All Classes Interface Summary Class Summary Enum Summary Exception Summary
| Class |
Description |
| AbstractAttributeDefinition |
Base class for attribute definition resolver plugins.
|
| AbstractAttributeDisplayFunction |
Abstract Function which returns Locale-aware information about an attribute.
|
| AbstractAttributePredicate |
|
| AbstractAttributeReleaseAction |
Base class for attribute release consent actions.
|
| AbstractAttributeResolutionLookupFunction<Type> |
|
| AbstractAttributeTranscoder<T> |
Base class for transcoders.
|
| AbstractAuditingValidationAction |
Base class for validation actions that includes new audit logging support.
|
| AbstractAuthenticationAction |
A base class for authentication related actions.
|
| AbstractBasicCredentialFactoryBean |
|
| AbstractBasicCredentialFactoryBean.SecretKeyEncoding |
Form of encoding for SecretKey info.
|
| AbstractBasicCredentialParser |
Specific parser for all BasicCredentials.
|
| AbstractBasicPKIXValidationInfoFactoryBean |
|
| AbstractCASAttributeTranscoder<EncodedType extends IdPAttributeValue> |
Base class for transcoders that support CAS attributes.
|
| AbstractCASAttributeTranscoder.NamingFunction |
A function to produce a "canonical" name for a CAS Attribute for transcoding rules.
|
| AbstractCASProtocolAction<RequestType,ResponseType> |
Base class for CAS protocol actions.
|
| AbstractChainingParser |
Base Parser for trust engines of type SignatureChaining and Chaining.
|
| AbstractCollectionConfigurationLookupStrategy<T1,T2> |
A strategy function that examines SAML metadata associated with a relying party and derives List<String>-valued
configuration settings based on EntityAttribute extension tags.
|
| AbstractCommandLineArguments |
Base class for JCommander command line argument handling for an HTTP-based remote service call,
with an abstract method that adds to a URL based on a derived class' arguments.
|
| AbstractComposedMatcher |
Base class for Matcher implementations that are compositions of two or more other
Matchers.
|
| AbstractComposedPolicyRule |
|
| AbstractConditionalProfileConfiguration |
|
| AbstractConsentAction |
Base class for consent actions.
|
| AbstractConsentIndexedStorageAction |
|
| AbstractConsentStorageAction |
|
| AbstractCredentialFactoryBean<T extends Credential> |
|
| AbstractCredentialParser |
Base parser for all <Credential> elements.
|
| AbstractCredentialValidator |
|
| AbstractDataConnector |
Base class for data connector resolver plugins.
|
| AbstractDataConnectorParser |
Base spring bean definition parser for data connectors.
|
| AbstractDuoAuthenticator |
A base class for authentication actions which call a Duo AuthAPI endpont.
|
| AbstractDynamicHTTPMetadataProviderParser |
Parser for abstract dynamic HTTP metadata resolvers.
|
| AbstractDynamicMetadataProviderParser |
|
| AbstractEntityAttributeExactPolicyRule |
Matcher that checks, via an exact match, for an entity attribute with a given value.
|
| AbstractEntityAttributeExactRuleParser |
Parser for EntityAttributeExactPolicyRule types.
|
| AbstractEntityAttributePolicyRule |
Base class for matchers that check whether a particular entity attribute is present and contains a given value.
|
| AbstractEntityAttributeRegexPolicyRule |
Matcher functor that checks entity attribute values via matching against a regular expression.
|
| AbstractEntityAttributeRegexRuleParser |
Parser for EntityAttributeRegexPolicyRule types.
|
| AbstractEntityAttributeRuleParser |
Base definition for all EntityAttribute Parsers.
|
| AbstractEntityGroupPolicyRule |
A matcher that evaluates to true if an entity's metadata matches the provided entity group name,
or a valid metadata-sourced affiliation of entities.
|
| AbstractEntityGroupRuleParser |
Parser for entity group policy rules.
|
| AbstractExecutableSearchFilterBuilder |
Abstract executable search filter builder for implementations that can provide a search filter.
|
| AbstractExecutableStatementBuilder |
Basis of statement builder.
|
| AbstractExtractionAction |
A base class for authentication actions that extract usernames for subsequent use.
|
| AbstractHTTPSearchBuilder |
Basis of request builder.
|
| AbstractIdPHomeAwareCommandLine<T extends AbstractIdPHomeAwareCommandLineArguments> |
An extension to AbstractCommandLine that auto-adds our context initializer for idp.home
and property support.
|
| AbstractIdPHomeAwareCommandLineArguments |
|
| AbstractIdPModule |
IdPModule base class implementing basic file management.
|
| AbstractIdPPlugin |
A base class implementing IdPPlugin that defaults common settings.
|
| AbstractIdPSession |
Abstract base for implementations of IdPSession, handles basic management of the
instance data without addressing persistence.
|
| AbstractIdPSession.AddressFamily |
Address syntaxes supported for address binding.
|
| AbstractMappingStrategy<T> |
Base class for implementing MappingStrategy instances that includes
support for field renaming/aliasing.
|
| AbstractMatcher |
This is the base of all implementations of Matcher which do some sort of comparison.
|
| AbstractMatchesShibMDScopeMatcher |
Base class for filters which rely on the issuer's <shibmd:scope> extensions.
|
| AbstractMetadataDrivenConfigurationLookupStrategy<T> |
A strategy function that examines SAML metadata associated with a relying party and derives configuration
settings based on EntityAttribute extension tags.
|
| AbstractMetadataDrivenConfigurationLookupStrategy.CachedConfigurationContext |
A child context that caches derived configuration properties.
|
| AbstractMetadataProviderParser |
Parser for the MetadataProviderType in the urn:mace:shibboleth:2.0:metadata namespace.
|
| AbstractNameIDFormatExactPolicyRule |
Checks if the attribute issuer supports the required NameID format.
|
| AbstractNameIDFormatRuleParser |
Parser for NameIDFormat rules.
|
| AbstractOutgoingSamlMessageAction |
Base class for all actions that build SAML Response messages for output.
|
| AbstractPKIXValidationInfoParser |
Base parser for all <ValidationInfo> types.
|
| AbstractPolicyRule |
|
| AbstractPrincipalSerializer<Type> |
|
| AbstractProfileAction |
Base class for Spring-aware profile actions.
|
| AbstractProfileConfiguration |
|
| AbstractProfileInterceptorAction |
A base class for profile interceptor actions.
|
| AbstractProfileInterceptorResult |
Base class for profile interceptor results.
|
| AbstractProtocolConfiguration |
Base class for CAS protocol configuration.
|
| AbstractProtocolResponse |
Abstract base class for protocol response messages.
|
| AbstractProxyRestrictionAuditExtractor<T> |
|
| AbstractRegexMatcherParser |
Base class for regex matching functors of natural type Matcher (mostly attribute value matchers).
|
| AbstractRegexPolicyRuleParser |
Base class for regex matching functors of natural type PolicyRule.
|
| AbstractRegexpPolicyRule |
General Matcher for regexp comparison of strings in Attribute Filters.
|
| AbstractRegexpStringMatcher |
General Matcher for regexp comparison of strings in Attribute
Filters.
|
| AbstractRegistrationAuthorityPolicyRule |
Base class for rules operating on the RPI extension in metadata.
|
| AbstractRegistrationAuthorityRuleParser |
Spring bean definition parser that creates RegistrationAuthorityPolicyRule beans.
|
| AbstractReloadingMetadataProviderParser |
Parser for all types which extend the <ReloadingMetadataProviderType>.
|
| AbstractRelyingPartyLookupFunction<ResultType> |
|
| AbstractRelyingPartyLookupFunction<ResultType> |
|
| AbstractRelyingPartyPredicate |
|
| AbstractRelyingPartyPredicate |
|
| AbstractResolverPlugin<ResolvedType> |
|
| AbstractResolverPluginFactoryBean<T extends AbstractResolverPlugin<?>> |
|
| AbstractSAML1ArtifactAwareProfileConfiguration |
Configuration support for artifact-aware profiles.
|
| AbstractSAML1AttributeTranscoder<EncodedType extends IdPAttributeValue> |
|
| AbstractSAML1AttributeTranscoder.NamingFunction |
A function to produce a "canonical" name for a SAML 1 AttributeDesignator for transcoding rules.
|
| AbstractSAML2ArtifactAwareProfileConfiguration |
Configuration support for artifact-aware profiles.
|
| AbstractSAML2AttributeTranscoder<EncodedType extends IdPAttributeValue> |
|
| AbstractSAML2AttributeTranscoder.NamingFunction |
A function to produce a "canonical" name for a SAML 2.0 Attribute for transcoding rules.
|
| AbstractSAML2ProfileConfiguration |
Base class for SAML 2 profile configurations.
|
| AbstractSAMLAttributeTranscoder<AttributeType extends SAMLObject,EncodedType extends IdPAttributeValue> |
Base class for transcoders that support SAML attributes.
|
| AbstractSAMLProfileConfiguration |
Base class for SAML profile configurations.
|
| AbstractScopingAuditExtractor<T> |
|
| AbstractSearchDataConnector<T1 extends ExecutableSearch,T2 extends MappingStrategy<?>> |
A DataConnector containing functionality common to data connectors that
retrieve attribute data by searching a data source.
|
| AbstractSPSessionSerializer |
Base class for SPSession serializers that handles data common to all such objects.
|
| AbstractStaticPKIXParser |
Base Parser for trust engines of type StaticPKIXKeySignature and StaticPKIXX509Credential.
|
| AbstractStaticPKIXParser.X509CredentialNameEvaluatorFactoryBean |
|
| AbstractStringMatcher |
General Matcher for String comparison of strings in Attribute Filters.
|
| AbstractStringMatcherParser |
Base class for string matching functors of natural type Matcher (mostly attribute value matchers).
|
| AbstractStringPolicyRule |
|
| AbstractStringPolicyRuleParser |
Base class for string matching functors of natural type PolicyRule.
|
| AbstractSubjectCanonicalizationAction |
A base class for subject canonicalization actions.
|
| AbstractTemplateSearchDnResolver |
Base class for Template based search dn resolvers.
|
| AbstractTemplateSearchDnResolver.EscapingReferenceInsertionEventHandler |
Escapes LDAP attribute values added to the template context.
|
| AbstractTicketSerializer<T extends Ticket> |
Base class for ticket serializers that use a simple field-delimited serialization strategy.
|
| AbstractTicketService |
Abstract base class for ticket services that rely on StorageService for ticket storage.
|
| AbstractTrustEngineParser |
Basis of all parsers for <security:TrustEngine>.
|
| AbstractUsernamePasswordCredentialValidator |
|
| AbstractValidationAction |
A base class for authentication related actions that validate credentials and produce an
AuthenticationResult.
|
| AbstractX509CredentialFactoryBean |
|
| AbstractX509CredentialParser |
Specific parser for all X509Credentials.
|
| AccountLockoutManager |
A component that manages lockout state for accounts.
|
| ACSUIInfo |
|
| ActionSupport |
Helper class for Action operations.
|
| AddAttributeStatementToAssertion |
|
| AddAttributeStatementToAssertion |
|
| AddAuthenticationStatementToAssertion |
|
| AddAuthnRequest |
|
| AddAuthnStatementToAssertion |
|
| AddAuthnStatementToAssertionFromInboundAssertionToken |
|
| AddDelegationPolicyToAssertion |
|
| AddDelegationRestrictionToAssertions |
|
| AddFrameworkHandler |
Handler implementation that adds a Liberty sbf:Framework header to the outbound SOAP envelope.
|
| AdditionalAudiencesForAssertionLookupFunction |
|
| AddLogoutRequest |
|
| AddSenderHandler |
Handler implementation that adds a Liberty sb:Sender header to the outbound SOAP envelope.
|
| AddSenderHandler.SAMLSelfEntityIDLookupFunction |
Function to return the SAML self entityID from the MessageContext.
|
| AdministrativeFlowDescriptor |
A descriptor for an administrative flow.
|
| AdministrativeFlowDescriptorManager |
|
| AlgorithmFilterParser |
Parser for Algorithm filter.
|
| AllowedSAMLPresentersPredicate |
|
| AndMatcher |
Matcher that implements the conjunction of matchers.
|
| AndMatcherParser |
|
| AndPolicyRule |
|
| AnyParser |
|
| ArtifactResolutionProfileConfiguration |
Configuration support for SAML 1 artifact resolution requests.
|
| ArtifactResolutionProfileConfiguration |
Configuration support for SAML 2 artifact resolution requests.
|
| AssertionIDAuditExtractor |
Function that returns the ID attribute from the assertions in a response.
|
| AssertionInstantAuditExtractor |
Function that returns the IssueInstant attribute from the assertions in a response.
|
| AssertionLifetimeLookupFunction |
|
| AttemptedAuthenticationFlowAuditExtractor |
Function that returns the latest attempted authentication flow ID.
|
| AttemptedUsernameAuditExtractor |
|
| Attribute |
Wrapper class for a CAS attribute/values construct in a validate response.
|
| AttributeContext |
|
| AttributeDecodingException |
Indicates a problem during decoding into an attribute.
|
| AttributeDefinition |
Definition of attribute definition resolver plugins.
|
| AttributeDisplayDescriptionFunction |
Function which returns the locale-aware display description of an attribute, defaulting to the
attribute ID if the attribute has no display description.
|
| AttributeDisplayNameFunction |
Function which returns the locale-aware display name of an attribute, defaulting to the
attribute ID if the attribute has no display name.
|
| AttributeEncodingException |
Indicates a problem during the encoding of an attribute.
|
| AttributeException |
Base class for attribute related exceptions.
|
| AttributeFilter |
Interface that filters out attributes and values based upon loaded policies.
