Class UnwrapGrant
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractOIDCRequestAction<com.nimbusds.oauth2.sdk.TokenRequest>
net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractOIDCTokenRequestAction
net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractOIDCTokenResponseAction
net.shibboleth.idp.plugin.oidc.op.profile.impl.UnwrapGrant
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
Action that unwraps an authorization grant or refresh token grant.
Operation is valid if it is successfully unwrapped, parsed as a code or refresh token, is unexpired and was issued to the expected client.
The claims set from the grant is stored to response context via
OIDCAuthenticationResponseContext.setAuthorizationGrantClaimsSet(TokenClaimsSet).
Note that the addition of support for the "client_credentials" grant type means that there may not in fact be a grant, or resulting claims set.
- Since:
- 4.4.0
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate Function<MessageContext,com.nimbusds.oauth2.sdk.id.ClientID> Strategy used to obtain the client id value from token request.private final DataSealerData sealer for unwrapping authorization code.private org.slf4j.LoggerClass logger.List of deserializer bi-functions for refresh tokens to be used in addition to unsealing opaque value. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected RefreshTokenClaimsSetdeserializeRefreshToken(ProfileRequestContext profileRequestContext, String refreshToken) Attempt to deseriaalize a (serialized) refresh token value via configured deserializers.protected voiddoExecute(ProfileRequestContext profileRequestContext) voidsetClientIDLookupStrategy(Function<MessageContext, com.nimbusds.oauth2.sdk.id.ClientID> strategy) Set the strategy used to locate the client id of the request.voidsetRefreshTokenDeserializers(List<BiFunction<ProfileRequestContext, String, RefreshTokenClaimsSet>> deserializers) Set the list of deserializer bi-functions for refresh tokens to be used in addition to unsealing opaque value.Methods inherited from class net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractOIDCTokenResponseAction
doPreExecute, getMetadataContext, getOidcResponseContextMethods inherited from class net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractOIDCTokenRequestAction
getTokenRequestMethods inherited from class net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractOIDCRequestAction
getRequestMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, doInitialize, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private org.slf4j.Logger logClass logger. -
dataSealer
Data sealer for unwrapping authorization code. -
clientIDLookupStrategy
@Nonnull private Function<MessageContext,com.nimbusds.oauth2.sdk.id.ClientID> clientIDLookupStrategyStrategy used to obtain the client id value from token request. -
refreshTokenDeserializers
@Nonnull private List<BiFunction<ProfileRequestContext,String, refreshTokenDeserializersRefreshTokenClaimsSet>> List of deserializer bi-functions for refresh tokens to be used in addition to unsealing opaque value.
-
-
Constructor Details
-
Method Details
-
setRefreshTokenDeserializers
public void setRefreshTokenDeserializers(@Nonnull List<BiFunction<ProfileRequestContext, String, RefreshTokenClaimsSet>> deserializers) Set the list of deserializer bi-functions for refresh tokens to be used in addition to unsealing opaque value.- Parameters:
deserializers- list of deserializers
-
setClientIDLookupStrategy
public void setClientIDLookupStrategy(@Nonnull Function<MessageContext, com.nimbusds.oauth2.sdk.id.ClientID> strategy) Set the strategy used to locate the client id of the request.- Parameters:
strategy- lookup strategy
-
doExecute
- Overrides:
doExecutein classAbstractProfileAction
-
deserializeRefreshToken
protected RefreshTokenClaimsSet deserializeRefreshToken(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull String refreshToken) Attempt to deseriaalize a (serialized) refresh token value via configured deserializers.- Parameters:
profileRequestContext- The profile request context given to the deserializersrefreshToken- The serialized refresh token value- Returns:
- refresh token claims set, or null if it couldn't be parsed
-