Class ValidateTokenClaims
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.authn.AbstractAuthenticationAction
net.shibboleth.idp.plugin.authn.duo.AbstractDuoAuthenticationAction
net.shibboleth.idp.plugin.authn.duo.impl.ValidateTokenClaims
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
Action that validates the claims of the Duo id_token using the supplied
ClaimsValidator.
The verifier must be thread-safe and validate the claims set against the OpenID Connect
core 1.0 section 3.1.3.7 specification and those required by Duo.- Event:
EventIds.PROCEED_EVENT_ID,AuthnEventIds.AUTHN_EXCEPTION,AuthnEventIds.NO_CREDENTIALS- Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null,AuthenticationContext.getSubcontext(DuoOIDCAuthenticationContext.class, false) != null,DuoOIDCAuthenticationContext.getAuthToken() != null,DuoOIDCAuthenticationContext.getIntegration() != null
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic classA cleanup hook that removes the 'nonce' parameter from theDuoOIDCAuthenticationContextso it could not be reused. -
Field Summary
FieldsModifier and TypeFieldDescriptionprivate com.nimbusds.jwt.JWTClaimsSetThe parsed claimset.private ClaimsValidatorThe JWT claims validator used to verify the claimsset.private Consumer<ProfileRequestContext>A cleanup hook to execute after either a successful or unsuccessful claims validation.private final org.slf4j.LoggerClass logger. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext, DuoOIDCAuthenticationContext duoContext) Performs this Duo authentication action using the supplied Duo context.protected voidprotected booleandoPreExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext, DuoOIDCAuthenticationContext duoContext) Performs this authentication action's pre-execute step.voidsetClaimsValidator(ClaimsValidator validator) Set the JWT claims verifier to use.voidSet the cleanup hook to execute after either a successful or unsuccessful claims validation.Methods inherited from class net.shibboleth.idp.plugin.authn.duo.AbstractDuoAuthenticationAction
doExecute, doPreExecute, setDuoContextLookupStrategyMethods inherited from class net.shibboleth.idp.authn.AbstractAuthenticationAction
doExecute, doPreExecute, setAuthenticationContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
claimsSet
The parsed claimset. -
cleanupHook
A cleanup hook to execute after either a successful or unsuccessful claims validation. -
claimsValidator
The JWT claims validator used to verify the claimsset.
-
-
Constructor Details
-
ValidateTokenClaims
public ValidateTokenClaims()
-
-
Method Details
-
doInitialize
- Overrides:
doInitializein classAbstractInitializableComponent- Throws:
ComponentInitializationException
-
setCleanupHook
Set the cleanup hook to execute after either a successful or unsuccessful claims validation.- Parameters:
hook- cleanup hook
-
setClaimsValidator
Set the JWT claims verifier to use.- Parameters:
validator- the claims validator.
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext) Performs this authentication action's pre-execute step. Default implementation just returns true.- Overrides:
doPreExecutein classAbstractDuoAuthenticationAction- Parameters:
profileRequestContext- the current IdP profile request contextauthenticationContext- the current authentication contextduoContext- the Duo authentication context- Returns:
- true iff execution should continue
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext) Performs this Duo authentication action using the supplied Duo context. Implementations should override this method.- Overrides:
doExecutein classAbstractDuoAuthenticationAction- Parameters:
profileRequestContext- the current IdP profile request contextauthenticationContext- the current authentication contextduoContext- the Duo authentication context
-