|
| AttributeFilterContext |
|
| AttributeFilterContext.Direction |
Used to indicate the "direction" of filtering relative to the IdP.
|
| AttributeFilterException |
Indicates that an error has occurred during an attribute filtering process.
|
| AttributeFilterImpl |
Service that filters out attributes and values based upon loaded policies.
|
| AttributeFilterNamespaceHandler |
Namespace handler for the attribute filtering engine.
|
| AttributeFilterPolicy |
A policy describing if a set of attribute value filters is applicable.
|
| AttributeFilterPolicyGroupParser |
Bean definition parser for <afp:AttributeFilterPolicyGroup>, top top level of the filter "stack".
|
| AttributeFilterPolicyParser |
|
| AttributeFilterServiceStrategy |
|
| AttributeFilterWorkContext |
A context which carries and collects information through the attribute filtering process, and coordinates data
between the filter implementation and the various resolver MatchFunctor implementations.
|
| AttributeInMetadataMatcher |
Matcher that checks whether an attribute is enumerated in an SP's metadata as a required or optional attribute.
|
| AttributeInMetadataRuleParser |
|
| AttributeIssuerIdLookupFunction |
|
| AttributeIssuerIdPredicate |
Predicate that evaluates a ProfileRequestContext by looking for an attribute issuer
that matches one of a designated set or a generic predicate.
|
| AttributeIssuerPolicyRule |
Compare the attribute issuer's entity ID for this resolution with the provided name.
|
| AttributeIssuerRegexpPolicyRule |
Compare the attribute issuer's entity ID for this resolution with the provided regexp.
|
| AttributeIssuerRegexRuleParser |
|
| AttributeIssuerRuleParser |
|
| AttributeMappingNodeProcessor |
|
| AttributePredicate |
Predicate to determine whether consent should be obtained for an attribute.
|
| AttributePrincipalLookupFunction |
|
| AttributePrincipalPredicate |
Predicate that evaluates a ProfileRequestContext by looking for an attribute subject
that matches one of a designated set or a generic predicate.
|
| AttributeQueryProfileConfiguration |
Configuration support for SAML 1 attribute query requests.
|
| AttributeQueryProfileConfiguration |
Configuration support for SAML 2 attribute query requests.
|
| AttributeRecipientIdLookupFunction |
|
| AttributeRecipientIdPredicate |
Predicate that evaluates a ProfileRequestContext by looking for an attribute recipient
that matches one of a designated set.
|
| AttributeRegistryServiceStrategy |
|
| AttributeReleaseConsentFunction |
Function that returns a map of consent objects representing consent to attribute release.
|
| AttributeReleaseContext |
Context for attribute release consent.
|
| AttributeReleaseFlowDescriptor |
Descriptor for an attribute release flow.
|
| AttributeRequesterPolicyRule |
Compare the attribute requester's entity ID for this resolution with the provided name.
|
| AttributeRequesterRegexpPolicyRule |
Compare the attribute requester's entity ID for this resolution with the provided regexp.
|
| AttributeRequesterRegexRuleParser |
|
| AttributeRequesterRuleParser |
|
| AttributeResolutionContext |
|
| AttributeResolver |
A component that resolves the attributes for a particular subject.
|
| AttributeResolverImpl |
A component that resolves the attributes for a particular subject.
|
| AttributeResolverNamespaceHandler |
Namespace handler for the attribute resolver.
|
| AttributeResolverParser |
|
| AttributeResolverServiceGaugeSet |
Additional gauges for attribute resolver.
|
| AttributeResolverServiceStrategy |
|
| AttributeResolverWorkContext |
A context which carries and collects information through the attribute resolution process, and coordinates data
between the resolver implementation and the various resolver plugin implementations.
|
| AttributeResolvingProfileConfiguration |
|
| AttributeRevocationCondition |
A condition for login flows that checks for revocation against a resolved
IdPAttribute.
|
| AttributeRule |
Represents a value filtering rule for a particular attribute.
|
| AttributeRuleParser |
|
| AttributesAuditExtractor |
|
| AttributeScopeMatcherParser |
|
| AttributeScopeMatchesShibMDScope |
Class to implement a filter of scopes against <shibmd:scope>.
|
| AttributeScopeRegexMatcherParser |
|
| AttributeScopeRegexpMatcher |
|
| AttributeScopeStringMatcher |
|
| AttributesMapContainer |
Container for decoded attributes.
|
| AttributeSourcedSAML1NameIdentifierGenerator |
|
| AttributeSourcedSAML2NameIDGenerator |
|
| AttributeSourcedSubjectCanonicalization |
|
| AttributeTranscoder<T> |
Transcoders are objects that support both attribute encoding and decoding for bidirectional
translation between IdPAttribute format and technology-specific formats.
|
| AttributeTranscoderRegistry |
The transcoder registry provides access to "instructions" for converting between
the IdPAttribute "neutral" representation within the IdP and protocol-specific
forms such as SAML Attributes or OIDC claims.
|
| AttributeTranscoderRegistry.NamingFunction<T> |
Interface to a naming function that allows an object to be turned into a unique string name.
|
| AttributeTranscoderRegistryImpl |
|
| AttributeValueLookupFunction |
|
| AttributeValueMatchesShibMDScope |
Class to implement a filter of string values against <shibmd:scope>.
|
| AttributeValueRegexMatcherParser |
|
| AttributeValueRegexpMatcher |
|
| AttributeValuesHashFunction |
Function to calculate the hash of the values of an IdP attribute.
|
| AttributeValueStringMatcher |
|
| AttributeValueStringMatcherParser |
|
| AudienceRestrictionsLookupFunction |
|
| AuditContext |
BaseContext containing information to preserve for auditing/logging.
|
| AuthenticationContext |
A context representing the state of an authentication attempt, this is the primary
input/output context for the action flow responsible for authentication, and
within that flow, the individual flows that carry out a specific kind of
authentication.
|
| AuthenticationErrorAuditExtractor |
|
| AuthenticationErrorContext |
A context that holds information about authentication failures.
|
| AuthenticationFlowAuditExtractor |
Function that returns the authentication flow ID used to satisfy a request.
|
| AuthenticationFlowDescriptor |
A descriptor for an authentication flow.
|
| AuthenticationFlowDescriptorManager |
|
| AuthenticationFlowsLookupFunction |
|
| AuthenticationMethodPrincipal |
Principal based on a SAML 1.x AuthenticationMethod.
|
| AuthenticationProfileConfiguration |
Configuration of profiles for authentication.
|
| AuthenticationResult |
Describes an act of authentication.
|
| AuthenticationResultPrincipal |
|
| AuthenticationResultPrincipalSerializer |
|
| AuthenticationWarningContext |
A context that holds information about authentication warnings.
|
| AuthnAuditFields |
Constants to use for audit logging fields stored in an AuditContext.
|
| AuthnContextAuditExtractor |
Function that returns the first AuthenticationMethod, AuthnContextCLassRef,
or AuthnContextDeclRef from an assertions in a response.
|
| AuthnContextClassRefPrincipal |
Principal based on a SAML AuthnContextClassRef.
|
| AuthnContextDeclPrincipal |
Principal based on a SAML AuthnContextDecl.
|
| AuthnContextDeclRefPrincipal |
Principal based on a SAML AuthnContextDeclRef.
|
| AuthnEventIds |
|
| AuthnInstantAuditExtractor |
Function that returns the first authentication timestamp from an assertions in a response.
|
| BaseAddAttributeStatementToAssertion<T extends SAMLObject> |
Base class for actions that encode an AttributeContext into a SAML attribute statement.
|
| BaseAddAuthenticationStatementToAssertion |
Base class for actions that encode authentication information into a SAML 1 or SAML 2 statement.
|
| BaseAttributeDefinitionParser |
Base spring bean definition parser for attribute definitions.
|
| BaseAttributeEncoderParser |
Base class for Spring bean definition parser for attribute encoders.
|
| BaseAttributeValueMatcherParser |
Base function for all Attribute Value matchers.
|
| BaseBridgingClass |
|
| BaseCryptoTransientDecoder |
An abstract action which contains the logic to do crypto transient decoding matching.
|
| BaseCSRFTokenPredicate |
A base helper class for predicates that determine if CSRF protection is required per state.
|
| BaseFilterParser |
Base class for Spring bean definition parsers within the filter engine configuration.
|
| BaseIdPInitiatedSSORequestMessageDecoder |
Decodes an incoming Shibboleth Authentication Request message.
|
| BasePolicyRuleParser |
Base function for all natural policy rules.
|
| BaseResolverPluginDependencyParser |
|
| BaseResolverPluginParser |
|
| BaseSAML1AttributeEncoderParser |
Base class for Spring bean definition parser for SAML 1 attribute encoders.
|
| BaseSAML2AttributeEncoderParser |
Base class for Spring bean definition parser for SAML 1 attribute encoders.
|
| BaseTransformingDecoder |
Regular expression, etc.
|
| BaseTransientDecoder |
An abstract action which contains the logic to do transient decoding matching (shared between SAML2 and SAML1).
|
| BasicAdministrativeFlowDescriptor |
A descriptor for an administrative flow.
|
| BasicAdministrativeFlowDescriptor.Logo |
A wrapper class to construct logo objects for exposure by UIInfo interface.
|
| BasicAttribute |
A class which is here solely to provide compatibility for V2 scripted attribute definitions.
|
| BasicDuoIntegration |
Wrapper for use of Duo.
|
| BasicInlineCredentialFactoryBean |
Factory bean for BasicInline Credentials.
|
| BasicInlineCredentialParser |
Parser for BasicInline Credentials.
|
| BasicKeystoreKeyStrategyTask |
|
| BasicNamingFunction<T> |
|
| BasicResourceCredentialFactoryBean |
|
| BasicResourceCredentialParser |
Parser for BasicFilesystem and BasicResourceBacked Credentials.
|
| BasicSAMLArtifactConfiguration |
Interface for outbound SAML artifact configuration.
|
| BasicSPSession |
Implementation support for a concrete SPSession implementation.
|
| BasicSPSessionCreationStrategy |
A function to create a BasicSPSession based on profile execution state.
|
| BasicSPSessionSerializer |
|
| BasicX509CredentialFactoryBean |
|
| BeanConfigurationLookupStrategy<T> |
A strategy function that examines SAML metadata associated with a relying party and derives bean-based
configuration settings based on EntityAttribute extension tags.
|
| BestMatchLocationLookupStrategy |
|
| BindingDescriptor |
Subclass that adds awareness of a Spring bean ID for a binding's
MessageEncoder.
|
| BooleanConfigurationLookupStrategy |
A strategy function that examines SAML metadata associated with a relying party and derives Boolean-valued
configuration settings based on EntityAttribute extension tags.
|
| BrowserSSOProfileConfiguration |
Configuration for SAML 1 Browser SSO profile requests.
|
| BrowserSSOProfileConfiguration |
Configuration support for SAML 2 Browser SSO.
|
| BuildAuthenticationContextAction |
|
| BuildProxyChainAction |
Action that builds the chain of visited proxies for a successful proxy ticket validation event.
|
| BuildRelyingPartyContextAction<RequestType,ResponseType> |
|
| BuildSAMLMetadataContextAction<RequestType,ResponseType> |
|
| BuildSamlValidationFailureMessageAction |
Creates the SAML response message for failed ticket validation at the /samlValidate URI.
|
| BuildSamlValidationSuccessMessageAction |
Creates the SAML response message for successful ticket validation at the /samlValidate URI.
|
| BuildWar |
Code to build the war file during an install or on request.
|
| ByReferenceFilterBeanPostProcessor |
|
| ByReferenceMetadataFilterBridge |
|
| ByReferenceParser |
Parser for a <ByReference> filter.
|
| ByteAttributeValue |
|
| CacheConfigParser |
Utility class for parsing v2 cache configuration.
|
| CanonicalUsernameLookupStrategy |
|
| CAS |
|
| CASAttributeTranscoder |
Marker interface for transcoders that support CAS attributes.
|
| CASAuditFields |
Constants to use for audit logging fields stored in an AuditContext.
|
| CASDateTimeAttributeTranscoder |
|
| CASScopedStringAttributeTranscoder |
|
| CASSPSession |
Describes a CAS protocol-specific service provider session created in response to a successful ticket validation.
|
| CASSPSessionSerializer |
|
| CASStringAttributeTranscoder |
|
| CertificateContext |
|
| CertificateIssuerAuditExtractor |
Function that returns the issuer of a client certificate.
|
| CertificateSubjectAuditExtractor |
Function that returns the subject of a client certificate.
|
| CertPathPKIXValidationOptionsParser |
Spring bean definition parser for {urn:mace:shibboleth:2.0:security}ValidationOptions elements which have a type
specialization of {urn:mace:shibboleth:2.0:security}CertPathValidationOptionsType.
|
| ChainingMetadataProviderParser |
Parser for <ChainingMetadataProvider>.
|
| ChainingParser |
Parser for trust engines of type SignatureChaining.
|
| ChainingSignatureTrustEngineFactory |
|
| ChainingTrustEngineFactory |
|
| CheckAddressPredicate |
|
| CheckProxyAuthorizationAction<RequestType,ResponseType> |
Checks the current ServiceContext to determine whether the service/relying party is authorized to proxy.
|
| CLI |
Entry point for command line attribute utility.
|
| ClientTLSArtifactRequestsPredicate |
|
| ClientTLSSOAPLogoutRequestsPredicate |
|
| ClientTLSValidationConfigurationLookupFunction |
|
| CloneablePrincipal |
Principal that can be cloned without knowledge of the underlying type.
|
| CollectionSerializer |
|
| CommandLineArguments |
Interface for JCommander command line argument handling for an HTTP-based remote service call.
|
| ComputedIdDataConnectorParser |
Spring bean definition parser for configuring ComputedIdDataConnector.
