetadataResolver resolver)
        Set a metadata source to use during filtering.
        Parameters:
        resolver - metadata resolver
        Since:
        4.0.0
      • doPreExecute

        protected boolean doPreExecute​(@Nonnull
                                       ProfileRequestContext profileRequestContext,
                                       @Nonnull
                                       AuthenticationContext authenticationContext)
        Performs this authentication action's pre-execute step. Default implementation just returns true.
        Overrides:
        doPreExecute in class AbstractValidationAction
        Parameters:
        profileRequestContext - the current IdP profile request context
        authenticationContext - the current authentication context
        Returns:
        true iff execution should continue
      • doExecute

        protected void doExecute​(@Nonnull
                                 ProfileRequestContext profileRequestContext,
                                 @Nonnull
                                 AuthenticationContext authenticationContext)
        Performs this authentication action. Default implementation throws an exception.
        Overrides:
        doExecute in class AbstractAuthenticationAction
        Parameters:
        profileRequestContext - the current IdP profile request context
        authenticationContext - the current authentication context
      • populateSubject

        @Nonnull
        protected Subject populateSubject​(@Nonnull
                                          Subject subject)
        Subclasses must override this method to complete the population of the Subject with Principal and credential information based on the validation they perform.

        Typically this will include attaching a UsernamePrincipal, but this is not a requirement if other components are suitably overridden.

        Specified by:
        populateSubject in class AbstractValidationAction
        Parameters:
        subject - subject to populate
        Returns:
        the input subject
      • checkUsername

        private boolean checkUsername​(@Nonnull
                                      Subject subject)
        Validate the username if necessary.
        Parameters:
        subject - subject containing a UsernamePrincipal to check
        Returns:
        true iff the username is acceptable
      • getUsername

        @Nullable
        private String getUsername​(@Nonnull
                                   Subject subject)
        Get the username from a UsernamePrincipal inside the subject.
        Parameters:
        subject - input subject
        Returns:
        username, or null
      • filterAttributes

        private void filterAttributes()
        Check for inbound attributes and apply filtering.
      • populateFilterContext

        private void populateFilterContext​(@Nonnull
                                           AttributeFilterContext filterContext)
        Fill in the filter context data.

        This is a very minimally populated context with nothing much set except possibly issuer, based on the AuthenticationAuthorities data.

        Parameters:
        filterContext - context to populate