Class BuildRequestObject
- java.lang.Object
-
- net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
-
- org.opensaml.profile.action.AbstractProfileAction
-
- org.opensaml.profile.action.AbstractConditionalProfileAction
-
- net.shibboleth.idp.profile.AbstractProfileAction
-
- net.shibboleth.idp.authn.AbstractAuthenticationAction
-
- net.shibboleth.idp.plugin.authn.oidc.rp.impl.BuildRequestObject
-
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class BuildRequestObject extends AbstractAuthenticationAction
Action that creates a Request ObjectJWT, and sets it to the work contextOIDCAuthenticationRequestlocated underInOutOperationContext.getOutboundMessageContext().Note, some parameters are set downstream in the flow before the request object is signed and or encrypted. These parameters are only available to the HTTP Controller e.g. state, and must be set during the external authentication redirect.
- Event:
EventIds.PROCEED_EVENT_ID,EventIds.INVALID_MSG_CTX,EventIds.INVALID_PROFILE_CTX,AuthnEventIds.INVALID_AUTHN_CTX- Precondition:
ProfileRequestContext.getOutboundMessageContext().getMessage() instance of OIDCAuthenticationRequest.class
- Postcondition:
- Add a JWT request object to the in-flight authentication request
-
-
Field Summary
Fields Modifier and Type Field Description private OIDCAuthenticationRequestauthnRequestOIDC authentication request built by the IdP.private Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet>claimsSetIsValidPredicateA hook to allow additional checking of the request object claims after it is built.private org.slf4j.LoggerlogClass logger.private com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadataproviderMetadataOpenID Provider metadata .private Function<ProfileRequestContext,OIDCProviderMetadataContext>providerMetadataLookupStrategyLookup strategy to locate the OpenID Provider metadata to use.private Function<ProfileRequestContext,RelyingPartyContext>relyingPartyContextLookupStrategyLookup function for relying party context.private Predicate<ProfileRequestContext>requestObjectToBeSignedPredicateIs the request object going to be signed? if so the 'iss' and 'aud' claims will be set.
-
Constructor Summary
Constructors Constructor Description BuildRequestObject()Constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description protected voiddoExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext)protected booleandoPreExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext)private voidsetClaimIfPresent(com.nimbusds.openid.connect.sdk.claims.ClaimsSet claims, String claimName, Object claim)Set the claim onto the claims set if notnull.voidsetClaimsSetIsValidPredicate(Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet> predicate)Set a hook that allows the built request object to be validated before it is used.voidsetProviderMetadataLookupStrategy(Function<ProfileRequestContext,OIDCProviderMetadataContext> strategy)Set the lookup strategy to locate the OpenID providers metadata.voidsetRelyingPartyContextLookupStrategy(Function<ProfileRequestContext,RelyingPartyContext> strategy)Set the strategy used to locate theRelyingPartyContextassociated with a givenProfileRequestContext.voidsetRequestObjectToBeSignedPredicate(Predicate<ProfileRequestContext> predicate)Set a predicate to determine if the request object will be 'eventually' signed.private booleanvalidateRequestObject(ProfileRequestContext profileRequestContext, com.nimbusds.openid.connect.sdk.claims.ClaimsSet requestObjectClaims)Ensure the request object is valid by assessing the claims are correct.-
Methods inherited from class net.shibboleth.idp.authn.AbstractAuthenticationAction
doExecute, doPreExecute, setAuthenticationContextLookupStrategy
-
Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy
-
Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationCondition
-
Methods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, setHttpServletRequest, setHttpServletRequestSupplier, setHttpServletResponse, setHttpServletResponseSupplier
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, doInitialize, initialize, isDestroyed, isInitialized
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface net.shibboleth.utilities.java.support.component.InitializableComponent
initialize, isInitialized
-
-
-
-
Field Detail
-
log
@Nonnull private final org.slf4j.Logger log
Class logger.
-
providerMetadataLookupStrategy
@Nonnull private Function<ProfileRequestContext,OIDCProviderMetadataContext> providerMetadataLookupStrategy
Lookup strategy to locate the OpenID Provider metadata to use.
-
relyingPartyContextLookupStrategy
@Nonnull private Function<ProfileRequestContext,RelyingPartyContext> relyingPartyContextLookupStrategy
Lookup function for relying party context.
-
claimsSetIsValidPredicate
@Nonnull private Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet> claimsSetIsValidPredicate
A hook to allow additional checking of the request object claims after it is built.
-
requestObjectToBeSignedPredicate
@Nonnull private Predicate<ProfileRequestContext> requestObjectToBeSignedPredicate
Is the request object going to be signed? if so the 'iss' and 'aud' claims will be set. Defaults to always true, as it is permissible that both 'iss' and 'aud' claim can exist in plain request objects.
-
authnRequest
@Nullable private OIDCAuthenticationRequest authnRequest
OIDC authentication request built by the IdP.
-
providerMetadata
@Nullable private com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata providerMetadata
OpenID Provider metadata .
-
-
Method Detail
-
setRelyingPartyContextLookupStrategy
public void setRelyingPartyContextLookupStrategy(@Nonnull Function<ProfileRequestContext,RelyingPartyContext> strategy)Set the strategy used to locate theRelyingPartyContextassociated with a givenProfileRequestContext.- Parameters:
strategy- lookup strategy
-
setProviderMetadataLookupStrategy
public void setProviderMetadataLookupStrategy(@Nonnull Function<ProfileRequestContext,OIDCProviderMetadataContext> strategy)Set the lookup strategy to locate the OpenID providers metadata.- Parameters:
strategy- the strategy.
-
setClaimsSetIsValidPredicate
public void setClaimsSetIsValidPredicate(@Nullable Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet> predicate)Set a hook that allows the built request object to be validated before it is used. This is run in addition too, but before, the built in validation taken from the specification. If this returns false, the built in validation is not run, and validation fails.- Parameters:
predicate- the hook to run
-
setRequestObjectToBeSignedPredicate
public void setRequestObjectToBeSignedPredicate(@Nullable Predicate<ProfileRequestContext> predicate)Set a predicate to determine if the request object will be 'eventually' signed. If so, the 'iss' and 'aud' claims will be set into the request object.- Parameters:
predicate- the predicate
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)- Overrides:
doPreExecutein classAbstractAuthenticationAction
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)- Overrides:
doExecutein classAbstractAuthenticationAction
-
setClaimIfPresent
private void setClaimIfPresent(@Nonnull com.nimbusds.openid.connect.sdk.claims.ClaimsSet claims, @Nonnull String claimName, @Nullable Object claim)Set the claim onto the claims set if notnull. Calls toString on each value, assuming it will produce the correct value.- Parameters:
claims- the claims setclaimName- the claim nameclaim- the claim
-
validateRequestObject
private boolean validateRequestObject(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull com.nimbusds.openid.connect.sdk.claims.ClaimsSet requestObjectClaims)Ensure the request object is valid by assessing the claims are correct.- Parameters:
profileRequestContext- the profile request contextrequestObjectClaims- the claims of the request object- Returns:
- true if the request object claims are valid, false otherwise
-
-