|
| ComputedPairwiseIdStore |
A PairwiseIdStore that generates a pairwise ID by computing the hash of
a given attribute value, the entity ID of the recipient, and a salt.
|
| ComputedPairwiseIdStore.Encoding |
Post-digest encoding types.
|
| ConditionalProfileConfiguration |
|
| ConfigLookupFunction<T extends AbstractProtocolConfiguration> |
Lookup function for extracting CAS profile configuration from the profile request context.
|
| ConnectionFactoryValidator |
Validator implementation that invokes Connection.open() to determine if the ConnectionFactory is properly
configured.
|
| Consent |
Represents consent.
|
| Consent |
|
| ConsentAuditFields |
|
| ConsentContext |
Context representing the state of a consent flow.
|
| ConsentFlowDescriptor |
Descriptor for a consent flow.
|
| ConsentManagementContext |
Context representing signals to consent flows for managing their state.
|
| ConsentResult |
The result of a consent flow, suitable for storage.
|
| ConsentSerializer |
|
| ContextCheck |
|
| ContextDerivedAttributeDefinition |
An attribute definition which returns an attribute whose values are derived from the
ProfileRequestContext associated with the request via a plugged in Function.
|
| ContextDerivedAttributeDefinitionParser |
Spring Bean Definition Parser for attribute definitions derived from the Principal.
|
| ContinueSAMLAuthentication |
|
| CopyDistribution |
Copy the distribution to the final location.
|
| CoreGaugeSet |
A set of gauges for core system information.
|
| CoreIdPModule |
Implementation base class for IdPModule that lives within the core code
and whose documentation URLs will float with the IdP's own.
|
| CounterStorageKeyComparator |
A Comparator used to order storage keys so that the least used and oldest storage keys are returned first.
|
| CounterStorageKeyFunction |
Function to order storage keys by least-used and oldest first during pruning of storage records.
|
| CreateGlobalConsentResult |
Consent action to create a consent result representing global consent to be stored in a storage service.
|
| CreateResult |
Consent action to create a consent result representing the result of a consent flow.
|
| CredentialConfigFactoryBean |
A Factory bean to summon up CredentialConfig from supplied <Credential> statements.
|
| CredentialValidator |
High-level API for validating credentials and producing a Java Subject as a result.
|
| CredentialValidator.ErrorHandler |
Interface to use to report errors to the caller.
|
| CredentialValidator.WarningHandler |
Interface to use to report warnings to the caller.
|
| CriteriaRelyingPartyConfigurationResolver |
|
| CriteriaSelfEntityIDResolver |
|
| CryptoTransientIdGenerationStrategy |
Generates transients using a DataSealer to encrypt the result into a recoverable value,
for use with stateless clustering.
|
| CryptoTransientNameIDDecoder |
|
| CryptoTransientNameIdentifierDecoder |
|
| CSRFToken |
An anti cross-site request forgery token.
|
| CSRFTokenFlowExecutionListener |
A flow execution lifecycle listener that, if enabled:
Sets an anti-CSRF token into the view-scope map on rendering of a suitable view-state
Checks the CSRF token in a HTTP request matches that stored in the view-scope map when a suitable
view-state event occurs.
|
| CSRFTokenManager |
A thread-safe helper class for dealing with cross-site request forgery tokens.
|
| CSRFTokenManager.DefaultCSRFTokenValidationPredicate |
A simple default CSRF token validation predicate.
|
| CurrentConsentIdsAuditExtractor |
|
| CurrentConsentIsApprovedAuditExtractor |
|
| CurrentConsentValuesAuditExtractor |
|
| CurrentInstallState |
Tells the installers about the current install state.
|
| CurrentInstallStateImpl |
Tells the installers about the current install state.
|
| DataConnector |
Base class for data connector resolver plugins.
|
| DataConnectorFactoryBean |
|
| DataSealerArguments |
Arguments for DataSealer CLI.
|
| DataSealerArguments.OperationType |
Operation enum.
|
| DataSealerCLI |
|
| DataSourceValidator |
|
| DateAttributePredicate |
Provides a date/time matching predicate that compares a date-based attribute value against
current system time with optional offset.
|
| DateTimeAttributeDefinition |
|
| DateTimeAttributeDefinitionParser |
|
| DateTimeAttributeValue |
Base class for IdPAttribute values that are date/time values.
|
| DecorateDelegatedAssertion |
A profile action which decorates instances of Assertion appropriately for use as delegation tokens.
|
| DecorateDelegatedAssertion.LibertySSOSEndpointURLStrategy |
Strategy that builds the SSOS endpoint URL based on the current HTTP request
using default values for scheme, port and URI path suffix.
|
| DecryptedAttributeDefinition |
An AttributeDefinition that creates an attribute whose values are the
decrypted values of its dependencies.
|
| DecryptedAttributeDefinitionParser |
|
| DecryptionConfigurationLookupFunction |
|
| DefaultAuthenticationResultSerializer |
|
| DefaultEventRequiresCSRFTokenValidationPredicate |
Default BiPredicate for determining if CSRF token validation should occur
from a compatible request context and event.
|
| DefaultNameIdentifierFormatStrategy |
Function to filter a set of candidate NameIdentifier/NameID Format values derived from an entity's SAML metadata
against configuration preferences.
|
| DefaultPrincipalDeterminationStrategy<T extends Principal> |
Deprecated, for removal: This API element is subject to removal in a future version. |
| DefaultRelyingPartyConfigurationResolver |
Retrieves a per-relying party configuration for a given profile request based on the request context.
|
| DefaultServiceComparator |
Default comparator implementation for comparing CAS service URLs.
|
| DefaultServiceComparator |
Deprecated, for removal: This API element is subject to removal in a future version. |
| DefaultViewRequiresCSRFTokenPredicate |
Default Predicate for determining if a CSRF token is required for the given
request context.
|
| DelegatedAssertionLookupStrategy |
Lookup function to return the valid delegated assertion token in effect for the Liberty SSOS request.
|
| DelegatingCriteriaRelyingPartyConfigurationResolver |
|
| DelegationContext |
Context which holds data relevant to the issuance of a delegated Assertion.
|
| DelegationPolicy |
SAMLObject for the Shibboleth DelegationPolicy extension supporting SAML delegation.
|
| DelegationPolicyBuilder |
|
| DelegationPolicyImpl |
|
| DelegationPolicyMarshaller |
|
| DelegationPolicyUnmarshaller |
|
| DelegationRequest |
Enum which represents the state of the relying party's indication of whether
a delegated assertion token is requested.
|
| Demo |
|
| DeprecatedEntityRoleFilterParser |
Deprecated, for removal: This API element is subject to removal in a future version. |
| DeprecatedPropertyBean |
A bean that emits deprecation warnings if a configurable set of properties are set.
|
| DestroySessions |
|
| DetailedErrorsPredicate |
Predicate to determine whether a relying party should see detailed error information.
|
| DetailedErrorsProfileConfigPredicate |
|
| DetectIdentitySwitch |
An authentication action that checks for a mismatch between an existing session's identity and
the result of a newly canonicalized subject (from a SubjectCanonicalizationContext).
|
| DirectionPolicyRule |
|
| DiscoveryProfileRequestFunction |
A Function that produces a discovery request URL using the protocol defined in
https://wiki.oasis-open.org/security/IdpDiscoSvcProtonProfile
|
| DoLockoutManagerOperation |
|
| DoRevocationCacheOperation |
|
| DoStorageOperation |
Action that implements a JSON REST API for accessing StorageService records.
|
| DoubleConfigurationLookupStrategy |
A strategy function that examines SAML metadata associated with a relying party and derives Double-valued
configuration settings based on EntityAttribute extension tags.
|
| Duo |
|
| DuoAuthAPI |
Constants defined in the Duo AuthAPI.
|
| DuoAuthAPIResponse |
Describes the results of a Duo AuthAPI call, intended for use with a jackson
ObjectMapper.
|
| DuoAuthAuthenticator |
Implementation of the the Duo AuthApi /v2/auth endpoint.
|
| DuoAuthenticationContext |
Context that carries Duo factor and device or passcode to be used in validation.
|
| DuoAuthResponse |
Describes the results of an authentication attempt via the Duo AuthAPI, intended for use with a jackson
ObjectMapper.
|
| DuoDevice |
Represents a Duo device, intended for use with a jackson
ObjectMapper.
|
| DuoFailureResponse |
Describes the failure of a Duo AuthAPI call.
|
| DuoIntegration |
Interface to a particular Duo integration point.
|
| DuoPreauthAuthenticator |
Implementation of the the Duo AuthAPI /v2/preauth endpoint.
|
| DuoPreauthResponse |
Describes the results of an pre-authentication attempt via the Duo AuthAPI.
|
| DuoPrincipal |
Principal based on a Duo authentication.
|
| DuoResponseWrapper<T extends DuoAuthAPIResponse> |
Handle a generic object returned from the response that will come from the Duo
AuthAPI.
|
| DuoSupport |
Helpers for DuoWeb and Duo AuthAPI operations.
|
| DurablePairwiseIdStore |
Extended PairwiseIdStore interface that supports reversal, mutation, and deactivation features
requiring durable storage.
|
| DurationConfigurationLookupStrategy |
A strategy function that examines SAML metadata associated with a relying party and derives Long-valued
configuration settings that are durations, based on EntityAttribute extension tags.
|
| DynamicAttributePredicate |
Predicate over an AttributeContext that derives the value(s) to match based
on one or more supplied Functions instead of static values.
|
| DynamicHTTPMetadataProviderParser |
|
| ECPProfileConfiguration |
Configuration support for SAML 2 ECP.
|
| EmptyAttributeValue |
|
| EmptyAttributeValue.EmptyType |
Types of empty values.
|
| EncodingTicketService |
Ticket service that uses two different strategies for ticket persistence:
Service tickets, proxy tickets, and root proxy-granting tickets are persisted by serializing
ticket data and encrypting it into the opaque part of the ticket ID using a DataSealer.
Chained proxy-granting tickets are persisted using a StorageService.
|
| EncryptionAlgorithmAuditExtractor |
Function that returns the data encryption algorithm used.
|
| EncryptionConfigurationLookupFunction |
|
| EncryptionCredentialsResolver |
Credential resolver whose purpose is to resolve configured IdP encryption credentials.
|
| EntitiesDescriptorNameParser |
Parser for a <EntitiesDescriptorName> node processor.
|
| EntityAttributesFilterParser |
Parser for a <EntityAttributes> filter.
|
| EntityRoleFilterParser |
Parser for a <EntityRolet> filter.
|
| EvaluateDelegationPolicy |
Action which implements policy controls to decide whether an SSO request based
on a delegated Assertion token is allowed to proceed.
|
| Events |
CAS protocol flow event identifiers.
|
| ExactPrincipalEvalPredicateFactory |
|
| ExecutableSearch |
Should be implemented by objects used to search for attributes, that uniquely identify those search results.
|
| ExecutableSearchBuilder<T extends ExecutableSearch> |
|
| ExecutableSearchFilter |
A search filter that can be executed against an LDAP to fetch results.
|
| ExecutableStatement |
A statement that can be executed against a database to fetch results.
|
| ExpiringPassword |
|
| ExtensionsConstants |
Constants used in XMLObject extensions.
|
| External |
|
| ExternalAuthentication |
Public interface supporting external authentication outside the webflow engine.
|
| ExternalAuthenticationContext |
A context representing the state of an externalized authentication attempt,
a case where authentication happens outside of a web flow.
|
| ExternalAuthenticationException |
Exception indicating a problem with the external authentication process.
|
| ExternalAuthenticationImpl |
Implementation of the ExternalAuthentication API that handles moving information in and out
of request attributes.
|
| ExternalInterceptor |
Public interface supporting external interceptor flows outside the webflow engine.
|
| ExternalInterceptorContext |
A context representing the state of an externalized interceptor flow.
|
| ExternalInterceptorException |
Exception indicating a problem with the external interceptor process.
|
| ExternalInterceptorImpl |
Implementation of the ExternalInterceptor API that handles moving information in and out
of request attributes.
|
| ExtractActiveAuthenticationResults |
|
| ExtractConsent |
Consent action which extracts user input and updates current consent objects in the consent context accordingly.
|
| ExtractDiscoveryResponse |
|
| ExtractDuoAuthenticationFromHeaders |
|
| ExtractKerberosTicketFromWSSToken |
TODO.
|
| ExtractRemoteUser |
|
| ExtractSubjectFromRequest |
|
| ExtractSubjectFromRequest.SubjectNameLookupFunction |
Lookup function that returns the NameIdentifier or NameID from the request in the inbound
message context.
|
| ExtractUserAgentAddress |
|
| ExtractUserAgentIdentifier |
|
| ExtractUsernamePasswordFromBasicAuth |
|
| ExtractUsernamePasswordFromFormRequest |
|
| ExtractUsernamePasswordFromWSSToken |
An authentication stage that extracts a username/password from the WSS Username/Password attached to a SOAP message.
|
| ExtractX509CertificateFromRequest |
|
| FileBackedHTTPMetadataProviderParser |
Parser for a <FileBackedHTTPMetadataProvider>.
|
| FileCachingHttpClientFactoryBean |
Factory bean customization for the Shibboleth IdP.
|
| FileCachingHttpClientFactoryBean |
Deprecated, for removal: This API element is subject to removal in a future version. |
| FilesystemMetadataProviderParser |
Parser for a <FilesystemMetadataProvider>.
|
| FilterAttributes |
|
| FilterByQueriedAttributeDesignators |
|
| FilterByQueriedAttributes |
|
| FilterFlowsByForcedAuthn |
An authentication action that filters out potential authentication flows if the request requires
forced authentication or max age behavior and the flows don't support forced authentication.
