Class BuildRequestObject

    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Class logger.
      • claimsSetIsValidPredicate

        @Nonnull
        private Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet> claimsSetIsValidPredicate
        A hook to allow additional checking of the request object claims after it is built.
      • requestObjectToBeSignedPredicate

        @Nonnull
        private Predicate<ProfileRequestContext> requestObjectToBeSignedPredicate
        Is the request object going to be signed? if so the 'iss' and 'aud' claims will be set. Defaults to always true, as it is permissible that both 'iss' and 'aud' claim can exist in plain request objects.
      • providerMetadata

        @Nullable
        private com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata providerMetadata
        OpenID Provider metadata .
    • Constructor Detail

      • BuildRequestObject

        public BuildRequestObject()
        Constructor.
    • Method Detail

      • setClaimsSetIsValidPredicate

        public void setClaimsSetIsValidPredicate​(@Nullable
                                                 Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet> predicate)
        Set a hook that allows the built request object to be validated before it is used. This is run in addition too, but before, the built in validation taken from the specification. If this returns false, the built in validation is not run, and validation fails.
        Parameters:
        predicate - the hook to run
      • setRequestObjectToBeSignedPredicate

        public void setRequestObjectToBeSignedPredicate​(@Nullable
                                                        Predicate<ProfileRequestContext> predicate)
        Set a predicate to determine if the request object will be 'eventually' signed. If so, the 'iss' and 'aud' claims will be set into the request object.
        Parameters:
        predicate - the predicate
      • setClaimIfPresent

        private void setClaimIfPresent​(@Nonnull
                                       com.nimbusds.openid.connect.sdk.claims.ClaimsSet claims,
                                       @Nonnull
                                       String claimName,
                                       @Nullable
                                       Object claim)
        Set the claim onto the claims set if not null. Calls toString on each value, assuming it will produce the correct value.
        Parameters:
        claims - the claims set
        claimName - the claim name
        claim - the claim
      • validateRequestObject

        private boolean validateRequestObject​(@Nonnull
                                              ProfileRequestContext profileRequestContext,
                                              @Nonnull
                                              com.nimbusds.openid.connect.sdk.claims.ClaimsSet requestObjectClaims)
        Ensure the request object is valid by assessing the claims are correct.
        Parameters:
        profileRequestContext - the profile request context
        requestObjectClaims - the claims of the request object
        Returns:
        true if the request object claims are valid, false otherwise