Class CheckUserHandleExistsIfNoAllowCredentials
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<WebAuthnAuthenticationContext>
net.shibboleth.idp.plugin.authn.webauthn.impl.CheckUserHandleExistsIfNoAllowCredentials
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class CheckUserHandleExistsIfNoAllowCredentials
extends AbstractWebAuthnAction<WebAuthnAuthenticationContext>
An action which checks if the userHandle is returned in the assertion response if the set of allowedCredentials
in the request was empty. If they are empty, the userHandle must be returned, if they are not empty the userHandle
may be returned in the response.
This generally protects against bad behaviour from authenticators for the rest of the flow.
- Since:
- 1.1.0
- Event:
- {EventIds#INVALID_PROFILE_CTX}, {AuthnEventIds#INVALID_CREDENTIALS}
- Precondition:
ProfileRequestContext.getSubcontext(WebAuthnRegistrationContext.class) != null
- Postcondition:
- a non-proceed event occurs if the userHandle was not present when the set of allowed credentials is empty.
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAssertionResponse,com.yubico.webauthn.data.ClientAssertionExtensionOutputs> The stashed assertion from the context.private final org.slf4j.LoggerClass logger.private com.yubico.webauthn.data.PublicKeyCredentialRequestOptionsThe stashed request options from the context. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, WebAuthnAuthenticationContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected booleandoPreExecute(ProfileRequestContext profileRequestContext, WebAuthnAuthenticationContext context) Performs this authentication action's pre-execute step.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doInitialize, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
assertion
private com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAssertionResponse,com.yubico.webauthn.data.ClientAssertionExtensionOutputs> assertionThe stashed assertion from the context. -
requestOptions
private com.yubico.webauthn.data.PublicKeyCredentialRequestOptions requestOptionsThe stashed request options from the context.
-
-
Constructor Details
-
CheckUserHandleExistsIfNoAllowCredentials
protected CheckUserHandleExistsIfNoAllowCredentials()Constructor.
-
-
Method Details
-
doPreExecute
protected boolean doPreExecute(ProfileRequestContext profileRequestContext, WebAuthnAuthenticationContext context) Performs this authentication action's pre-execute step. Default implementation just returns true.- Overrides:
doPreExecutein classAbstractWebAuthnAction<WebAuthnAuthenticationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context- Returns:
- true iff execution should continue
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnAuthenticationContext context) Description copied from class:AbstractWebAuthnActionPerforms this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<WebAuthnAuthenticationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-