|
| FilterFlowsByNonBrowserSupport |
An authentication action that filters out potential authentication flows if the request requires
non-browser support and the flows require a browser.
|
| FilterFlowsByNonBrowserSupport |
A profile interceptor action that filters out available interceptor flows if the request requires non-browser support
and the flows require a browser.
|
| FinalizeAuthentication |
An authentication action that runs after a completed authentication flow (or the reuse
of an active result) and transfers information from other contexts into a SubjectContext
child of the ProfileRequestContext.
|
| FinalizeMultiFactorAuthentication |
|
| FinalizeMultiFactorAuthentication.DefaultResultMergingStrategy |
|
| FinalizeSAMLSubjectCanonicalization |
|
| FinalizeSAMLTokenProcessing |
Post-process the results of Assertion token subject canonicalization.
|
| FirstPartyIdPPlugin |
Implementation class for plugins from the project itself to centralize
update handling.
|
| FlowDefinitionRegistryFactoryBean |
A bean factory for creating FlowDefinitionRegistry instances, based on the programmatic
builder built into SWF.
|
| FlowDefinitionRegistryFactoryBean.DefaultFlowRegistry |
Copied from SWF, a basic registry implementation.
|
| FlowDefinitionResourceFactory |
Derivation of SWF-supplied resource factory for flow definitions.
|
| FlowDescriptor |
Marker interface for a descriptor for a webflow allowing managed injection of configuration settings.
|
| FlowDescriptorLookupFunction<T extends ProfileInterceptorFlowDescriptor> |
Function that returns a profile interceptor flow descriptor from a profile request context using a lookup strategy.
|
| FlowIdLookupFunction |
|
| FlowModelFlowBuilder |
|
| FlowRelativeResourceLoader |
This code is extended from org.springframework.webflow.engine.builder.model.FlowRelativeResourceLoader
with modifications to support proper lookup of resources via both filesystem and classpath along with
custom protocol-specific loaders.
|
| ForceAuthnAuditExtractor |
|
| ForceAuthnProfileConfigPredicate |
|
| FormatExecutableStatementBuilder |
|
| FormatExecutableStatementBuilder |
Deprecated.
|
| Function |
|
| GatewayLookupFunction |
Looks up the value of the CAS gateway parameter from the request to the /login URI.
|
| GenericPrincipalSerializer |
Principal serializer for arbitrary principal types.
|
| GenericPrincipalService<T extends Principal> |
|
| GlobalAttributeConsentPredicate |
Predicate to determine whether global consent has been given by user.
|
| GrantProxyTicketAction |
Generates and stores a CAS protocol proxy ticket.
|
| GrantServiceTicketAction |
Generates and stores a CAS protocol service ticket.
|
| GSSAcceptorLoginModule |
Kerberos login utility for the context acceptor, encapsulates a number of special options
used to create a security context for the GSS acceptor, usually based on a keytab file.
|
| GSSContextAcceptor |
Helper class that manages context establishment for the SPNEGO GSS-API mechanism.
|
| Hello |
|
| HOTPPrincipal |
Principal based on an HOTP authentication.
|
| HTPasswdCredentialValidator |
A password validator that authenticates against Apache htpasswd files.
|
| HttpClientFactoryBean |
Factory bean customization for the Shibboleth IdP.
|
| HttpClientFactoryBean |
Deprecated, for removal: This API element is subject to removal in a future version. |
| HttpClientProxyValidator |
Authenticates a CAS proxy callback endpoint using an HttpClient instance to establish
the connection and a TrustEngine to verify the TLS certificate presented by the remote peer.
|
| HttpClientSecurityConfigurationLookupFunction |
|
| HTTPDataConnector |
This class implements a DataConnector
that obtains data from an HTTP service.
|
| HTTPDataConnectorParser |
|
| HTTPDataConnectorParser.V2Parser |
Utility class for parsing v2 schema configuration.
|
| HTTPMetadataProviderParser |
Parser for a FilesystemMetadataProvider.
|
| HTTPMetadataProvidersParserSupport |
Helper class for Spring configuration of HTTP metadata providers.
|
| HTTPReporter |
A metrics reporter that runs at scheduled times and posts a JSON feed of metrics to a designated endpoint.
|
| HTTPResourceFactoryBean |
Factory bean for simple use cases that auto-configure PKIX or key pinning for
an HTTPResource.
|
| HTTPResponseMappingStrategy |
Strategy for processing an HttpClient response into a map of
IdPAttributes.
|
| HTTPSearch |
An HTTP request that returns attribute data.
|
| HttpServletRequestCriterion |
Criterion representing a session bound to a servlet request,
which is implicitly the "current" request known to the resolver.
|
| IdentifierGenerationStrategyLookupFunction |
|
| IdPAttribute |
Each attribute represents one piece of information about a user and has associated encoders used to turn that
information in to protocol-specific formats.
|
| IdPAttributePrincipal |
|
| IdPAttributePrincipalSerializer |
|
| IdPAttributePrincipalValuesFunction |
|
| IdPAttributeValue |
|
| IdPAuditFields |
Constants to use for audit logging fields stored in an AuditContext.
|
| IdPEventIds |
|
| IdPGaugeSet |
A set of gauges for core system information.
|
| IdPInitiatedSSORequest |
Object representing a Shibboleth Authentication Request message.
|
| IdPInitiatedSSORequestMessageDecoder |
Decodes an incoming Shibboleth Authentication Request message.
|
| IdPInitiatedSSORequestMessageDecoder |
Decodes an incoming Shibboleth Authentication Request message.
|
| IdPModule |
This interface is exported (via the service API) by every IdP module.
|
| IdPModule.ModuleResource |
Interface to a resource managed by the module.
|
| IdPModule.ResourceResult |
Resource management outcome.
|
| IdPPlugin |
This interface is exported (via the service API) by every IdP plugin.
|
| IdPPropertiesApplicationContextInitializer |
|
| IdPRequestedAttribute |
IdP Representation of the SAML2 RequestedAttribute.
|
| IdPSession |
An identity provider session belonging to a particular subject and client device.
|
| IdPUIInfo |
Class to contain a processed form of the UIInfo suitable for display purposes.
|
| IgnoreRequestSignaturesPredicate |
Predicate that decides whether to ignore a request signature.
|
| IgnoreScopingProfileConfigPredicate |
|
| Impersonate |
|
| InboundFlowsLookupFunction |
|
| InboundRuleParser |
|
| IncludeAttributeStatementPredicate |
A predicate that evaluates a SSO ProfileRequestContext and determines whether an attribute statement
should be included in the outgoing assertion.
|
| InexactPrincipalEvalPredicateFactory |
|
| InitializeAdministrativeProfileContextTree |
An action that processes settings from a supplied AdministrativeFlowDescriptor to prepare
the profile context tree for subsequent use by an administrative profile flow.
|
| InitializeAttributeReleaseContext |
|
| InitializeAuthenticationContext |
|
| InitializeConsentContext |
|
| InitializeLoginAction |
Initializes the CAS protocol interaction at the /login URI.
|
| InitializeOutboundMessageContext |
Action that adds an outbound MessageContext and related SAML contexts to the ProfileRequestContext
based on the identity of a relying party accessed via a lookup strategy, by default an immediate child of the profile
request context.
|
| InitializeOutboundMessageContextForError |
Action that prepares an outbound MessageContext and related SAML contexts
in the event that they are not already prepared, to allow error responses to be
generated in the case of synchronous bindings (i.e., SOAP).
|
| InitializeProfileRequestContext |
|
| InitializeProxyAction |
Initializes the CAS protocol interaction at the /proxy URI.
|
| InitializeProxyProfileRequestContext |
Action that creates a new ProfileRequestContext via a creation strategy,
and sets the profile and logging IDs, if provided.
|
| InitializeRelyingPartyContextFromSAMLPeer |
|
| InitializeRelyingPartyContextFromSAMLPeer |
|
| InitializeRequestedPrincipalContext |
|
| InitializeValidateAction |
Initializes the CAS protocol interaction at the /login URI.
|
| InlineMetadataProviderParser |
Parser for <InlineMetadataProvider>.
|
| InMemoryCachingHttpClientFactoryBean |
Deprecated, for removal: This API element is subject to removal in a future version. |
| InMemoryCachingHttpClientFactoryBean |
Factory bean customization for the Shibboleth IdP.
|
| InputAttributeDefinitionParser |
|
| InputDataConnectorParser |
|
| InResponseToAuditExtractor |
Function that returns the InResponseTo attribute from a response.
|
| InstallationLogger |
Shimmed logger.
|
| Installer |
Entry point to run the main classes.
|
| InstallerProperties |
Interface to describe simply parameterization and status of the installation.
|
| InstallerPropertiesImpl |
|
| InstallerSupport |
General common names and helper functions for the Installer.
|
| IntegerConfigurationLookupStrategy |
A strategy function that examines SAML metadata associated with a relying party and derives Integer-valued
configuration settings based on EntityAttribute extension tags.
|
| InvalidCSRFTokenException |
Exception indicating a problem validating a CSRF token at runtime.
|
| IPAddress |
|
| IPRangeBiPredicate |
|
| IsAttributeRequiredPredicate |
Predicate that determines whether an IdP attribute is required by the requester.
|
| IsConsentRequiredPredicate |
Predicate that returns whether consent is required by comparing the previous and current consents from the consent
context.
|
| IsPassiveAuditExtractor |
|
| IssuerEntityAttributeExactPolicyRule |
Matcher that checks, via an exact match, if the attribute issuer contains an entity attribute with a given value.
|
| IssuerEntityAttributeExactRuleParser |
|
| IssuerEntityAttributeRegexPolicyRule |
Matcher that checks, via regex, if the attribute issuer contains an entity attribute with a given value.
|
| IssuerEntityAttributeRegexRuleParser |
|
| IssuerInEntityGroupPolicyRule |
A matcher that evaluates to true if attribute issuer's metadata matches the provided entity group name,
or a valid metadata-sourced affiliation of entities.
|
| IssuerInEntityGroupRuleParser |
|
| IssuerNameIDFormatExactPolicyRule |
Checks if the attribute issuer supports the required NameID format.
|
| IssuerNameIDFormatRuleParser |
|
| IssuerRegistrationAuthorityPolicyRule |
Rule based on RPI extension in attribute issuer's metadata.
|
| IssuerRegistrationAuthorityRuleParser |
|
| IssuingDelegatedAssertionPredicate |
A predicate which determines whether issuance of a delegated
SAML 2 Assertion is active.
|
| JAASCredentialValidator |
A password validator that authenticates against JAAS.
|
| JarCheckArguments |
|
| JarCheckCLI |
Program to check for potential jar clashes.
|
| JDBCPairwiseIdStore |
JDBC-based storage management for pairwise IDs.
|
| JoinFunction |
Function to join the result of two functions with a separator.
|
| KerberosCredentialValidator |
A password validator that authenticates against Kerberos natively, with optional service ticket verification.
|
| KerberosRealmSettings |
Kerberos realm settings for the SPNEGO authentication flow.
|
| KerberosSettings |
Kerberos settings for the SPNEGO authentication flow.
|
| KerberosTicketContext |
|
| KeyAuthority |
XMLObject for the Shibboleth KeyAuthority metadata extension.
|
| KeyAuthorityBuilder |
|
| KeyAuthorityImpl |
|
| KeyAuthorityMarshaller |
|
| KeyAuthorityNodeProcessor |
|
| KeyAuthorityParser |
Parser for a <KeyAuthority> node processor.
|
| KeyAuthoritySupport |
|
| KeyAuthoritySupport.KeyAuthorityPKIXValidationInformation |
|
| KeyAuthorityUnmarshaller |
|
| KeystoreResourceCredentialConfig |
|
| LDAPAuthenticationFactoryBean |
LDAP Authentication configuration.
|
| LDAPAuthenticationFactoryBean.AuthenticatorType |
Enum that defines authenticator configuration.
|
| LDAPAuthenticationFactoryBean.ConnectionStrategyType |
Enum that defines LDAP connection strategy.
|
| LDAPAuthenticationFactoryBean.PassivatorType |
Enum that defines an LDAP pool passivator.
|
| LDAPAuthenticationFactoryBean.TrustType |
Enum that defines LDAP trust configuration.
|
| LDAPCredentialValidator |
A password validator that authenticates against LDAP natively.
|
| LDAPDataConnector |
A DataConnector that queries an LDAP in order to retrieve attribute
data.
|
| LDAPDataConnectorParser |
|
| LDAPDataConnectorParser.V2Parser |
Utility class for parsing v2 schema configuration.
|
| LDAPPrincipalSerializer |
|
| LDAPResponseContext |
A context containing data about an LDAP authentication operation.
|
| LegacyCanonicalization |
Deprecated. |
| LegacyEncryptionRequirementPredicate |
A predicate implementation that supports the legacy V2 configuration options of
"always", "conditional", and "never" for encryption.
|
| LegacyEncryptionRequirementPredicate.EncryptionRequirementSetting |
Internal enum for the options supported.
|
| LegacySigningRequirementPredicate |
A predicate implementation that supports the legacy V2 configuration options of
"always", "conditional", and "never" for signing.
|
| LegacySigningRequirementPredicate.SigningRequirementSetting |
Internal enum for the options supported.
|
| LibertyConstants |
Liberty-related constants.
|
| LibertyHTTPSOAP11Decoder |
Decoder for Liberty ID-WSF 2.0 SOAP 1.1 HTTP binding carrying SAML protocol messages
used in SAML delegation.
|
| LibertyHTTPSOAP11Encoder |
Encoder for Liberty ID-WSF 2.0 SOAP 1.1 HTTP binding carrying SAML protocol messages
used in SAML delegation.
|
| LibertySSOSContext |
Context for storing information related to the Liberty SSOS profile and use of an inbound delegated
Assertion token.
