Class ValidateTokenClaims
- java.lang.Object
-
- net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
-
- org.opensaml.profile.action.AbstractProfileAction
-
- org.opensaml.profile.action.AbstractConditionalProfileAction
-
- net.shibboleth.idp.profile.AbstractProfileAction
-
- net.shibboleth.idp.authn.AbstractAuthenticationAction
-
- net.shibboleth.idp.plugin.authn.oidc.rp.impl.ValidateTokenClaims
-
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class ValidateTokenClaims extends AbstractAuthenticationAction
Action that validates the claims of a JWT using the suppliedclaims validator. The verifier must be thread-safe and validate, at minimum, the claims set against the OpenID Connect core 1.0 section 3.1.3.7 specification.- Event:
EventIds.PROCEED_EVENT_ID,AuthnEventIds.INVALID_AUTHN_CTX,OidcEventIds.INVALID_TOKEN- Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null
,JWT.getJWTClaimsSet() != null
-
-
Field Summary
Fields Modifier and Type Field Description private com.nimbusds.jwt.JWTClaimsSetclaimsSetThe parsed claimset.private ClaimsValidatorclaimsValidatorThe JWT claims validator used to verify the claimsset.private Consumer<ProfileRequestContext>cleanupHookA cleanup hook to execute after either a successful or unsuccessful claims validation.private Function<ProfileRequestContext,com.nimbusds.jwt.JWT>jwtLookupStrategyStrategy used to pull out a JWT to validate from the context.private org.slf4j.LoggerlogClass logger.
-
Constructor Summary
Constructors Constructor Description ValidateTokenClaims()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description protected voiddoExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext)protected voiddoInitialize()protected booleandoPreExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext)voidsetClaimsValidator(ClaimsValidator validator)Set the JWT claims verifier to use.voidsetCleanupHook(Consumer<ProfileRequestContext> hook)Set the cleanup hook to execute after either a successful or unsuccessful claims validation.voidsetJwtLookupStrategy(Function<ProfileRequestContext,com.nimbusds.jwt.JWT> strategy)Set the lookup strategy that locates the JWT to validate from the context.-
Methods inherited from class net.shibboleth.idp.authn.AbstractAuthenticationAction
doExecute, doPreExecute, setAuthenticationContextLookupStrategy
-
Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy
-
Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationCondition
-
Methods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, setHttpServletRequest, setHttpServletRequestSupplier, setHttpServletResponse, setHttpServletResponseSupplier
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, initialize, isDestroyed, isInitialized
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface net.shibboleth.utilities.java.support.component.InitializableComponent
initialize, isInitialized
-
-
-
-
Field Detail
-
log
@Nonnull private final org.slf4j.Logger log
Class logger.
-
cleanupHook
@Nullable private Consumer<ProfileRequestContext> cleanupHook
A cleanup hook to execute after either a successful or unsuccessful claims validation.
-
claimsSet
@Nullable private com.nimbusds.jwt.JWTClaimsSet claimsSet
The parsed claimset.
-
claimsValidator
@NonnullAfterInit private ClaimsValidator claimsValidator
The JWT claims validator used to verify the claimsset.
-
jwtLookupStrategy
@NonnullAfterInit private Function<ProfileRequestContext,com.nimbusds.jwt.JWT> jwtLookupStrategy
Strategy used to pull out a JWT to validate from the context.
-
-
Method Detail
-
doInitialize
protected void doInitialize() throws ComponentInitializationException- Overrides:
doInitializein classAbstractInitializableComponent- Throws:
ComponentInitializationException
-
setJwtLookupStrategy
public void setJwtLookupStrategy(@Nonnull Function<ProfileRequestContext,com.nimbusds.jwt.JWT> strategy)Set the lookup strategy that locates the JWT to validate from the context.- Parameters:
strategy- the strategy
-
setCleanupHook
public void setCleanupHook(@Nullable Consumer<ProfileRequestContext> hook)Set the cleanup hook to execute after either a successful or unsuccessful claims validation.- Parameters:
hook- cleanup hook
-
setClaimsValidator
public void setClaimsValidator(@Nonnull ClaimsValidator validator)Set the JWT claims verifier to use.- Parameters:
validator- the claims validator.
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)- Overrides:
doPreExecutein classAbstractAuthenticationAction
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)- Overrides:
doExecutein classAbstractAuthenticationAction
-
-