Class DuoSDKClientAdaptor

    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Class logger.
      • client

        @Nonnull
        private final com.duosecurity.Client client
        The wrapped Duo native client.
      • healthCheckResponseConverter

        @Nonnull
        private final Function<com.duosecurity.model.HealthCheckResponse,​DuoHealthCheck> healthCheckResponseConverter
        Function to map the native Duo HealthCheckResponse object to the interface DuoHealthCheck object.
      • tokenResponseConverter

        @Nonnull
        private final BiFunction<com.duosecurity.model.Token,​DuoOIDCIntegration,​com.nimbusds.jwt.JWT> tokenResponseConverter
        Function to map the native Duo Token object to the interface JWT object.
      • duoIntegration

        @Nonnull
        private final DuoOIDCIntegration duoIntegration
        Save off the integration to help generate the JWT.
    • Constructor Detail

      • DuoSDKClientAdaptor

        DuoSDKClientAdaptor​(@Nonnull
                            DuoOIDCIntegration integration,
                            @Nullable
                            List<String> caCerts)
                     throws DuoClientException
        Package-private constructor. Initialises the native Duo SDK client.

        Should only be instantiated by the DuoSDKClientFactory.

        Parameters:
        integration - the Duo integration to initialize the client from. Never null.
        caCerts - the list of CA Certificates used to validate connections to Duo. Can be null.
        Throws:
        DuoClientException - if there is an error instantiating the client
    • Method Detail

      • healthCheck

        @Nonnull
        public DuoHealthCheck healthCheck()
                                   throws DuoClientException
        Check the health of the Duo 2FA endpoint and the clients configuration.
        Returns:
        the heath check response, never null.
        Throws:
        DuoClientException - if there is an error returning the health check response.
      • createAuthUrl

        @Nonnull
        public String createAuthUrl​(@Nonnull @NotEmpty
                                    String username,
                                    @Nonnull @NotEmpty
                                    String state,
                                    @Nullable
                                    String nonce,
                                    @Nullable
                                    String redirectURIOverride)
                             throws DuoClientException
        Constructs an authorization redirection URL string with the query parameters required to initiate a Duo 2FA request.

        The Duo WebSDK Client does not support either the nonce or redirectURIOverride parameters.

        Parameters:
        username - The user to be authenticated by Duo, never null.
        state - A randomly generated minimum 22 character String, which is relayed back to the client, never null.
        nonce - a randomly generated (minimum 22 character) cryptographically secure nonce that is replayed in the id_token. Can be null if not supported by the client as indicated by the clients described capabilities.
        redirectURIOverride - the redirectURI to use in the authorization request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
        Returns:
        the authorization redirect URL as a string, never null.
        Throws:
        DuoClientException - if there is an error creating the authentication URL.
      • exchangeAuthorizationCodeFor2FAResult

        @Nonnull
        public com.nimbusds.jwt.JWT exchangeAuthorizationCodeFor2FAResult​(@Nonnull
                                                                          String code,
                                                                          @Nonnull
                                                                          String username,
                                                                          @Nullable
                                                                          String redirectURIOverride)
                                                                   throws DuoClientException
        Exchanges the authorizaton code for a signed Json Web Token (JWT) which contains information pertaining to the authentication. There is no requirement on the client to verify the tokens authenticity or claims - these should be performed elsewhere in the flow. The JWT **must** be signed.

        The Duo WebSDK Client does not support the redirectURIOverride parameter.

        Parameters:
        code - An authentication identifier which is exchanged (per OAuth2.0 spec) with Duo for a token. the token can be used to determine if authentication was successful as well as obtain meta-data about the authentication, never null. *
        username - The user to be authenticated by Duo, never null.
        redirectURIOverride - the redirectURI to use in the code exchange request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
        Returns:
        the **signed** JWT, never null.
        Throws:
        DuoClientException - if there is an error exchanging the auth_code for a token result.
      • isSupportsNonce

        public boolean isSupportsNonce()
        Description copied from interface: DuoOIDCClientCapabilities

        Does this client support the OIDC nonce parameter.

        If the client does support a nonce, it must be included by the client in the authorisation request URL, where it must then be returned by the provider in the id_token as part of the 2FA result.

        Returns:
        true iff the client supports the nonce parameter, false otherwise.