|
| ListConfigurationLookupStrategy<T> |
A strategy function that examines SAML metadata associated with a relying party and derives List<String>-valued
configuration settings based on EntityAttribute extension tags.
|
| LocalDynamicMetadataProviderParser |
|
| LocaleLookupFunction |
|
| LocalFlowBuilderContext |
This code is copied verbatim from org.springframework.webflow.engine.builder.model.LocalFlowBuilderContext
A builder context that delegates to a flow-local bean factory for builder services.
|
| LockoutManagerContext |
|
| LogbackLoggingService |
Simple LoggingService that watches for logback configuration file changes
and reloads the file when a change occurs.
|
| LogContextTree |
Spring Web Flow utility action for logging on DEBUG a representation of the current
ProfileRequestContext.
|
| LoggingService |
Deprecated, for removal: This API element is subject to removal in a future version. |
| LoggingVisitor |
A @{link FileVisitor copies directory trees keeping a note of all copied target files.
|
| LogImplementationDetails |
A bean that logs IdP internals when instantiated.
|
| LoginConfiguration |
CAS protocol configuration that applies to the /login URI.
|
| LogoutContext |
|
| LogoutContextSessionLookupFunction |
A function that returns a session from a LogoutContext
and removes it from that context at the same time.
|
| LogoutPropagationContext |
Context holding information needed to perform logout for a single SP session.
|
| LogoutPropagationContext.Result |
Logout propagation result.
|
| LogoutPropagationFlowDescriptor |
A descriptor for a logout propagation flow.
|
| LogoutPropagationFlowDescriptorManager |
|
| LogoutPropagationFlowDescriptorSelector |
Selection function to retrieve the logout propagation flow descriptor that is suitable for a given SPSession.
|
| LogoutStatusStrategyFunction |
A strategy function for determining the status of a logout based on the content of
a LogoutContext.
|
| LogRuntimeException |
Dedicated bean used to log flow exceptions, to get around issues with Spring Expressions
referencing class objects under certain conditions that are so far not understood.
|
| LogSpringContextInfo |
Spring Web Flow utility action for logging on DEBUG details about the current hierarchy of
Spring ApplicationContext and the beans contained within each.
|
| LongConfigurationLookupStrategy |
A strategy function that examines SAML metadata associated with a relying party and derives Long-valued
configuration settings based on EntityAttribute extension tags.
|
| LoopDetectionPredicate |
A condition that relies on a Meter to detect looping SPs.
|
| ManagedConnectionParser |
Utility class for parsing v2 managed connection configuration.
|
| MapDrivenAuthnContextTranslationStrategy |
Implements a set of default logic for mapping an AuthnContext's content into a set of
custom Principals based on a set of static mapping rules.
|
| MappedAttributeDefinition |
Implementation of Mapped Attributes.
|
| MappedAttributeDefinitionParser |
|
| MappedAttributeInMetadataRuleParser |
|
| MappedEntityAttributesPredicate |
Extended version of EntityAttributes-driven predicate that uses an optimization to check
for mapped attributes in an AttributesMapContainer structure.
|
| MappingStrategy<T> |
Strategy for mapping from an arbitrary result type to a collection of IdPAttributes.
|
| MapRequestedAttributesInAttributeConsumingService |
Action that ensures that the attributes in the ACS (if any) are mapped.
|
| Matcher |
Java definition of MatchFunctorType as applied to value filtering.
|
| MatcherFromPolicy |
|
| MaximumTimeSinceAuthnLookupFunction |
|
| MergePropertiesTask |
A class to merge a property file into another property file, preserving the comments.
|
| MessageSourceConsentFunction |
Function that returns a consent object whose id and value are resolved from a lookup function
and MessageSource.
|
| MetadataGenerator |
Interface to define Metadata Generation.
|
| MetadataGeneratorImpl |
This class gathers information which it then uses to generate IdP Metadata.
|
| MetadataGeneratorImpl.Endpoints |
The end points we understand.
|
| MetadataGeneratorParameters |
Interface which describes metadata that needs to be generated.
|
| MetadataGeneratorParametersImpl |
|
| MetadataGeneratorTask |
Task to generate metadata.
|
| MetadataNamespaceHandler |
Namespace handler for urn:mace:shibboleth:2.0:metadata.
|
| MetadataPKIXValidationInformationResolver |
|
| MetadataProtocolAuditExtractor |
Function that returns the Metadata protocol (as defined by the bean
called shibboleth.MetadataLookup.Protocol).
|
| MetadataProviderContainer |
This class is a sortable container of MetadataResolvers, wrapped into a serviceable component.
|
| MetadataQueryArguments |
Command line processing for MetadataQuery flow.
|
| MetadataQueryRequest |
Object representing a query for metadata.
|
| MetadataQueryRequestDecoder |
Decodes an incoming metadata query request.
|
| MetadataResolverServiceGaugeSet |
Additional gauges for metadata resolvers.
|
| MetadataResolverServiceStrategy |
|
| MetadataServiceRegistry |
CAS service registry implementation that queries SAML metadata for a CAS service given a CAS service URL using
the following strategy.
|
| MetadataServiceRegistry.LoginEndpointPredicate |
Predicate defines CAS login endpoints so that the metadata index on endpoints can be scoped to the smallest
set needed to support CAS entities in SAML metadata.
|
| MFA |
|
| ModuleContext |
Information required to perform some module operations.
|
| ModuleException |
Module exception class.
|
| ModuleManagerArguments |
|
| ModuleManagerCLI |
|
| MultiFactorAuthenticationContext |
A context that holds information about the intermediate state of the multi-factor login flow.
|
| MultiFactorAuthenticationTransition |
A ruleset for managing the transition out of a step during the multi-factor authn flow.
|
| MultipleResultAnErrorResolutionException |
A special ResolutionException which is thrown if multiple results were resolved
by a data connector and the deployer specified "MultipleResultsAnError".
|
| MultiRelyingPartyContext |
|
| NameDecoderException |
Error thrown if decoding of a SAML subject identifier fails.
|
| NameIDAuditExtractor |
Function that returns the Name Identifier from a request or response.
|
| NameIDCanonicalization |
Action to perform subject canonicalization, transforming the input Subject
into a principal name by searching for one and only one NameIDPrincipal custom principal,
using an injected NameIDDecoder to carry out the process.
|
| NameIDCanonicalization.ActivationCondition |
A predicate that determines if this action can run or not.
|
| NameIDCanonicalizationFlowDescriptor |
|
| NameIDDecoder |
Interface for converting a NameID back into a principal name.
|
| NameIdentifierCanonicalization |
|
| NameIdentifierCanonicalization.ActivationCondition |
A predicate that determines if this action can run or not.
|
| NameIdentifierDecoder |
|
| NameIdentifierGenerationService |
A service interface for obtaining name identifier generators.
|
| NameIdentifierGenerationServiceImpl |
|
| NameIdentifierPrincipal |
|
| NameIDFormatAuditExtractor |
Function that returns the Name Identifier Format from a SAML Subject.
|
| NameIDFormatFilterParser |
Parser for a <NameIDFormat> filter.
|
| NameIDPolicyFormatAuditExtractor |
Function that returns the NameID Format from a NameIDPolicy element.
|
| NameIDPolicySPNameQualifierAuditExtractor |
Function that returns the SPNameQualifier from a NameIDPolicy element.
|
| NameIDPrincipal |
Principal based on the SAML2 NameID.
|
| NameIDPrincipalSerializer |
|
| NodeProcessingAttachingBeanPostProcessor |
|
| NodeProcessingParser |
Parser for a <NodeProcessing> filter.
|
| NonFailFastValidator |
Used to determine whether a Data Connector initialized properly and continues to be fit for use.
|
| NoResultAnErrorResolutionException |
A special ResolutionException which is thrown if no results were resolved
by a data connector and the deployer specified "NoResultsAnError".
|
| NotBeforeProfileConfigPredicate |
|
| NotMatcher |
Matcher that implements the negation of a matcher.
|
| NotMatcherParser |
|
| NotPolicyRule |
|
| NumOfAttributeValuesPolicyRule |
A policy rule that checks if the given attribute has more than the minimum number of values but less than the
maximum.
|
| NumOfAttributeValuesRuleParser |
|
| OneTimeAdministrativeFlowDescriptor |
Descriptor for an administrative flow that tracks whether it's been run or not to
limit use.
|
| OpenSAMLConfigBean |
A simple bean that may be used with Spring to initialize the OpenSAML library
with injected instances of some critical objects.
|
| OrganizationDisplayNameTag |
Service OrganizationDisplayName - directly from the metadata if present.
|
| OrganizationNameTag |
Service OrganizationName - directly from the metadata if present.
|
| OrganizationUIInfo |
Class to contain a processed form of the Organization suitable for display purposes.
|
| OrganizationURLTag |
Service OrganizationURL - directly from the metadata if present.
|
| OrMatcher |
Matcher that implements the disjunction of matchers.
|
| OrMatcherParser |
|
| OrPolicyRule |
|
| OutboundFlowsLookupFunction |
|
| OutboundRuleParser |
|
| OutputMetrics |
Action that outputs one or more Metric objects.
|
| OverriddenIssuerProfileConfiguration |
|
| PairwiseId |
Object representing a pairwise/targeted identifier entry as a storage input/output.
|
| PairwiseIdDataConnector |
|
| PairwiseIdDataConnectorParser |
|
| PairwiseIdStore |
Storage and retrieval interface for pairwise/targeted identifiers allowing for custom implementations.
|
| ParameterizedExecutableSearchFilterBuilder |
Deprecated.
|
| ParameterizedExecutableSearchFilterBuilder |
|
| Password |
|
| PasswordHandler |
Ant helper class to ask for passwords, rejecting zero length passwords and asking for confirmation.
|
| PasswordPrincipal |
Principal that wraps a password.
|
| PathInfoSupportingFlowUrlHandler |
Extension of standard SWF URL handler that checks for requests in which a valid flow ID
is a prefix of the PATH_INFO value, allowing the flow to run with the rest of the path
available to it as input.
|
| PatternServiceRegistry |
Service registry that evaluates a candidate service URL against one or more defined services, where each
definition contains a service URL regular expression pattern.
|
| PersistenceManager<ItemType> |
Deprecated. |
| PersistentSAML2NameIDGenerator |
Generator for "persistent" Format NameID objects that provides a source/seed ID based on IdPAttribute
data.
|
| PKIXInlineValidationInfoFactoryBean |
File system specific bean for PKIXValidationInfo.
|
| PKIXInlineValidationInfoParser |
Parser for <ValidationInfo type="PKIXInline">.
|
| PKIXResourceValidationInfoFactoryBean |
File system specific bean for PKIXValidationInfo.
|
| PKIXResourceValidationInfoParser |
Parser for <ValidationInfo type="PKIXFilesystem"> and <ValidationInfo type="PKIXResourceBacked">.
|
| PKIXValidationOptionsParser |
A Parser for the < ValidationOptions > within a StaticPKIXSignature.
|
| PluginDependencySupport |
|
| PluginException |
Plugin exception class.
|
| PluginIdPModule |
Implementation base class for IdPModule that is shipped in a plugin
produced by the Shibboleth Project ourselves and for which the documentation
will be in the wiki in a fixed location.
|
| PluginInfo |
Class which encapsulates the information about a given plugin as downloaded
fro the plugin URL (or file).
|
| PluginInstaller |
The class where the heavy lifting of managing a plugin happens.
|
| PluginInstallerArguments |
Arguments for Plugin Installer CLI.
|
| PluginInstallerArguments.OperationType |
Operation enum.
|
| PluginInstallerCLI |
Command line for Plugin Installation.
|
| PluginInstallerSupport |
Support for copying files during plugin manipulation.
|
| PluginInstallerSupport.DeletingVisitor |
|
| PluginInstallerSupport.NameClashVisitor |
A @{link FileVisitor which detects (and logs) whether a copy would overwrite.
|
| PluginState |
A class which will answer questions about a plugin state as of now
(by querying the information Resources for the current published state).
|
| PluginState.VersionInfo |
Encapsulation of the information about a given IdP version.
|
| PluginSupport |
Useful methods for supporting plugins.
|
| PluginSupport.SupportLevel |
|
| PluginVersion |
A version string (Major.minor.patch) as a handy class.
|
| PolicyFromMatcher |
|
| PolicyFromMatcherId |
|
| PolicyRequirementRule |
Java definition of PolicyRequirementRule.
|
| PolicyRequirementRule.Tristate |
Representation of the three outcomes of a PolicyRequirementRule.
|
| PooledTemplateSearchDnResolver |
Template-based pooled search dn resolver.
|
| PopulateAttributeReleaseContext |
Attribute consent action to populate the attribute consent context with the attributes for which consent should be
obtained.
|
| PopulateAuditContext |
Action that populates fields in an AuditContext using injected functions.
|
| PopulateAuditContext.FormattingMapParser |
Parser for the formatting strings that exposes a final set of field labels that are
present in any of the input formatters.
|
| PopulateAuthenticationContext |
|
| PopulateBindingAndEndpointContexts |
|
| PopulateConsentContext |
Consent action which populates the current consents of a consent context with the output value of a function whose
input value is a profile request context.
|
| PopulateDelegationContext |
A profile action which determines whether issuance of a delegated
Assertion token
is active, and populates a DelegationContext appropriately.
|
| PopulateEncryptionParameters |
|
| PopulateInboundMessageContextWithSAMLSelf |
|
| PopulateLibertyContext |
|
| PopulateLogoutPropagationContext |
|
| PopulateMultiFactorAuthenticationContext |
|
| PopulateMultiRPContextFromLogoutContext |
|
| PopulateOutboundMessageContext |
Populate the outbound message context with data that is specific to the delegation flow.
