Class ValidateTokenSignature

All Implemented Interfaces:
Component, DestructableComponent, InitializableComponent, ProfileAction, Aware, MessageSource, MessageSourceAware, Action

public class ValidateTokenSignature extends AbstractDuoAuthenticationAction
Action to validate the JWT signature. The JWT **must** be signed using the HMAC_SHA family, any other type, including 'none', emits an error back to the flow.
Event:
AuthnEventIds.NO_CREDENTIALS, AuthnEventIds.INVALID_AUTHN_CTX, AuthnEventIds.AUTHN_EXCEPTION
Precondition:
      ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null
      
,
      AuthenticationContext.getSubcontext(DuoOIDCAuthenticationContext.class, false) != null
      
  • Field Details

    • SUPPORTED_SIGNATURE_FAMILY

      @Nonnull private static final com.nimbusds.jose.JWSAlgorithm.Family SUPPORTED_SIGNATURE_FAMILY
      The HMAC 'family' of signature algorithms is the only supported, based on the shared secret in the client integration.
    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
    • signatureAlgorithm

      @Nonnull private com.nimbusds.jose.Algorithm signatureAlgorithm
      The signature algorithm used. This is fixed and not taken from the JWS. There is no reason, in the Duo case, to determine the algorithm from the JWS as HS512 is the only required algorithm.
    • token

      @NonnullBeforeExec private com.nimbusds.jwt.JWT token
      The Duo authentication token.
    • claimSet

      @NonnullBeforeExec private com.nimbusds.jwt.JWTClaimsSet claimSet
      The parsed claimset.
    • integration

      The Duo integration appropriate for this request.
  • Constructor Details

    • ValidateTokenSignature

      public ValidateTokenSignature()
      Constructor.
  • Method Details

    • setSignatureAlgorithm

      public void setSignatureAlgorithm(@Nonnull com.nimbusds.jose.JWSAlgorithm algo)
      Set the signature algorithm to use. Only supports one of the HMAC_SHA family.
      Parameters:
      algo - the JWS signature algorithm.
    • doPreExecute

      protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext)
      Description copied from class: AbstractDuoAuthenticationAction
      Performs this authentication action's pre-execute step. Default implementation just returns true.
      Overrides:
      doPreExecute in class AbstractDuoAuthenticationAction
      Parameters:
      profileRequestContext - the current IdP profile request context
      authenticationContext - the current authentication context
      duoContext - the Duo authentication context
      Returns:
      true iff execution should continue
    • doExecute

      protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext)
      Performs this Duo authentication action using the supplied Duo context. Implementations should override this method.
      Overrides:
      doExecute in class AbstractDuoAuthenticationAction
      Parameters:
      profileRequestContext - the current IdP profile request context
      authenticationContext - the current authentication context
      duoContext - the Duo authentication context