Class DefaultUserInfoResponseDecoder

java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
net.shibboleth.idp.plugin.authn.oidc.rp.decoding.impl.AbstractJSONResponseDecoderFunction<com.nimbusds.openid.connect.sdk.UserInfoResponse>
net.shibboleth.idp.plugin.authn.oidc.rp.decoding.impl.DefaultUserInfoResponseDecoder
All Implemented Interfaces:
Component, DestructableComponent, InitializableComponent, org.apache.hc.core5.http.io.HttpClientResponseHandler<com.nimbusds.openid.connect.sdk.UserInfoResponse>

public class DefaultUserInfoResponseDecoder extends AbstractJSONResponseDecoderFunction<com.nimbusds.openid.connect.sdk.UserInfoResponse>
The default Http client UserInfo response decoder. Supports both plain JSON Object and JWT responses.

Importantly,the decoder *must not ever* decode a JWT response as a plain response type, otherwise the signature check may not be performed downstream - although other validation for the plain object type should. That is, we can not rely solely on the content-type header in-case of content-type header injection attacks — the logic that builds either the JWT or plain response should fail, or at least present an invalid UserInfo response token. Any decoding error is logged and null is returned.

  • Field Details

    • USERINFO_ERROR_RESPONSE_HEADER

      @Nonnull public static final String USERINFO_ERROR_RESPONSE_HEADER
      The UserInfo response header that carries error information.
      See Also:
    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
  • Constructor Details

    • DefaultUserInfoResponseDecoder

      public DefaultUserInfoResponseDecoder()
  • Method Details

    • handleResponse

      public com.nimbusds.openid.connect.sdk.UserInfoResponse handleResponse(@Nullable org.apache.hc.core5.http.ClassicHttpResponse httpResponse)