|
| PopulateProfileInterceptorContext |
|
| PopulateProtocolErrorAction<RequestType> |
Populates error information needed for protocol error messages.
|
| PopulateSessionContext |
|
| PopulateSubjectCanonicalizationContext |
|
| PopulateSubjectContext |
|
| PopulateUserAgentContext |
|
| PostAuthenticationFlowsLookupFunction |
|
| PredicateFilterDirectionFactoryBean |
Factory bean allow property replacements of the direction going in to a PredicateFilter.
|
| PredicateFilterParser |
Parser for a <Predicate> filter.
|
| PredicatePolicyRule |
Call out to an externally define predicate.
|
| PredicateRuleParser |
|
| PreferExplicitOrderComparator |
Comparator which prefers to order strings according to the order in which they appear in a list, and which falls back
to natural ordering for strings not present in the list.
|
| PreferredPrincipalContext |
A context that holds information about an authentication request's
preference for a specific custom Principal.
|
| PrepareInboundMessageContext |
|
| PrepareTicketValidationResponseAction |
|
| PreProcessLogoutMessage |
|
| PrescopedAttributeDefinition |
|
| PrescopedAttributeDefinitionParser |
Spring bean definition parser for prescoped attributes.
|
| PreserveAuthenticationFlowState |
|
| PreviousResultLookupFunction |
|
| PrincipalEvalPredicate |
|
| PrincipalEvalPredicateFactory |
|
| PrincipalEvalPredicateFactoryRegistration |
|
| PrincipalEvalPredicateFactoryRegistry |
A registry of mappings between a custom Principal subtype with a matching operator
and a corresponding PrincipalEvalPredicateFactory that returns predicates enforcing
a particular set of matching rules for that operator and subtype.
|
| PrincipalNameAttributeDefinition |
An attribute definition which returns an attribute with a single value - the principal.
|
| PrincipalNameAttributeDefinitionParser |
Spring Bean Definition Parser for PrincipalName attribute definitions.
|
| PrincipalNamePolicyRule |
Compare the principal name for this resolution with the provided string.
|
| PrincipalNameRegexpPolicyRule |
Compare the principal name for this resolution with the provided regexp.
|
| PrincipalNameRegexRuleParser |
|
| PrincipalNameRuleParser |
|
| PrincipalSerializer<Type> |
Interface for the serialization/deserialization of principals.
|
| PrincipalService<T extends Principal> |
Interface that provides services for a Principal of a given type.
|
| PrincipalServiceManager |
|
| PrincipalSupportingComponent |
Interface for an authentication component that exposes custom Principal objects.
|
| ProcessAssertionsForAuthentication |
Perform processing of a SAML 2 Response's Assertions that have been validated by earlier actions
for use in finalization of SAML-based authentication by later actions.
|
| ProcessDelegatedAssertion |
Process the pre-validated inbound Assertion WS-Security token, and set up the resulting
NameID for subject canonicalization as the effective subject of the request.
|
| ProcessFrameworkHandler |
Handler implementation that handles sbf:Framework header on the inbound SOAP envelope.
|
| ProcessLogout |
Profile action that resolves an active session from the profile request, and records it,
populating the associated SPSession objects into a LogoutContext.
|
| ProcessLogoutRequest |
Profile action that processes a LogoutRequest by resolving matching sessions, and destroys them,
populating the associated SPSession objects (excepting the one initiating the logout) into a
LogoutContext.
|
| ProcessRequestedAuthnContext |
|
| ProcessSamlMessageAction |
Processes the ticket validation request message from decoded SAML 1.1 message and request parameters.
|
| ProcessSenderHandler |
Handler implementation that handles the sb:Sender header on the inbound SOAP envelope.
|
| ProfileActionBeanFactoryPostProcessor |
Post-processes bean configuration metadata to ensure that stateful beans are scoped properly.
|
| ProfileActionBeanPostProcessor |
Post-processes ProfileAction beans by wrapping them in a Spring Web Flow adaptor.
|
| ProfileConfiguration |
Represents the configuration of a particular communication profile.
|
| ProfileInterceptorContext |
A BaseContext which holds flows that are available to be executed, the last flow attempted, and any flow
result.
|
| ProfileInterceptorFlowDescriptor |
A descriptor for a profile interceptor flow.
|
| ProfileInterceptorFlowDescriptorManager |
|
| ProfileInterceptorResult |
Represents the result of a profile interceptor flow intended for storage by a
StorageService.
|
| ProfilePolicyRule |
Compare the profile identifier for this resolution with the provided string.
|
| ProfileRequestContextFlowExecutionListener |
Exposes the ProfileRequestContext in a request attribute to make it
accessible outside the Webflow execution pipeline.
|
| ProfileRuleParser |
|
| ProgressReportingOutputStream |
|
| PropertiesWithComments |
A package which is similar to Properties, but allows comments to be preserved.
|
| PropertiesWithComments.CommentedProperty |
A POJO which looks like a property.
|
| PropertyDrivenIdPModule |
|
| PropertyDrivenIdPPlugin |
|
| ProtocolContext<RequestType,ResponseType> |
Context container for CAS protocol request and response messages.
|
| ProtocolError |
CAS protocol errors.
|
| ProtocolParam |
Protocol parameter name enumeration.
|
| ProxiedRequesterEntityAttributeExactPolicyRule |
Matcher that checks, via an exact match, if the proxied requester's metadata
contains an entity attribute with a given value.
|
| ProxiedRequesterEntityAttributeExactRuleParser |
|
| ProxiedRequesterEntityAttributeRegexPolicyRule |
Matcher that checks, via regex, if the proxied attribute requester's metadata
contains an entity attribute with a given value.
|
| ProxiedRequesterEntityAttributeRegexRuleParser |
|
| ProxiedRequesterInEntityGroupPolicyRule |
A matcher that evaluates to true if proxied requester's metadata matches the provided entity group name,
or a valid metadata-sourced affiliation of entities.
|
| ProxiedRequesterInEntityGroupRuleParser |
|
| ProxiedRequesterPolicyRule |
Compare a proxied attribute requester's entity ID for this resolution with the provided name.
|
| ProxiedRequesterRegexpPolicyRule |
Compare a proxied attribute requester's entity ID for this resolution with the provided regexp.
|
| ProxiedRequesterRegexRuleParser |
|
| ProxiedRequesterRegistrationAuthorityPolicyRule |
Rule based on RPI extension in proxied requester's metadata.
|
| ProxiedRequesterRegistrationAuthorityRuleParser |
|
| ProxiedRequesterRuleParser |
|
| ProxyAudienceAuditExtractor |
|
| ProxyAuthenticationLookupFunction |
|
| ProxyAuthenticationPrincipal |
Principal that wraps a set of proxied authentication authorities and any restrictions
on subsequent re-use.
|
| ProxyAuthenticationPrincipalSerializer |
|
| ProxyAwareAuthnContextComparisonLookupFunction |
|
| ProxyAwareDefaultAuthenticationMethodsLookupFunction |
Implements a set of default logic for determining the custom principals to derive the
RequestedAuthnContext from.
|
| ProxyAwareForceAuthnPredicate |
Implements a set of default logic for determining whether ForceAuthn should be applied.
|
| ProxyConfiguration |
CAS protocol configuration that applies to the /proxy URI.
|
| ProxyCountAuditExtractor |
|
| ProxyCountLookupFunction |
|
| ProxyGrantingTicket |
CAS proxy-granting ticket.
|
| ProxyGrantingTicketLookupFunction |
Looks up the PGT from a proxy ticket request.
|
| ProxyGrantingTicketSerializer |
Serializes proxy-granting tickets in simple field-delimited form.
|
| ProxyIdentifiers |
Container for identifiers used in authenticating a proxy callback endpoint.
|
| ProxyRestrictionLookupFunction |
A function that returns the allowable proxy count and audiences to include in assertions,
based on the results of lookup functions for local configuration merged with upstream
proxy restrictions to compute a final result in accordance with the standard.
|
| ProxySAML1NameIdentifierGenerator |
A compound implementation of the SAML1NameIdentifierGenerator interface that wraps a sequence of
candidate generators along with a default to try if no format-specific options are available.
|
| ProxySAML2NameIDGenerator |
A compound implementation of the SAML2NameIDGenerator interface that wraps a sequence of
candidate generators along with a default to try if no format-specific options are available.
|
| ProxyTicket |
CAS proxy ticket.
|
| ProxyTicketRequest |
Container for proxy ticket request parameters provided to /proxy URI.
|
| ProxyTicketResponse |
Container for proxy ticket response parameters returned from /proxy URI.
|
| ProxyTicketSerializer |
Proxy ticket storage serializer.
|
| ProxyValidator |
Strategy pattern component for proxy callback endpoint validation.
|
| PublishProtocolMessageAction<RequestType,ResponseType> |
Action to publish the CAS protocol request or response messages, i.e.
|
| QualifiedNameIDFormatsLookupFunction |
|
| RDBMSDataConnector |
A DataConnector that queries a relation database in order to retrieve
attribute data.
|
| RDBMSDataConnectorParser |
|
| RDBMSDataConnectorParser.V2Parser |
Utility class for parsing v2 schema configuration.
|
| ReadConsentFromStorage |
Consent action which reads consent records from storage and adds the serialized consent records to the consent
context as previous consents.
|
| RecordResponseComplete |
Action that records the "Response Complete" status on the external context if not done so already.
|
| RegexAttributePredicate |
Predicate that evaluates an AttributeContext and checks
a specific attribute for value(s) that match a regular expression.
|
| RegexSplitAttributeDefinition |
An AttributeDefinition that produces its attribute values by taking the
first group match of a regular expression evaluating against the values of this definition's dependencies.
|
| RegexSplitAttributeDefinitionParser |
Spring Bean Definition Parser for Regexp split attribute definitions.
|
| ReleaseAttributes |
Attribute consent action which constrains the attributes released to those consented to.
|
| ReloadableServiceGaugeSet<T> |
A set of gauges for a reloadable service.
|
| ReloadingAccessControlService |
|
| ReloadingRelyingPartyConfigurationResolver |
Retrieves a per-relying party configuration for a given profile request based on the request context.
|
| ReloadingRelyingPartyMetadataProvider |
|
| ReloadingServiceRegistry |
|
| ReloadMetadata |
|
| ReloadMetadataArguments |
Command line processing for reload-metadata flow.
|
| ReloadServiceArguments |
Command line processing for reload-service flow.
|
| ReloadServiceConfiguration |
|
| RelyingPartyConfiguration |
The configuration that applies to a given relying party.
|
| RelyingPartyConfigurationResolver |
|
| RelyingPartyConfigurationSupport |
|
| RelyingPartyContext |
|
| RelyingPartyContextLookupByCurrent |
|
| RelyingPartyContextLookupById |
|
| RelyingPartyContextLookupByLabel |
|
| RelyingPartyIdLookupFunction |
|
| RelyingPartyIdPredicate |
Predicate that evaluates a ProfileRequestContext by looking for a relying party ID
that matches one of a designated set, or a generic predicate.
|
| RelyingPartyMapJAASLoginConfigStrategy |
An implementation of the loginConfigStrategy for JAASCredentialValidator
which uses a supplied map to resolve the JAAS config to use.
|
| RelyingPartyResolverCredentialHolder |
This is a utility class used as an auto-wiring source for collections of
signing and encryption Credential objects so that other layers of the
system can gain access to the complete set of them.
|
| RelyingPartyUIContext |
The context which carries the user interface information.
|
| RemoteUser |
|
| RemoteUserAuthServlet |
Extracts authentication information from the request and returns it via the IdP's external authentication
interface.
|
| RemoteUserInternal |
|
| RenewLookupFunction |
Looks up the value of the CAS renew parameter from the request to the /login URI.
|
| RequestedPrincipalContext |
A context that holds information about an authentication request's
requirement for a specific custom Principal.
|
| RequestedPrincipalContextOperatorLookupFunction |
|
| RequestedPrincipalContextPrincipalLookupFunction |
|
| RequesterEntityAttributeExactPolicyRule |
Matcher that checks, via an exact match, if the attribute requester's metadata
contains an entity attribute with a given value.
|
| RequesterEntityAttributeExactRuleParser |
|
| RequesterEntityAttributeRegexPolicyRule |
Matcher that checks, via regex, if the attribute requester's metadata
contains an entity attribute with a given value.
|
| RequesterEntityAttributeRegexRuleParser |
|
| RequesterInEntityGroupPolicyRule |
A matcher that evaluates to true if attribute requester's metadata matches the provided entity group name,
or a valid metadata-sourced affiliation of entities.
|
| RequesterInEntityGroupRuleParser |
|
| RequesterNameIDFormatExactPolicyRule |
Checks if the attribute requester supports the required NameID format.
|
| RequesterNameIDFormatRuleParser |
|
| RequesterRegistrationAuthorityPolicyRule |
Rule based on RPI extension in attribute requester's metadata.
|
| RequesterRegistrationAuthorityRuleParser |
|
| RequiredValidUntilParser |
Parser for a <RequiredValidUntil> filter.
|
| ResolutionException |
An exception indicating a problem resolving attribute data.
|
| ResolutionLabelLookupFunction |
|
| ResolutionLabelPredicate |
Predicate that evaluates a ProfileRequestContext by looking for an attribute resolution label
that matches one of a designated set or a generic predicate.
|
| ResolveAttributes |
|
| ResolveAttributesPredicate |
Predicate to determine whether a profile request should resolve attributes.
|
| ResolveAttributesProfileConfigPredicate |
Deprecated, for removal: This API element is subject to removal in a future version. |
| ResolvedAttributeDefinition |
A proxy which wraps a resolved attribute definition and always returns the same attribute.
|
| ResolvedDataConnector |
A proxy which wraps a resolved data connector and always returns the same attributes.
|
| ResolverAttributeDefinitionDependency |
A Dependency that references to an Attribute Definition.
