Class ValidateUserInfoJSONObjectClaims
- java.lang.Object
-
- net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
-
- org.opensaml.profile.action.AbstractProfileAction
-
- org.opensaml.profile.action.AbstractConditionalProfileAction
-
- net.shibboleth.idp.profile.AbstractProfileAction
-
- net.shibboleth.idp.authn.AbstractAuthenticationAction
-
- net.shibboleth.idp.plugin.authn.oidc.rp.impl.ValidateUserInfoJSONObjectClaims
-
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class ValidateUserInfoJSONObjectClaims extends AbstractAuthenticationAction
Validate a successful UserInfo JSON Object Response according to section 5.3.2 of OpenID Connect Core 1.0.- Event:
EventIds.PROCEED_EVENT_ID,OidcEventIds.INVALID_USERINFO_CLAIMS,EventIds.INVALID_PROFILE_CTX- Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null
-
-
Field Summary
Fields Modifier and Type Field Description private com.nimbusds.jwt.JWTClaimsSetidTokenClaimsThe stashed id_token claims.private org.slf4j.LoggerlogClass logger.private Function<ProfileRequestContext,AccessTokenResponseContext>tokenResponseContextLookupStrategyStrategy used to look up theAccessTokenResponseContext.private UserInfoResponseContextuserInfoCtxThe stashed user info response context.private Function<ProfileRequestContext,UserInfoResponseContext>userInfoResponseContextLookupStrategyStrategy used to look up theUserInfoResponseContext.
-
Constructor Summary
Constructors Constructor Description ValidateUserInfoJSONObjectClaims()Constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description protected voiddoExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext)protected booleandoPreExecute(ProfileRequestContext profileRequestContext, AuthenticationContext authenticationContext)private com.nimbusds.openid.connect.sdk.claims.ClaimsSetresolveClaimsSet(com.nimbusds.openid.connect.sdk.UserInfoResponse response)Resolve the UserInfo claims from the user info response.voidsetTokenResponseContextLookupStrategy(Function<ProfileRequestContext,AccessTokenResponseContext> strategy)Set the strategy used to look up aAccessTokenResponseContext.voidsetUserInfoResponseContextLookupStrategy(Function<ProfileRequestContext,UserInfoResponseContext> strategy)Set the strategy used to look up aUserInfoResponseContext.-
Methods inherited from class net.shibboleth.idp.authn.AbstractAuthenticationAction
doExecute, doPreExecute, setAuthenticationContextLookupStrategy
-
Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy
-
Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationCondition
-
Methods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, setHttpServletRequest, setHttpServletRequestSupplier, setHttpServletResponse, setHttpServletResponseSupplier
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, doInitialize, initialize, isDestroyed, isInitialized
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface net.shibboleth.utilities.java.support.component.InitializableComponent
initialize, isInitialized
-
-
-
-
Field Detail
-
log
@Nonnull private final org.slf4j.Logger log
Class logger.
-
userInfoResponseContextLookupStrategy
@Nonnull private Function<ProfileRequestContext,UserInfoResponseContext> userInfoResponseContextLookupStrategy
Strategy used to look up theUserInfoResponseContext.
-
tokenResponseContextLookupStrategy
@Nonnull private Function<ProfileRequestContext,AccessTokenResponseContext> tokenResponseContextLookupStrategy
Strategy used to look up theAccessTokenResponseContext.
-
userInfoCtx
@Nullable private UserInfoResponseContext userInfoCtx
The stashed user info response context.
-
idTokenClaims
@Nullable private com.nimbusds.jwt.JWTClaimsSet idTokenClaims
The stashed id_token claims.
-
-
Method Detail
-
setTokenResponseContextLookupStrategy
public void setTokenResponseContextLookupStrategy(@Nonnull Function<ProfileRequestContext,AccessTokenResponseContext> strategy)Set the strategy used to look up aAccessTokenResponseContext.- Parameters:
strategy- lookup strategy
-
setUserInfoResponseContextLookupStrategy
public void setUserInfoResponseContextLookupStrategy(@Nonnull Function<ProfileRequestContext,UserInfoResponseContext> strategy)Set the strategy used to look up aUserInfoResponseContext.- Parameters:
strategy- lookup strategy
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)- Overrides:
doPreExecutein classAbstractAuthenticationAction
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)- Overrides:
doExecutein classAbstractAuthenticationAction
-
resolveClaimsSet
@Nullable private com.nimbusds.openid.connect.sdk.claims.ClaimsSet resolveClaimsSet(@Nonnull com.nimbusds.openid.connect.sdk.UserInfoResponse response)Resolve the UserInfo claims from the user info response. If JWT type, extract from the JWT claims. If plain JSON object type, resolve directly from the UserInfo claims set.- Parameters:
response- the UserInfo response- Returns:
- the UserInfo claims. Return
nullif not found, wrong response type, or there was a parsing exception
-
-