Class BuildRequestObject

All Implemented Interfaces:
Component, DestructableComponent, InitializableComponent, ProfileAction, Aware, MessageSource, MessageSourceAware, Action

public class BuildRequestObject extends AbstractAuthenticationAction
Action that creates a Request Object JWT, and sets it to the work context OIDCAuthenticationRequest located under InOutOperationContext.getOutboundMessageContext().

Note, some parameters are set downstream in the flow before the request object is signed and or encrypted. These parameters are only available to the HTTP Controller e.g. state, and must be set during the external authentication redirect.

Event:
EventIds.PROCEED_EVENT_ID, EventIds.INVALID_MSG_CTX, EventIds.INVALID_PROFILE_CTX, AuthnEventIds.INVALID_AUTHN_CTX
Precondition:
ProfileRequestContext.getOutboundMessageContext().getMessage() 
 instance of OIDCAuthenticationRequest.class
Postcondition:
Add a JWT request object to the in-flight authentication request
  • Field Details

    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
    • providerMetadataLookupStrategy

      @Nonnull private Function<ProfileRequestContext,OIDCProviderMetadataContext> providerMetadataLookupStrategy
      Lookup strategy to locate the OpenID Provider metadata to use.
    • relyingPartyContextLookupStrategy

      @Nonnull private Function<ProfileRequestContext,RelyingPartyContext> relyingPartyContextLookupStrategy
      Lookup function for relying party context.
    • claimsSetIsValidPredicate

      @Nonnull private Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet> claimsSetIsValidPredicate
      A hook to allow additional checking of the request object claims after it is built.
    • requestObjectToBeSignedPredicate

      @Nonnull private Predicate<ProfileRequestContext> requestObjectToBeSignedPredicate
      Is the request object going to be signed? if so the 'iss' and 'aud' claims will be set. Defaults to always true, as it is permissible that both 'iss' and 'aud' claim can exist in plain request objects.
    • authnRequest

      OIDC authentication request built by the IdP.
    • providerMetadata

      @NonnullBeforeExec private com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata providerMetadata
      OpenID Provider metadata .
  • Constructor Details

    • BuildRequestObject

      public BuildRequestObject()
      Constructor.
  • Method Details

    • setRelyingPartyContextLookupStrategy

      public void setRelyingPartyContextLookupStrategy(@Nonnull Function<ProfileRequestContext,RelyingPartyContext> strategy)
      Set the strategy used to locate the RelyingPartyContext associated with a given ProfileRequestContext.
      Parameters:
      strategy - lookup strategy
    • setProviderMetadataLookupStrategy

      public void setProviderMetadataLookupStrategy(@Nonnull Function<ProfileRequestContext,OIDCProviderMetadataContext> strategy)
      Set the lookup strategy to locate the OpenID providers metadata.
      Parameters:
      strategy - the strategy.
    • setClaimsSetIsValidPredicate

      public void setClaimsSetIsValidPredicate(@Nullable Predicate<com.nimbusds.openid.connect.sdk.claims.ClaimsSet> predicate)
      Set a hook that allows the built request object to be validated before it is used. This is run in addition too, but before, the built in validation taken from the specification. If this returns false, the built in validation is not run, and validation fails.
      Parameters:
      predicate - the hook to run
    • setRequestObjectToBeSignedPredicate

      public void setRequestObjectToBeSignedPredicate(@Nullable Predicate<ProfileRequestContext> predicate)
      Set a predicate to determine if the request object will be 'eventually' signed. If so, the 'iss' and 'aud' claims will be set into the request object.
      Parameters:
      predicate - the predicate
    • doPreExecute

      protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)
      Overrides:
      doPreExecute in class AbstractAuthenticationAction
    • doExecute

      protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull AuthenticationContext authenticationContext)
      Overrides:
      doExecute in class AbstractAuthenticationAction
    • setClaimIfPresent

      private void setClaimIfPresent(@Nonnull com.nimbusds.openid.connect.sdk.claims.ClaimsSet claims, @Nonnull String claimName, @Nullable Object claim)
      Set the claim onto the claims set if not null. Calls toString on each value, assuming it will produce the correct value.
      Parameters:
      claims - the claims set
      claimName - the claim name
      claim - the claim
    • validateRequestObject

      private boolean validateRequestObject(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull com.nimbusds.openid.connect.sdk.claims.ClaimsSet requestObjectClaims)
      Ensure the request object is valid by assessing the claims are correct.
      Parameters:
      profileRequestContext - the profile request context
      requestObjectClaims - the claims of the request object
      Returns:
      true if the request object claims are valid, false otherwise