java.lang.Object
net.shibboleth.idp.plugin.authn.duo.AbstractDuoOIDCClient
net.shibboleth.idp.plugin.authn.duo.nimbus.impl.NimbusClient
All Implemented Interfaces:
DuoOIDCClient, DuoOIDCClientCapabilities

@ThreadSafe @Immutable public final class NimbusClient extends AbstractDuoOIDCClient
A Duo client using the Nimbus OIDC library.
  • Field Details

    • CLIENT_ASSERTION_TYPE

      @Nonnull @NotEmpty private static final String CLIENT_ASSERTION_TYPE
      The only supported client assertion type.
      See Also:
    • HTTPS

      @Nonnull @NotEmpty private static final String HTTPS
      The HTTPS scheme.
      See Also:
    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
    • duoIntegration

      @Nonnull private final DuoOIDCIntegration duoIntegration
      The integration to help generate the JWT.
    • httpClient

      @Nonnull private final org.apache.hc.client5.http.classic.HttpClient httpClient
      HttpClient for contacting Duo.
    • httpClientSecurityParameters

      @Nullable private final HttpClientSecurityParameters httpClientSecurityParameters
      HTTP client security parameters.
    • objectMapper

      @Nonnull private final com.fasterxml.jackson.databind.ObjectMapper objectMapper
      JSON object mapper.
  • Constructor Details

    • NimbusClient

      NimbusClient(@Nonnull DuoOIDCIntegration integration, @Nonnull org.apache.hc.client5.http.classic.HttpClient client, @Nullable HttpClientSecurityParameters params, @Nonnull com.fasterxml.jackson.databind.ObjectMapper oMapper)
      Package-private Constructor.

      Should only be instantiated by the NimbusClientFactory.

      Parameters:
      integration - the integration to create the client for, never null
      client - the Http client to use to execute HTTP requests, never null
      params - any security parameters to use for the Http client, can be null.
      oMapper - the JSON object mapper, never null.
  • Method Details

    • healthCheck

      @Nonnull public DuoHealthCheck healthCheck() throws DuoClientException
      Description copied from interface: DuoOIDCClient
      Check the health of the Duo 2FA endpoint and the clients configuration.
      Returns:
      the heath check response, never null.
      Throws:
      DuoClientException - if there is an error returning the health check response.
    • createAuthUrl

      @Nonnull public String createAuthUrl(@Nonnull @NotEmpty String username, @Nonnull @NotEmpty String state, @Nullable String nonce, @Nullable String redirectURIOverride) throws DuoClientException
      Description copied from interface: DuoOIDCClient
      Constructs an authorization redirection URL string with the query parameters required to initiate a Duo 2FA request.
      Parameters:
      username - The user to be authenticated by Duo, never null.
      state - A randomly generated minimum 22 character String, which is relayed back to the client, never null.
      nonce - a randomly generated (minimum 22 character) cryptographically secure nonce that is replayed in the id_token. Can be null if not supported by the client as indicated by the clients described capabilities.
      redirectURIOverride - the redirectURI to use in the authorization request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
      Returns:
      the authorization redirect URL as a string, never null.
      Throws:
      DuoClientException - if there is an error creating the authentication URL.
    • exchangeAuthorizationCodeFor2FAResult

      @Nonnull public com.nimbusds.jwt.JWT exchangeAuthorizationCodeFor2FAResult(@Nonnull String code, @Nonnull String username, @Nullable String redirectURIOverride) throws DuoClientException
      Description copied from interface: DuoOIDCClient
      Exchanges the authorizaton code for a signed Json Web Token (JWT) which contains information pertaining to the authentication. There is no requirement on the client to verify the tokens authenticity or claims - these should be performed elsewhere in the flow. The JWT **must** be signed.
      Parameters:
      code - An authentication identifier which is exchanged (per OAuth2.0 spec) with Duo for a token. the token can be used to determine if authentication was successful as well as obtain meta-data about the authentication, never null. *
      username - The user to be authenticated by Duo, never null.
      redirectURIOverride - the redirectURI to use in the code exchange request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
      Returns:
      the **signed** JWT, never null.
      Throws:
      DuoClientException - if there is an error exchanging the auth_code for a token result.
    • executeRequest

      @Nonnull private <T> T executeRequest(@Nonnull org.apache.hc.core5.http.ClassicHttpRequest request, @Nonnull com.fasterxml.jackson.core.type.TypeReference<T> wrapperTypeRef) throws DuoClientException
      Performs a call to a Duo OIDC endpoint. Iff successful, the JSON response is mapped into the appropriate type.
      Type Parameters:
      T - the response type
      Parameters:
      request - the prepared HTTP request
      wrapperTypeRef - the type to deserialise the JSON into
      Returns:
      the response type, never null.
      Throws:
      DuoClientException - if there is an error producing a response
    • isSupportsNonce

      public boolean isSupportsNonce()
      Description copied from interface: DuoOIDCClientCapabilities

      Does this client support the OIDC nonce parameter.

      If the client does support a nonce, it must be included by the client in the authorisation request URL, where it must then be returned by the provider in the id_token as part of the 2FA result.

      Returns:
      true iff the client supports the nonce parameter, false otherwise.