Class LookupRegisteredCredentials
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<BaseWebAuthnContext>
net.shibboleth.idp.plugin.authn.webauthn.impl.LookupRegisteredCredentials
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
An action that lookups existing registered credentials based on the username contained in the WebAuthn context
and sets them back onto the context. Also sets the user.id from the userHandle associated with the username back
onto the WebAuthn context.
If the username is not required and is not found in the context (e.g. failed c14n) the set of existing credentials will remain empty. If the username is required and is not found in the context an error event will be returned. If no credentials exist and the trigger event condition is set, an error event will be produced.
- Event:
AuthnEventIds.INVALID_AUTHN_CTX- Postcondition:
- BaseWebAuthnContext.setExistingCredentials() is either null if no existing credentials are found, or contains
the credentials from the credential repository.
BaseWebAuthnContext.getUserId()!= null if the userHandle is found from the username.
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate final org.slf4j.LoggerClass logger.private StringThe EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsPredicateevaluates to true.private WebAuthnCredentialRepositoryThe credential repository to use.private Predicate<ProfileRequestContext>Should an non-proceed event be built if there are no credentials found?.private Predicate<ProfileRequestContext>Is the username required? If not, just leave an empty set of existing credentials. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, BaseWebAuthnContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected voidvoidsetNoCredentialsEventId(String eventId) Set the EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsis set.voidsetTriggerEventOnNoCredentials(boolean trigger) Set a flag which triggers a custom event to be built if no credentials are found.voidSet a predicate which triggers a custom event to be built if no credentials are found.voidsetUsernameRequired(boolean flag) Set a flag to determine if the username is required or not.voidSet a strategy to determine if the username is required or not.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doPreExecute, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
triggerEventOnNoCredentialsPredicate
Should an non-proceed event be built if there are no credentials found?. Defaults to false. -
noCredentialsEventId
The EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsPredicateevaluates to true. -
repository
The credential repository to use. -
usernameRequiredPredicate
Is the username required? If not, just leave an empty set of existing credentials.
-
-
Constructor Details
-
LookupRegisteredCredentials
public LookupRegisteredCredentials()Constructor.
-
-
Method Details
-
setUsernameRequired
public void setUsernameRequired(boolean flag) Set a flag to determine if the username is required or not.- Parameters:
flag- is the username required?
-
setUsernameRequiredPredicate
Set a strategy to determine if the username is required or not.- Parameters:
predicate- the predicate to set.
-
doInitialize
- Overrides:
doInitializein classAbstractWebAuthnAction<BaseWebAuthnContext>- Throws:
ComponentInitializationException
-
setTriggerEventOnNoCredentials
public void setTriggerEventOnNoCredentials(boolean trigger) Set a flag which triggers a custom event to be built if no credentials are found.- Parameters:
trigger- the flag to set
-
setTriggerEventOnNoCredentialsPredicate
public void setTriggerEventOnNoCredentialsPredicate(@Nonnull Predicate<ProfileRequestContext> predicate) Set a predicate which triggers a custom event to be built if no credentials are found.- Parameters:
predicate- the flag to set
-
setNoCredentialsEventId
Set the EventID of the event to build if no credentials are found andtriggerEventOnNoCredentialsis set.- Parameters:
eventId- the eventId to build.
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull BaseWebAuthnContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<BaseWebAuthnContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-