Interface DuoOIDCIntegration

All Superinterfaces:
PrincipalSupportingComponent
All Known Subinterfaces:
DynamicDuoOIDCIntegration
All Known Implementing Classes:
DefaultDuoOIDCIntegration, SimpleDuoOIDCIntegration

public interface DuoOIDCIntegration extends PrincipalSupportingComponent
Interface to a particular Duo OIDC integration point. In part replaces OIDC metadata, as that is not supported by Duo. Implementations must override the equality and hashcode methods appropriately (e.g., using the clientId as the object's identity).
  • Method Details

    • getAPIHost

      @Nonnull @NotEmpty String getAPIHost()
      Get the name of the API host to contact.
      Returns:
      name of API host
    • getClientId

      @Nonnull @NotEmpty String getClientId()
      Get the clientId key.
      Returns:
      the integration key
    • getSecretKey

      @Nonnull @NotEmpty String getSecretKey()
      Get the secret key.
      Returns:
      the secret key
    • getRedirectURI

      @Nullable String getRedirectURI()
      Get the runtime redirectURI to direct the client to after authorisation.
      Returns:
      the redirectURI
    • getHealthCheckEndpoint

      @Nonnull @NotEmpty String getHealthCheckEndpoint()
      Get the path of the health check endpoint.
      Returns:
      the path of the health check endpoint
    • getAuthorizeEndpoint

      @Nonnull @NotEmpty String getAuthorizeEndpoint()
      Get the path of the authorization endpoint.
      Returns:
      the path of the authorization endpoint
    • getTokenEndpoint

      @Nonnull @NotEmpty String getTokenEndpoint()
      Get the path of the token endpoint.
      Returns:
      the path of the token endpoint;
    • isPasswordless

      default boolean isPasswordless()
      Gets whether the integration is suitable for use as a passwordless single factor.

      Defaults to false.

      Returns:
      true iff the integration limits methods to passwordless
      Since:
      2.1.0
    • getAllowedFactors

      @Nullable @NonnullElements @Unmodifiable @NotLive default Set<String> getAllowedFactors()
      Gets the set of allowable factors to enforce during validation.
      Returns:
      allowable factors, or null for any
      Since:
      2.1.0
    • getContextToPrincipalMappingStrategy

      @Nullable default Function<ProfileRequestContext,Collection<Principal>> getContextToPrincipalMappingStrategy()
      Get a context to principal mapping strategy for mapping context information into principal collections to insert into Subject.
      Returns:
      the mapping hook or null
      Since:
      2.1.0