Class CheckCredentialPolicy
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<WebAuthnAuthenticationContext>
net.shibboleth.idp.plugin.authn.webauthn.impl.CheckCredentialPolicy
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
A policy engine action that checks with the configured policy if the credential, used to sign the assertion can
be used to authenticate. If it is rejected by the policy, a
WebAuthnAuthenticationEventIds.CREDENTIAL_POLICY_REJECTION is returned. Similarly, if a credential can
not be found to evaluate the policy returns an WebAuthnAuthenticationEventIds.CREDENTIAL_POLICY_REJECTION.- Event:
- {EventIds#INVALID_PROFILE_CTX}, {WebAuthnAuthenticationEventIds#CREDENTIAL_POLICY_REJECTION}
- Precondition:
ProfileRequestContext.getSubcontext(WebAuthnRegistrationContext.class) != null
- Postcondition:
- the credential is allowed to be used for authentication, or an error event is triggered
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAssertionResponse,com.yubico.webauthn.data.ClientAssertionExtensionOutputs> The stashed assertion response.private AuthenticationContextThe stashed authentication context.private CredentialPolicyThe credential policy to check.private final org.slf4j.LoggerClass logger.private WebAuthnCredentialRepositoryThe credential repository to use.private Function<ProfileRequestContext,byte[]> Get the userHandle to help find the credential used to sign the assertion. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, WebAuthnAuthenticationContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected voidprotected booleandoPreExecute(ProfileRequestContext profileRequestContext, WebAuthnAuthenticationContext context) Performs this authentication action's pre-execute step.voidsetCredentialPolicy(CredentialPolicy policy) Set the policy to verify that the credential can be used for authentication.voidsetUserHandleLookupStrategy(Function<ProfileRequestContext, byte[]> strategy) Set the strategy to locate the userHandle of the user that holds the credential used to sign the assertion.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
assertion
@NonnullBeforeExec private com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAssertionResponse,com.yubico.webauthn.data.ClientAssertionExtensionOutputs> assertionThe stashed assertion response. -
userHandleLookupStrategy
Get the userHandle to help find the credential used to sign the assertion. -
credentialPolicy
The credential policy to check. -
repository
The credential repository to use. -
authnContext
The stashed authentication context.
-
-
Constructor Details
-
CheckCredentialPolicy
protected CheckCredentialPolicy()Constructor.
-
-
Method Details
-
setCredentialPolicy
Set the policy to verify that the credential can be used for authentication.- Parameters:
policy- The authenticator policy to set.
-
setUserHandleLookupStrategy
Set the strategy to locate the userHandle of the user that holds the credential used to sign the assertion.- Parameters:
strategy- The user handle lookup strategy to set.- Since:
- 1.1.0
-
doInitialize
- Overrides:
doInitializein classAbstractWebAuthnAction<WebAuthnAuthenticationContext>- Throws:
ComponentInitializationException
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnAuthenticationContext context) Performs this authentication action's pre-execute step. Default implementation just returns true.- Overrides:
doPreExecutein classAbstractWebAuthnAction<WebAuthnAuthenticationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context- Returns:
- true iff execution should continue
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnAuthenticationContext context) Description copied from class:AbstractWebAuthnActionPerforms this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<WebAuthnAuthenticationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-