Class DuoSDKClientAdaptor

java.lang.Object
net.shibboleth.idp.plugin.authn.duo.AbstractDuoOIDCClient
net.shibboleth.idp.plugin.authn.duo.sdk.impl.DuoSDKClientAdaptor
All Implemented Interfaces:
DuoOIDCClient, DuoOIDCClientCapabilities

@ThreadSafe @Immutable public final class DuoSDKClientAdaptor extends AbstractDuoOIDCClient

An Object Adaptor class for bridging between the Duo SDK implementation and the internal DuoOIDCClient interface.

  • Field Details

    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
    • client

      @Nonnull private final com.duosecurity.Client client
      The wrapped Duo native client.
    • healthCheckResponseConverter

      @Nonnull private final Function<com.duosecurity.model.HealthCheckResponse,DuoHealthCheck> healthCheckResponseConverter
      Function to map the native Duo HealthCheckResponse object to the interface DuoHealthCheck object.
    • tokenResponseConverter

      @Nonnull private final BiFunction<com.duosecurity.model.Token,DuoOIDCIntegration,com.nimbusds.jwt.JWT> tokenResponseConverter
      Function to map the native Duo Token object to the interface JWT object.
    • duoIntegration

      @Nonnull private final DuoOIDCIntegration duoIntegration
      Save off the integration to help generate the JWT.
  • Constructor Details

    • DuoSDKClientAdaptor

      DuoSDKClientAdaptor(@Nonnull DuoOIDCIntegration integration, @Nullable List<String> caCerts) throws DuoClientException
      Package-private constructor. Initialises the native Duo SDK client.

      Should only be instantiated by the DuoSDKClientFactory.

      Parameters:
      integration - the Duo integration to initialize the client from. Never null.
      caCerts - the list of CA Certificates used to validate connections to Duo. Can be null.
      Throws:
      DuoClientException - if there is an error instantiating the client
    • DuoSDKClientAdaptor

      DuoSDKClientAdaptor(@Nonnull DuoOIDCIntegration integration, @Nullable List<String> caCerts, @Nonnull @NotEmpty String proxyHost, @Nonnull Integer proxyPort) throws DuoClientException
      Package-private constructor. Initialises the native Duo SDK client.

      Should only be instantiated by the DuoSDKClientFactory.

      Parameters:
      integration - the Duo integration to initialize the client from. Never null.
      caCerts - the list of CA Certificates used to validate connections to Duo. Can be null.
      proxyHost - the HTTP proxy host.
      proxyPort - the HTTP proxy port.
      Throws:
      DuoClientException - if there is an error instantiating the client
      Since:
      2.2.0
    • DuoSDKClientAdaptor

      DuoSDKClientAdaptor(@Nonnull com.duosecurity.Client injectedClient, @Nonnull DuoOIDCIntegration integration)
      Package-private constructor used primarily for testing. Uses the injected Duo client.
      Parameters:
      injectedClient - the Duo client to use in this adaptor.
      integration - the Duo integration to store off.
  • Method Details

    • healthCheck

      @Nonnull public DuoHealthCheck healthCheck() throws DuoClientException
      Check the health of the Duo 2FA endpoint and the clients configuration.
      Returns:
      the heath check response, never null.
      Throws:
      DuoClientException - if there is an error returning the health check response.
    • createAuthUrl

      @Nonnull public String createAuthUrl(@Nonnull @NotEmpty String username, @Nonnull @NotEmpty String state, @Nullable String nonce, @Nullable String redirectURIOverride) throws DuoClientException
      Constructs an authorization redirection URL string with the query parameters required to initiate a Duo 2FA request.

      The Duo WebSDK Client does not support either the nonce or redirectURIOverride parameters.

      Parameters:
      username - The user to be authenticated by Duo, never null.
      state - A randomly generated minimum 22 character String, which is relayed back to the client, never null.
      nonce - a randomly generated (minimum 22 character) cryptographically secure nonce that is replayed in the id_token. Can be null if not supported by the client as indicated by the clients described capabilities.
      redirectURIOverride - the redirectURI to use in the authorization request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
      Returns:
      the authorization redirect URL as a string, never null.
      Throws:
      DuoClientException - if there is an error creating the authentication URL.
    • exchangeAuthorizationCodeFor2FAResult

      @Nonnull public com.nimbusds.jwt.JWT exchangeAuthorizationCodeFor2FAResult(@Nonnull String code, @Nonnull String username, @Nullable String redirectURIOverride) throws DuoClientException
      Exchanges the authorizaton code for a signed Json Web Token (JWT) which contains information pertaining to the authentication. There is no requirement on the client to verify the tokens authenticity or claims - these should be performed elsewhere in the flow. The JWT **must** be signed.

      The Duo WebSDK Client does not support the redirectURIOverride parameter.

      Parameters:
      code - An authentication identifier which is exchanged (per OAuth2.0 spec) with Duo for a token. the token can be used to determine if authentication was successful as well as obtain meta-data about the authentication, never null. *
      username - The user to be authenticated by Duo, never null.
      redirectURIOverride - the redirectURI to use in the code exchange request. If not null and the client supports dynamic redirect URIs, it should override any redirect_uri held internally to the client e.g. from the DuoOIDCIntegration. If the client does not support dynamic redirect URIs, it can be ignored in favour of one held internally.
      Returns:
      the **signed** JWT, never null.
      Throws:
      DuoClientException - if there is an error exchanging the auth_code for a token result.
    • isSupportsNonce

      public boolean isSupportsNonce()
      Description copied from interface: DuoOIDCClientCapabilities

      Does this client support the OIDC nonce parameter.

      If the client does support a nonce, it must be included by the client in the authorisation request URL, where it must then be returned by the provider in the id_token as part of the 2FA result.

      Returns:
      true iff the client supports the nonce parameter, false otherwise.