|
| ResolverDataConnectorDependency |
A Dependency that references to an Data Connector.
|
| ResolverPlugin<ResolvedType> |
Interface defining the base work done by all plugins used within attribute resolution.
|
| ResolverTestArguments |
Command line processing for ResolverTest flow.
|
| ResolverTestPrincipalLookup |
|
| ResolverTestRequest |
Object representing a request to run the attribute resolution and filtering components.
|
| ResolverTestRequestDecoder |
Decodes an incoming resolver test message.
|
| ResourceBackedMetadataProviderParser |
Parser for a ResourceBackedMetadataProvider.
|
| ResponderIdLookupFunction |
|
| RestoreProfileRequestContextTree |
Restores specific portions of the context tree used during logout processing to enable
reuse of logout propagation subflows during back channel logout.
|
| ResultMappingStrategy |
|
| RethrowingFlowExecutionExceptionHandler |
This handler can be attached to view or end states that are used to respond to errors,
including RuntimeExceptions, so that if they themselves raise another RuntimeException,
it won't trigger the state again, but just fail the flow.
|
| RethrowingFlowHandlerAdapter |
Extension of SWF's built-in FlowHandlerAdapter implementation that overrides its
poor assumption that a missing flow exception should result in the flow being restarted.
|
| RevocationCacheCondition |
A condition for login flows that checks for revocation against a RevocationCache.
|
| RevokeConsent |
Consent action which deletes a consent record from storage.
|
| RewritePropertiesTask |
A class to rename the property names in a property file, preserving the comments.
|
| RollbackPluginInstall |
|
| SAML1AttributeTranscoder<EncodedType extends IdPAttributeValue> |
|
| SAML1Base64AttributeEncoderParser |
|
| SAML1ByteAttributeTranscoder |
|
| SAML1NameIdentifierAttributeDefinition |
Deprecated, for removal: This API element is subject to removal in a future version. |
| SAML1NameIdentifierAttributeDefinitionParser |
Spring bean definition parser for SAML 1 NameIdentifier attribute definitions.
|
| SAML1ProfileConfiguration |
Marker interface for SAML 1.x profile configuration interfaces, currently empty.
|
| SAML1ScopedStringAttributeEncoderParser |
|
| SAML1ScopedStringAttributeTranscoder |
|
| SAML1SPSession |
Marker subtype for a SAML 1 session, adds no actual information other than its identity as
a SAML 1 session.
|
| SAML1SPSessionCreationStrategy |
A function to create a SAML1SPSession based on profile execution state.
|
| SAML1SPSessionSerializer |
|
| SAML1StringAttributeEncoderParser |
|
| SAML1StringAttributeTranscoder |
|
| SAML1XMLObjectAttributeEncoderParser |
|
| SAML1XMLObjectAttributeTranscoder |
|
| SAML2AttributeTranscoder<EncodedType extends IdPAttributeValue> |
|
| SAML2AuthnRequestsSignedSecurityHandler |
Message handler implementation that enforces the AuthnRequestsSigned flag of
SAML 2 metadata element @{link SPSSODescriptor and/or a local profile
configuration option.
|
| SAML2Base64AttributeEncoderParser |
|
| SAML2ByteAttributeTranscoder |
|
| SAML2DateTimeAttributeEncoderParser |
|
| SAML2DateTimeAttributeTranscoder |
|
| SAML2NameIDAttributeDefinition |
Deprecated, for removal: This API element is subject to removal in a future version. |
| SAML2NameIDAttributeDefinitionParser |
Spring bean definition parser for SAML 2 NameID attribute definitions.
|
| SAML2ProfileConfiguration |
Base interface for SAML 2 profile configurations.
|
| SAML2ScopedStringAttributeEncoderParser |
|
| SAML2ScopedStringAttributeTranscoder |
|
| SAML2SPSession |
Extends a BasicSPSession with SAML 2.0 information required for
reverse lookup in the case of a logout.
|
| SAML2SPSessionCreationStrategy |
A function to create a SAML2SPSession based on profile execution state.
|
| SAML2SPSessionSerializer |
|
| SAML2StringAttributeEncoderParser |
|
| SAML2StringAttributeTranscoder |
|
| SAML2XMLObjectAttributeEncoderParser |
|
| SAML2XMLObjectAttributeTranscoder |
|
| SAMLArtifactAwareProfileConfiguration |
Common interface for SAML profile configurations involving artifact production.
|
| SAMLArtifactConfiguration |
Interface for outbound SAML artifact configuration.
|
| SAMLArtifactConsumerProfileConfiguration |
Common interface for SAML profile configurations involving artifact consumption, for example artifact
resolution requests.
|
| SAMLAuditFields |
Constants to use for audit logging fields stored in an AuditContext.
|
| SAMLAuthnContext |
Manages state during proxied SAML authentication.
|
| SAMLAuthnController |
MVC controller that handles outbound and inbound message I/O for
proxied SAML authentication.
|
| SAMLConstants |
XML related constants used with SAML.
|
| SAMLContext |
|
| SAMLEncoderSupport |
Support class for encoding IdP Attributes and their value.
|
| SAMLMetadataContextLookupFunction |
|
| SAMLMetadataContextLookupFunction |
|
| SamlParam |
SAML 1.1 protocol params needed to support /samlValidate endpoint.
|
| SAMLProfileConfiguration |
Common interface for SAML profile configurations.
|
| SAMLRelyingPartyIdLookupStrategy |
|
| SAMLSOAPDecoderBodyHandler |
Body handler impl for use with SAML SOAP message decoders.
|
| SAMLVerificationLookupStrategy |
|
| SaveLogoutContext |
Stores the LogoutContext in the servlet session to facilitate lookup by logout propagation flows.
|
| SaveProfileRequestContextTree |
Saves off specific portions of the context tree in use during logout processing to enable
reuse of logout propagation subflows during back channel logout.
|
| SchemaValidationParser |
Parser for a <SchemaValidation> filter.
|
| Scope |
XMLObject for the Shibboleth Scope metadata extension.
|
| ScopeBuilder |
Builder of Scope objects.
|
| ScopedAttributeDefinition |
An attribute definition that creates ScopedStringAttributeValues by taking a source attribute value and
applying a static scope to each.
|
| ScopedAttributeDefinitionParser |
Spring Bean Definition Parser for scoped attribute definitions.
|
| ScopedStringAttributeValue |
An attribute value with an associated scope.
|
| ScopedValue |
XMLObject that represents a SAML attribute value whose value contains a scope attribute.
|
| ScopedValueBuilder |
|
| ScopedValueImpl |
|
| ScopedValueMarshaller |
|
| ScopedValueUnmarshaller |
|
| ScopeImpl |
|
| ScopeMarshaller |
|
| ScopeMatchesShibMDScopeParser |
|
| ScopesContainer |
|
| ScopesNodeProcessor |
|
| ScopeUnmarshaller |
|
| ScopingIdPListAuditExtractor |
|
| ScopingProxyCountAuditExtractor |
|
| ScopingRequesterListAuditExtractor |
|
| ScriptDataConnectorParser |
|
| ScriptedAction |
An action which calls out to a supplied script.
|
| ScriptedAttributeDefinition |
An AttributeDefinition that executes a script in order to populate the
values of the generated attribute.
|
| ScriptedAttributeDefinitionParser |
Spring bean definition parser for scripted attribute configuration elements.
|
| ScriptedContextLookupFunction<T extends BaseContext> |
|
| ScriptedDataConnector |
|
| ScriptedIdPAttribute |
This is the API which is available to ECMAScripted attributes.
|
| ScriptedIdPAttributeImpl |
An encapsulated Attribute suitable for handing to scripts.
|
| ScriptedMatcher |
A Matcher that delegates to a JSR-223 script for its actual processing.
|
| ScriptedMatcherParser |
|
| ScriptedPolicyRule |
|
| ScriptedPredicate |
A Predicate which calls out to a supplied script.
|
| ScriptedResponseMappingStrategy |
|
| ScriptedStorageMappingStrategy |
|
| ScriptTypeBeanParser |
Parser for elements derived from ScriptType in the various namespaces.
|
| SealedPrincipalSerializer<T extends Principal> |
Principal serializer that encrypts/decrypts the data when serializing.
|
| SearchResultMappingStrategy |
|
| SecurityConfiguration |
Configuration for security behavior of profiles.
|
| SecurityNamespaceHandler |
|
| SelectAuthenticationFlow |
An authentication action that selects an authentication flow to invoke, or re-uses an
existing result for SSO.
|
| SelectLogoutPropagationFlow |
A profile action that selects a logout propagation flow to invoke.
|
| SelectProfileConfiguration |
|
| SelectProfileConfiguration |
|
| SelectProfileInterceptorFlow |
A profile interceptor action that selects flows to invoke.
|
| SelectRelyingPartyConfiguration |
|
| SelectRelyingPartyConfiguration |
|
| SelectSubjectCanonicalizationFlow |
A canonicalization action that selects a canonicalization flow to invoke.
|
| SelfEncryptionConfigurationLookupFunction |
|
| SelfSignedCertificateGeneratorTask |
|
| Service |
Container for metadata about a CAS service (i.e.
|
| ServiceContactTag |
return the contactInfo for the SP or null.
|
| ServiceContext |
IdP context container for CAS service (i.e.
|
| ServiceDefinition |
Defines a registered CAS service (i.e.
|
| ServiceDescriptionTag |
Display the description from the <mdui:UIInfo>.
|
| ServiceEntityDescriptor |
Adapts CAS protocol service metadata onto SAML metadata.
|
| ServiceInformationURLTag |
Service InformationURL - directly from the metadata if present.
|
| ServiceLogoTag |
Logo for the SP.
|
| ServiceLookupFunction |
Looks up the service URL from the CAS protocol request.
|
| ServiceNameTag |
Display the serviceName.
|
| ServicePrivacyURLTag |
Service PrivacyURL - directly from the metadata if present.
|
| ServiceRegistry |
Registry for explicitly verified CAS services (relying parties).
|
| ServiceTagSupport |
Display the serviceName.
|
| ServiceTicket |
CAS service ticket.
|
| ServiceTicketRequest |
Describes a request for a ticket to access a service.
|
| ServiceTicketResponse |
CAS protocol response message for a successfully granted service ticket.
|
| ServiceTicketSerializer |
Serializes service tickets in simple field-delimited form.
|
| ServletRequestProfileRequestContextLookup |
Looks up the profile request context from a servlet request attribute.
|
| SessionContext |
|
| SessionContextIDLookupFunction |
A function that returns the session ID from the session inside a SessionContext.
|
| SessionContextPrincipalLookupFunction |
A function that returns the principal name from the session inside a SessionContext.
|
| SessionException |
Exception indicating a problem authenticating a user.
|
| SessionIdCriterion |
|
| SessionIndexAuditExtractor |
Function that returns SessionIndex values from assertions in a response or a logout request.
|
| SessionLifetimeLookupFunction |
|
| SessionManager |
Component that manages sessions between the IdP and client devices.
|
| SessionResolver |
A resolver that is capable of finding IdPSession objects that meet certain criteria.
|
| SetConfigurationLookupStrategy<T> |
A strategy function that examines SAML metadata associated with a relying party and derives Set<String>-valued
configuration settings based on EntityAttribute extension tags.
|
| SetRPUIInformation |
|
| SignArtifactRequestsPredicate |
|
| SignAssertionsPredicate |
|
| SignatureChainingParser |
Parser for trust engines of type SignatureChaining.
|
| SignatureSigningConfigurationLookupFunction |
|
| SignatureSigningConfigurationLookupFunction |
|
| SignatureValidationConfigurationLookupFunction |
|
| SignatureValidationConfigurationLookupFunction |
|
| SignatureValidationCriteriaSetFactoryBean |
|
| SignatureValidationParser |
Parser for xsi:type="SignatureValidation".
|
| SigningCredentialsResolver |
Credential resolver whose purpose is to resolve configured IdP signing credentials.
|
| SignRequestsPredicate |
|
| SignResponsesPredicate |
|
| SignSOAPLogoutRequestsPredicate |
|
| SimpleAttributeDefinition |
An AttributeDefinition that creates an attribute whose values are the
values of all its dependencies.
|
| SimpleAttributeDefinitionParser |
|
| SimpleAttributePredicate |
Predicate that evaluates an AttributeContext and checks
for particular attribute/value pairs.
|
| SimpleCSRFToken |
A default, immutable, implementation of a CSRFToken.
|
| SimplePrincipalSerializer<T extends Principal> |
Principal serializer for string-based principals that serialize to a simple JSON structure.
|
| SimpleStorageMappingStrategy |
|
| SimpleSubjectCanonicalization |
|
| SimpleSubjectCanonicalization.ActivationCondition |
A predicate that determines if this action can run or not.
|
| SimpleTicketService |
Simple CAS ticket management service that delegates storage to StorageService.
|
| SingleLogoutProfileConfiguration |
Configuration support for SAML 2 Single Logout.
|
| SLF4JMDCServletFilter |
Servlet filter that sets some interesting MDC attributes as the request comes in and clears the MDC as the response
is returned.
|
| SOAPErrorPredicate |
Predicate that decides whether to handle an error by returning a SOAP fault to a requester
or fail locally.
|
| SOAPLogoutRequest |
Profile action that propagates a prepared LogoutRequest message to an SP via the SOAP
binding, encapsulating SOAP pipeline construction and execution.
|
| SourceValue |
Represents incoming attribute values and rules used for matching them.
|
| SourceValueParser |
|
| SPNameQualifierAuditExtractor |
Function that returns the SPNameQualifier from a SAML Subject.
|
| SPNEGO |
|
| SPNEGOAuthnController |
|
| SPNEGOAutoLoginManager |
Component managing the auto-login state via cookie.
