Class ValidateTokenClaims
- java.lang.Object
-
- net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
-
- org.opensaml.profile.action.AbstractProfileAction
-
- org.opensaml.profile.action.AbstractConditionalProfileAction
-
- net.shibboleth.idp.profile.AbstractProfileAction
-
- net.shibboleth.idp.authn.AbstractAuthenticationAction
-
- net.shibboleth.idp.plugin.authn.duo.AbstractDuoAuthenticationAction
-
- net.shibboleth.idp.plugin.authn.duo.impl.ValidateTokenClaims
-
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class ValidateTokenClaims extends AbstractDuoAuthenticationAction
Action that validates the claims of the Duo id_token using the suppliedClaimsValidator. The verifier must be thread-safe and validate the claims set against the OpenID Connect core 1.0 section 3.1.3.7 specification and those required by Duo.- Event:
EventIds.PROCEED_EVENT_ID,AuthnEventIds.AUTHN_EXCEPTION,AuthnEventIds.NO_CREDENTIALS- Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null,AuthenticationContext.getSubcontext(DuoOIDCAuthenticationContext.class, false) != null,DuoOIDCAuthenticationContext.getAuthToken() != null,DuoOIDCAuthenticationContext.getIntegration() != null
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static classValidateTokenClaims.DuoOIDAuthenticationContextCleanupHookA cleanup hook that removes the 'nonce' parameter from theDuoOIDCAuthenticationContextso it could not be reused.
-
Field Summary
Fields Modifier and Type Field Description private com.nimbusds.jwt.JWTClaimsSetclaimsSetThe parsed claimset.private ClaimsValidatorclaimsValidatorThe JWT claims validator used to verify the claimsset.private Consumer<ProfileRequestContext>cleanupHookA cleanup hook to execute after either a successful or unsuccessful claims validation.private org.slf4j.LoggerlogClass logger.
-
Constructor Summary
Constructors Constructor Description ValidateTokenClaims()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description protected voiddoExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext, DuoOIDCAuthenticationContext duoContext)Performs this Duo authentication action using the supplied Duo context.protected voiddoInitialize()protected booleandoPreExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext, DuoOIDCAuthenticationContext duoContext)Performs this authentication action's pre-execute step.voidsetClaimsValidator(ClaimsValidator validator)Set the JWT claims verifier to use.voidsetCleanupHook(Consumer<ProfileRequestContext> hook)Set the cleanup hook to execute after either a successful or unsuccessful claims validation.-
Methods inherited from class net.shibboleth.idp.plugin.authn.duo.AbstractDuoAuthenticationAction
doExecute, doPreExecute, setDuoContextLookupStrategy
-
Methods inherited from class net.shibboleth.idp.authn.AbstractAuthenticationAction
doExecute, doPreExecute, setAuthenticationContextLookupStrategy
-
Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy
-
Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationCondition
-
Methods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, setHttpServletRequest, setHttpServletRequestSupplier, setHttpServletResponse, setHttpServletResponseSupplier
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, initialize, isDestroyed, isInitialized
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface net.shibboleth.utilities.java.support.component.InitializableComponent
initialize, isInitialized
-
-
-
-
Field Detail
-
log
@Nonnull private final org.slf4j.Logger log
Class logger.
-
claimsSet
@Nullable private com.nimbusds.jwt.JWTClaimsSet claimsSet
The parsed claimset.
-
cleanupHook
@Nullable private Consumer<ProfileRequestContext> cleanupHook
A cleanup hook to execute after either a successful or unsuccessful claims validation.
-
claimsValidator
@NonnullAfterInit private ClaimsValidator claimsValidator
The JWT claims validator used to verify the claimsset.
-
-
Method Detail
-
doInitialize
protected void doInitialize() throws ComponentInitializationException- Overrides:
doInitializein classAbstractInitializableComponent- Throws:
ComponentInitializationException
-
setCleanupHook
public void setCleanupHook(@Nullable Consumer<ProfileRequestContext> hook)Set the cleanup hook to execute after either a successful or unsuccessful claims validation.- Parameters:
hook- cleanup hook
-
setClaimsValidator
public void setClaimsValidator(@Nonnull ClaimsValidator validator)Set the JWT claims verifier to use.- Parameters:
validator- the claims validator.
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext)Performs this authentication action's pre-execute step. Default implementation just returns true.- Overrides:
doPreExecutein classAbstractDuoAuthenticationAction- Parameters:
profileRequestContext- the current IdP profile request contextauthenticationContext- the current authentication contextduoContext- the Duo authentication context- Returns:
- true iff execution should continue
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext)Performs this Duo authentication action using the supplied Duo context. Implementations should override this method.- Overrides:
doExecutein classAbstractDuoAuthenticationAction- Parameters:
profileRequestContext- the current IdP profile request contextauthenticationContext- the current authentication contextduoContext- the Duo authentication context
-
-