Class GenerateServerChallenge
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<BaseWebAuthnContext>
net.shibboleth.idp.plugin.authn.webauthn.impl.GenerateServerChallenge
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
An action to generate an appropriate server challenge for use in either the PublicKeyCredentialCreationOptions or the
PublicKeyCredentialRequestOptions. A challenge must have high entropy such that it can not be guessed, and should
therefore be at least 16 bytes long.
- Event:
EventIds.PROCEED_EVENT_ID,EventIds.INVALID_PROFILE_CTX- Postcondition:
- a challenge is added to the
base context
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionprivate static final classDefault challenge generator that generates a 32 byte randomized challenge of sufficient entropy. -
Field Summary
FieldsModifier and TypeFieldDescriptionprivate Function<ProfileRequestContext,byte[]> Strategy used to generate the challenge to use.private final org.slf4j.LoggerClass logger. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, BaseWebAuthnContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected voidvoidsetChallengeGeneratorStrategy(Function<ProfileRequestContext, byte[]> strategy) Set the strategy used to generate the challenge.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doPreExecute, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
challengeGeneratorStrategy
Strategy used to generate the challenge to use.
-
-
Constructor Details
-
GenerateServerChallenge
public GenerateServerChallenge()Constructor.
-
-
Method Details
-
doInitialize
- Overrides:
doInitializein classAbstractWebAuthnAction<BaseWebAuthnContext>- Throws:
ComponentInitializationException
-
setChallengeGeneratorStrategy
public void setChallengeGeneratorStrategy(@Nullable Function<ProfileRequestContext, byte[]> strategy) Set the strategy used to generate the challenge.- Parameters:
strategy- the strategy
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull BaseWebAuthnContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<BaseWebAuthnContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-