Class NimbusClient

    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Class logger.
      • duoIntegration

        @Nonnull
        private final DuoOIDCIntegration duoIntegration
        The integration to help generate the JWT.
      • httpClient

        @Nonnull
        private final org.apache.http.client.HttpClient httpClient
        HttpClient for contacting Duo.
      • httpClientSecurityParameters

        @Nullable
        private final HttpClientSecurityParameters httpClientSecurityParameters
        HTTP client security parameters.
      • objectMapper

        @Nonnull
        private final com.fasterxml.jackson.databind.ObjectMapper objectMapper
        JSON object mapper.
    • Constructor Detail

      • NimbusClient

        NimbusClient​(@Nonnull
                     DuoOIDCIntegration integration,
                     @Nonnull
                     org.apache.http.client.HttpClient client,
                     @Nullable
                     HttpClientSecurityParameters params,
                     @Nonnull
                     com.fasterxml.jackson.databind.ObjectMapper oMapper)
        Package-private Constructor.

        Should only be instantiated by the NimbusClientFactory.

        Parameters:
        integration - the integration to create the client for, never null
        client - the Http client to use to execute HTTP requests, never null
        params - any security parameters to use for the Http client, can be null.
        oMapper - the JSON object mapper, never null.
    • Method Detail

      • healthCheck

        @Nonnull
        public DuoHealthCheck healthCheck()
                                   throws DuoClientException
        Description copied from interface: DuoOIDCClient
        Check the health of the Duo 2FA endpoint and the clients configuration.
        Returns:
        the heath check response, never null.
        Throws:
        DuoClientException - if there is an error returning the health check response.
      • createAuthUrl

        @Nonnull
        public String createAuthUrl​(@Nonnull @NotEmpty
                                    String username,
                                    @Nonnull @NotEmpty
                                    String state,
                                    @Nullable
                                    String nonce,
                                    @Nullable
                                    String redirectURIOverride)
                             throws DuoClientException
        Description copied from interface: DuoOIDCClient
        Constructs an authorization redirection URL string with the query parameters required to initiate a Duo 2FA request.
        Parameters:
        username - The user to be authenticated by Duo, never null.
        state - A randomly generated minimum 22 character String, which is relayed back to the client, never null.
        nonce - a randomly generated (minimum 22 character) cryptographically secure nonce that is replayed in the id_token. Can be null if not supported by the client as indicated by the clients described capabilities.
        redirectURIOverride - the redirectURI to use in the authorization request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
        Returns:
        the authorization redirect URL as a string, never null.
        Throws:
        DuoClientException - if there is an error creating the authentication URL.
      • exchangeAuthorizationCodeFor2FAResult

        public com.nimbusds.jwt.JWT exchangeAuthorizationCodeFor2FAResult​(@Nonnull
                                                                          String code,
                                                                          @Nonnull
                                                                          String username,
                                                                          @Nullable
                                                                          String redirectURIOverride)
                                                                   throws DuoClientException
        Description copied from interface: DuoOIDCClient
        Exchanges the authorizaton code for a signed Json Web Token (JWT) which contains information pertaining to the authentication. There is no requirement on the client to verify the tokens authenticity or claims - these should be performed elsewhere in the flow. The JWT **must** be signed.
        Parameters:
        code - An authentication identifier which is exchanged (per OAuth2.0 spec) with Duo for a token. the token can be used to determine if authentication was successful as well as obtain meta-data about the authentication, never null. *
        username - The user to be authenticated by Duo, never null.
        redirectURIOverride - the redirectURI to use in the code exchange request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
        Returns:
        the **signed** JWT, never null.
        Throws:
        DuoClientException - if there is an error exchanging the auth_code for a token result.
      • executeRequest

        private <T> T executeRequest​(@Nonnull
                                     org.apache.http.client.methods.HttpUriRequest request,
                                     @Nonnull
                                     com.fasterxml.jackson.core.type.TypeReference<T> wrapperTypeRef)
                              throws DuoClientException
        Performs a call to a Duo OIDC endpoint. Iff successful, the JSON response is mapped into the appropriate type.
        Type Parameters:
        T - the response type
        Parameters:
        request - the prepared HTTP request
        wrapperTypeRef - the type to deserialise the JSON into
        Returns:
        the response type, never null.
        Throws:
        DuoClientException - if there is an error producing a response
      • isSupportsNonce

        public boolean isSupportsNonce()
        Description copied from interface: DuoOIDCClientCapabilities

        Does this client support the OIDC nonce parameter.

        If the client does support a nonce, it must be included by the client in the authorisation request URL, where it must then be returned by the provider in the id_token as part of the 2FA result.

        Returns:
        true iff the client supports the nonce parameter, false otherwise.