|
| SPNEGOContext |
Context, usually attached to AuthenticationContext,
that carries configuration data and request state for SPNEGO authentication.
|
| SpringAwareMessageDecoderFactory |
A function that returns the correct MessageDecoder to use based on a simple map of
strings to bean IDs.
|
| SpringAwareMessageEncoderFactory |
|
| SpringEventToViewLookupFunction |
A function that returns a view name to render based on a Spring Web Flow Event.
|
| SpringExpressionContextLookupFunction<T extends BaseContext,U> |
|
| SpringExpressionPredicate |
Predicate whose condition is defined by an Spring EL expression.
|
| SpringFlowScopeLookupFunction |
A lookup function that fetches a SWF flow scope parameters.
|
| SpringRequestContext |
|
| SpringStatusMessageLookupFunction |
A function that returns a status message to include, if any, in a SAML response based on the current
profile request context state, using Spring's MessageSource functionality.
|
| SPSession |
Describes a session with a service in turn associated with an IdPSession.
|
| SPSessionCriterion |
Criterion representing a service ID and an implementation-specific service session key.
|
| SPSessionEx |
Deprecated, for removal: This API element is subject to removal in a future version. |
| SPSessionSerializerRegistry |
|
| SPSessionSerializerRegistry.Entry<T extends SPSession> |
Wrapper type for auto-wiring serializers.
|
| SSOSProfileConfiguration |
Configuration support for the Liberty ID-WSF SSOS profile.
|
| StaticAttributeDefinition |
An attribute definition that simply returns a static value.
|
| StaticDataConnector |
A DataConnector that just returns a static collection of
attributes.
|
| StaticDataConnectorParser |
|
| StaticExplicitKeyFactoryBean |
|
| StaticExplicitKeyParser |
Parser for trust engines of type StaticExplicitKey TrustEngine.
|
| StaticExplicitKeySignatureParser |
Parser for trust engines of type StaticExplicitKeySignature.
|
| StaticPKIXFactoryBean |
File system specific bean for PKIXX509CredentialTrustEngine.
|
| StaticPKIXSignatureParser |
Parser for trust engines of type StaticPKIXKeySignature.
|
| StaticPKIXX509CredentialParser |
Parser for trust engines of type StaticPKIXX509Credential.
|
| StatusArguments |
Command line processing for status flow.
|
| StatusCodeAuditExtractor |
Function that returns the StatusCode from a response.
|
| StatusCodeLookupFunction |
Looks up the protocol message status code from a CAS protocol message response.
|
| StatusDetailLookupFunction |
Looks up the protocol message status detail from a CAS protocol message response.
|
| StatusMessageAuditExtractor |
Function that returns the StatusMessage from a response.
|
| StorageBackedAccountLockoutManager |
|
| StorageBackedAccountLockoutManager.UsernameIPLockoutKeyStrategy |
A function to generate a key for lockout storage.
|
| StorageBackedIdPSession |
|
| StorageBackedIdPSessionSerializer |
|
| StorageBackedSessionManager |
|
| StorageBackedSessionManager.DefaultConsistentAddressConditionFactory |
Simplifies Spring wiring of a true/false condition for the consistentAddress feature.
|
| StorageMappingStrategy |
|
| StorageServiceDataConnector |
|
| StorageServiceDataConnectorParser |
|
| StorageServiceDataConnectorParser.V2Parser |
Utility class for parsing v2 schema configuration.
|
| StorageServiceSearch |
A search that can be executed against a StorageService to fetch a result.
|
| StoredIdDataConnectorParser |
Spring bean definition parser for StoredIDDataConnector.
|
| StoredPersistentIdDecoder |
An abstract decoder which contains the logic to decode SAML persistent IDs that are managed with a
DurablePairwiseIdStore.
|
| StoredTransientIdGenerationStrategy |
Generates transients using a StorageService to manage the reverse mappings.
|
| StringAttributeValue |
|
| StringAttributeValueMappingStrategy |
Deprecated.
|
| StringAttributeValueMappingStrategy |
|
| StringConfigurationLookupStrategy |
A strategy function that examines SAML metadata associated with a relying party and derives String-valued
configuration settings based on EntityAttribute extension tags.
|
| StringResultMappingStrategy |
Deprecated.
|
| StringResultMappingStrategy |
A simple ResultMappingStrategy that assumes all columns in the result set should be mapped and that all
values are strings.
|
| SubflowExpression |
This code is copied verbatim from org.springframework.webflow.engine.builder.model.SubflowExpression
|
| SubjectCanonicalizationContext |
A context that holds an input Subject to canonicalize into a principal name, and
the collection of c14n flows to attempt.
|
| SubjectCanonicalizationContextSubjectLookupFunction |
|
| SubjectCanonicalizationException |
Exception indicating a problem translating a subject between forms.
|
| SubjectCanonicalizationFlowDescriptor |
A descriptor for a subject canonicalization flow.
|
| SubjectContext |
A context that holds information about the subject of a request.
|
| SubjectContextImpersonatingPrincipalLookupFunction |
A function that returns the impersonating principal name from a SubjectContext.
|
| SubjectContextPrincipalLookupFunction |
|
| SubjectDataConnector |
|
| SubjectDataConnectorParser |
|
| SubjectDerivedAttributeDefinitionParser |
Spring Bean Definition Parser for attribute definitions derived from the Principal.
|
| SubjectDerivedAttributeValuesFunction |
|
| SubStatusCodeAuditExtractor |
Function that returns the lower-level StatusCode(s) from a response.
|
| SuppressAuthenticatingAuthorityPredicate |
|
| TemplateAttributeDefinition |
An attribute definition that constructs its values based on the values of its dependencies using the Velocity
Template Language.
|
| TemplateAttributeDefinitionParser |
Spring bean definition parser for templated attribute definition elements.
|
| TemplatedBodyBuilder |
|
| TemplatedExecutableSearchFilterBuilder |
Deprecated.
|
| TemplatedExecutableSearchFilterBuilder |
|
| TemplatedExecutableSearchFilterBuilder.EscapingReferenceInsertionEventHandler |
Escapes LDAP attribute values added to the template context.
|
| TemplatedExecutableStatementBuilder |
Deprecated.
|
| TemplatedExecutableStatementBuilder |
|
| TemplatedExecutableStatementBuilder.EscapingReferenceInsertionEventHandler |
Escapes SQL values added to the template context.
|
| TemplatedSearchBuilder |
|
| TemplatedURLBuilder |
|
| TemplateSearchDnResolver |
|
| Ticket |
Generic CAS ticket that has a natural identifier and expiration.
|
| TicketContext |
IdP context that stores a granted CAS ticket.
|
| TicketIdentifierGenerationStrategy |
Generates CAS protocol ticket identifiers of the form:
|
| TicketIdGenerator |
Strategy for ticket generation.
|
| TicketLookupFunction |
Looks up the service (proxy) ticket provided in a CAS protocol request or produced in a CAS protocol response.
|
| TicketPrincipalLookupFunction |
|
| TicketService |
CAS ticket management service.
|
| TicketState |
Supplemental state data to be stored with a ticket.
|
| TicketValidationRequest |
Ticket validation request message.
|
| TicketValidationResponse |
Service ticket validation response protocol message.
|
| TLSSocketFactoryFactoryBean |
A factory bean for producing instances of LayeredConnectionSocketFactory for use in HttpClient.
|
| TOTPPrincipal |
Principal based on a TOTP authentication.
|
| TranscoderSupport |
|
| TranscodingRule |
Wrapper around a Map representing a rule for transcoding, used to
detect and load the rules at runtime from a Spring context.
|
| TranscodingRuleLoader |
A mechanism for loading a set of TranscodingRule objects from sources such as maps
or directories of property files.
|
| TransformedUsernameAuditExtractor |
|
| TransformingNameIDDecoder |
|
| TransformingNameIdentifierDecoder |
|
| TransientIdGenerationStrategy |
Generates and manages transient identifiers according to specific strategies.
|
| TransientIdParameters |
The Parameters we need to store in, and get out of a transient ID, namely the attribute recipient (aka the SP) and
the principal.
|
| TransientNameIDDecoder |
|
| TransientNameIdentifierDecoder |
|
| TransientSAML1NameIdentifierGenerator |
|
| TransientSAML2NameIDGenerator |
Generator for transient NameID objects.
|
| TransitionMultiFactorAuthentication |
An authentication action that acts as the driver regulating execution of transitions
between MFA stages.
|
| TrustStore |
Code to handle (load, update, check) the trust store for an individual plugin.
|
| TrustStore.Signature |
An opaque handle around a PGPSignature.
|
| UIInfoNodeProcessor |
|
| UnlockDataSealers |
Action that sets keystore and key passwords for one or more DataSealer KeyStrategy
objects based on query parameters.
|
| UnlockKeys |
|
| UnlockPrivateKeys |
Action that creates private key objects and injects them into existing
MutableCredential objects.
|
| UnsupportedAttributeTypeException |
Exception thrown when a particular IdPAttributeValue type was expected but a
different one was encountered.
|
| UpdateCounter |
Consent action which maintains a storage record whose value is the current time in milliseconds.
|
| UpdateIdPSessionWithSPSessionAction<RequestType,ResponseType> |
|
| UpdateSAMLSelfEntityContext |
Action that updates inbound and/or outbound instances of SAMLSelfEntityContext
based on the identity of a relying party accessed via a lookup strategy,
by default an immediate child of the profile request context.
|
| UpdateSessionWithAuthenticationResult |
An authentication action that establishes a record of the AuthenticationResult
in an IdPSession for the client, either by updating an existing session or creating a new one.
|
| UpdateSessionWithSPSession |
|
| UserAgentContext |
A context containing data about the user agent.
|
| UsernameContext |
Context that carries a username (without a password) to be validated.
|
| UsernamePasswordContext |
Context that carries a username/password pair to be validated.
|
| UsernamePrincipal |
Principal based on a username.
|
| V2CompatibleTemplatedExecutableSearchFilterBuilder |
|
| V2CompatibleTemplatedExecutableStatementBuilder |
|
| V2SAMLProfileRequestContext |
Emulation code for Scripted Attributes.
|
| V4Install |
Code to do most of the V4 Install.
|
| V4InstallTask |
A thin veneer around the V4 installer.
|
| ValidateConfiguration |
CAS protocol configuration.
|
| ValidateCredentials |
|
| ValidateCredentials.UsernamePasswordCleanupHook |
|
| ValidateDuoAuthAPI |
|
| ValidateDuoWebResponse |
An action that validates a DuoWeb response message and produces an
AuthenticationResult or records error state.
|
| ValidateExternalAuthentication |
|
| ValidateExternalAuthentication.CertificateCleanupHook |
|
| ValidateFunctionResult |
An action that executes a deployer-supplied function and produces an
AuthenticationResult based on the function result.
|
| ValidateProxyCallbackAction |
Validates the proxy callback URL provided in the service ticket validation request and creates a PGT when
the proxy callback is successfully authenticated.
|
| ValidateRemoteUser |
|
| ValidateRenewAction |
Ensures that a service ticket validation request that specifies renew=true matches the renew flag on the ticket
that is presented for validation.
|
| ValidateSAMLAuthentication |
|
| ValidateTicketAction |
CAS protocol service ticket validation action.
|
| ValidateUserAgentAddress |
|
| ValidationException |
Exception thrown by Validators when validation fails.
|
| Validator |
Used to determine whether a Data Connector initialized properly and continues to be fit for use.
|
| ValueMap |
Performs many to one mapping of source values to a return value.
|
| ValueMapParser |
|
| ValueMatchesShibMDScopeParser |
|
| VerifiedProfilePredicate |
Predicate to determine whether a profile request is from a verified source.
|
| Version |
Class for getting and printing the version of the IdP.
|
| Warning |
|
| WebFlowCurrentEventLookupFunction |
A Function that checks for cases in which the webflow's current event is not reflected by
an attached EventContext and compensates, along with returning a suitably populated context.
|
| WebFlowMessageHandlerAdaptor |
|
| WebFlowMessageHandlerAdaptor.Direction |
Used to indicate the target message context for invocation of the adapted message handler.
|
| WebFlowProfileActionAdaptor |
Adaptor that wraps a ProfileAction with a Spring Web Flow compatible action implementation
so that it can be executed as part of a flow.
|
| WebflowRequestContextProfileRequestContextLookup |
|
| WriteAuditLog |
Action that produces audit log entries based on an AuditContext and one or more formatting strings.
|
| WriteFTICKSLog |
Action that produces F-TICKS log entries for successful SAML SSO responses.
|
| WriteProfileInterceptorResultToStorage |
|
| WriteValidateResponseAction |
CAS 1.0 protocol response handler.
|
| X500PrincipalSerializer |
|
| X500SubjectCanonicalization |
|
| X500SubjectCanonicalization.ActivationCondition |
A predicate that determines if this action can run or not.
|
| X509 |
|
| X509AuthServlet |
Servlet compatible with the ExternalAuthentication interface that extracts and validates
an X.509 client certificate for user authentication.
|
| X509CertificateCredentialValidator |
A credential validator that validates an X.509 certificate.
|
| X509InlineCredentialFactoryBean |
A factory bean to understand X509Inline credentials.
|
| X509InlineCredentialParser |
Parser for X509Inline credentials.
|
| X509ProxyFilter |
Servlet filter to translate Apache mod_ssl certificate variables into Java servlet attributes.
|
| X509ResourceCredentialConfig |
|
| X509ResourceCredentialParser |
Parser for X509Filesystem credentials.
|
| XMLObjectAttributeValue |
|
| XMLObjectProviderInitializer |
XMLObject provider initializer for providers from OpenLiberty used in delegation.
|
| XMLObjectProviderInitializer |
XMLObject provider initializer for module "saml-impl".
|