Class LookupRegisteredCredentialsFromUserHandle
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<WebAuthnAuthenticationContext>
net.shibboleth.idp.plugin.authn.webauthn.impl.LookupRegisteredCredentialsFromUserHandle
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class LookupRegisteredCredentialsFromUserHandle
extends AbstractWebAuthnAction<WebAuthnAuthenticationContext>
An action that lookups existing registered credentials from the userHandle supplied in the authenticators assertion
response and sets them back onto the context. If no credentials exist and the trigger condition is set, an error
event will be produced.
Also ensures the username found from the userHandle matches that in the authentication context if supplied e.g. for a passwordless authentication.
- Event:
AuthnEventIds.INVALID_AUTHN_CTX- Postcondition:
- BaseWebAuthnContext.setExistingCredentials() is either null if no existing credentials are found, or contains the credentials from the credential repository
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate final org.slf4j.LoggerClass logger.private StringThe EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsPredicateevaluates to true.private WebAuthnCredentialRepositoryThe credential repository to use.private Predicate<ProfileRequestContext>Should an event be built if there are no credentials found?. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, WebAuthnAuthenticationContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected voidvoidsetNoCredentialsEventId(String eventId) Set the EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsis set.voidsetTriggerEventOnNoCredentials(boolean trigger) Set a flag which triggers a custom event to be built if no credentials are found.voidSet a predicate which triggers a custom event to be built if no credentials are found.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doPreExecute, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
triggerEventOnNoCredentialsPredicate
Should an event be built if there are no credentials found?. Defaults to false. -
noCredentialsEventId
The EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsPredicateevaluates to true. -
repository
The credential repository to use.
-
-
Constructor Details
-
LookupRegisteredCredentialsFromUserHandle
public LookupRegisteredCredentialsFromUserHandle()Constructor.
-
-
Method Details
-
doInitialize
- Overrides:
doInitializein classAbstractWebAuthnAction<WebAuthnAuthenticationContext>- Throws:
ComponentInitializationException
-
setTriggerEventOnNoCredentials
public void setTriggerEventOnNoCredentials(boolean trigger) Set a flag which triggers a custom event to be built if no credentials are found.- Parameters:
trigger- the flag to set
-
setTriggerEventOnNoCredentialsPredicate
public void setTriggerEventOnNoCredentialsPredicate(@Nonnull Predicate<ProfileRequestContext> predicate) Set a predicate which triggers a custom event to be built if no credentials are found.- Parameters:
predicate- the flag to set
-
setNoCredentialsEventId
Set the EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsis set.- Parameters:
eventId- the eventId to build.
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnAuthenticationContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<WebAuthnAuthenticationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-