Class ValidateTokenSignature
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.authn.AbstractAuthenticationAction
net.shibboleth.idp.plugin.authn.duo.AbstractDuoAuthenticationAction
net.shibboleth.idp.plugin.authn.duo.impl.ValidateTokenSignature
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
Action to validate the JWT signature. The JWT **must** be signed using the HMAC_SHA family,
any other type, including 'none', emits an error back to the flow.
- Event:
AuthnEventIds.NO_CREDENTIALS,AuthnEventIds.INVALID_AUTHN_CTX,AuthnEventIds.AUTHN_EXCEPTION- Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null,AuthenticationContext.getSubcontext(DuoOIDCAuthenticationContext.class, false) != null
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate com.nimbusds.jwt.JWTClaimsSetThe parsed claimset.private DuoOIDCIntegrationThe Duo integration appropriate for this request.private final org.slf4j.LoggerClass logger.private com.nimbusds.jose.AlgorithmThe signature algorithm used.private static final com.nimbusds.jose.JWSAlgorithm.FamilyThe HMAC 'family' of signature algorithms is the only supported, based on the shared secret in the client integration.private com.nimbusds.jwt.JWTThe Duo authentication token. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext, DuoOIDCAuthenticationContext duoContext) Performs this Duo authentication action using the supplied Duo context.protected booleandoPreExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext, DuoOIDCAuthenticationContext duoContext) Performs this authentication action's pre-execute step.voidsetSignatureAlgorithm(com.nimbusds.jose.JWSAlgorithm algo) Set the signature algorithm to use.Methods inherited from class net.shibboleth.idp.plugin.authn.duo.AbstractDuoAuthenticationAction
doExecute, doPreExecute, setDuoContextLookupStrategyMethods inherited from class net.shibboleth.idp.authn.AbstractAuthenticationAction
doExecute, doPreExecute, setAuthenticationContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, doInitialize, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
SUPPORTED_SIGNATURE_FAMILY
@Nonnull private static final com.nimbusds.jose.JWSAlgorithm.Family SUPPORTED_SIGNATURE_FAMILYThe HMAC 'family' of signature algorithms is the only supported, based on the shared secret in the client integration. -
log
@Nonnull private final org.slf4j.Logger logClass logger. -
signatureAlgorithm
@Nonnull private com.nimbusds.jose.Algorithm signatureAlgorithmThe signature algorithm used. This is fixed and not taken from the JWS. There is no reason, in the Duo case, to determine the algorithm from the JWS as HS512 is the only required algorithm. -
token
The Duo authentication token. -
claimSet
The parsed claimset. -
integration
The Duo integration appropriate for this request.
-
-
Constructor Details
-
ValidateTokenSignature
public ValidateTokenSignature()Constructor.
-
-
Method Details
-
setSignatureAlgorithm
public void setSignatureAlgorithm(@Nonnull com.nimbusds.jose.JWSAlgorithm algo) Set the signature algorithm to use. Only supports one of the HMAC_SHA family.- Parameters:
algo- the JWS signature algorithm.
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext) Description copied from class:AbstractDuoAuthenticationActionPerforms this authentication action's pre-execute step. Default implementation just returns true.- Overrides:
doPreExecutein classAbstractDuoAuthenticationAction- Parameters:
profileRequestContext- the current IdP profile request contextauthenticationContext- the current authentication contextduoContext- the Duo authentication context- Returns:
- true iff execution should continue
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext, @Nonnull DuoOIDCAuthenticationContext duoContext) Performs this Duo authentication action using the supplied Duo context. Implementations should override this method.- Overrides:
doExecutein classAbstractDuoAuthenticationAction- Parameters:
profileRequestContext- the current IdP profile request contextauthenticationContext- the current authentication contextduoContext- the Duo authentication context
-