Class CheckRegistrationPolicy
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<WebAuthnRegistrationContext>
net.shibboleth.idp.plugin.authn.webauthn.admin.impl.CheckRegistrationPolicy
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
A registration policy engine action that checks with the configured policy if the authenticator can be used to
register credentials with the IdP.
- Event:
- {WebAuthnRegistrationEventIds#INVALID_REGISTRATION_CTX}
- Precondition:
ProfileRequestContext.getSubcontext(WebAuthnRegistrationContext.class) != null
- Postcondition:
- the authenticator is allowed to register a credential, or an error event is triggered
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAttestationResponse,com.yubico.webauthn.data.ClientRegistrationExtensionOutputs> The stashed attestation response.private AuthenticatorPolicyThe authenticator policy to check.private final org.slf4j.LoggerClass logger. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, WebAuthnRegistrationContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected booleandoPreExecute(ProfileRequestContext profileRequestContext, WebAuthnRegistrationContext context) Performs this authentication action's pre-execute step.voidSet the policy to verify that the authenticator is authorized before the credential is stored.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doInitialize, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
attestation
@NonnullBeforeExec private com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAttestationResponse,com.yubico.webauthn.data.ClientRegistrationExtensionOutputs> attestationThe stashed attestation response. -
authenticatorPolicy
The authenticator policy to check.
-
-
Constructor Details
-
CheckRegistrationPolicy
protected CheckRegistrationPolicy()Constructor.
-
-
Method Details
-
setAuthenticatorPolicy
Set the policy to verify that the authenticator is authorized before the credential is stored.- Parameters:
policy- The authenticator policy to set.
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnRegistrationContext context) Performs this authentication action's pre-execute step. Default implementation just returns true.- Overrides:
doPreExecutein classAbstractWebAuthnAction<WebAuthnRegistrationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context- Returns:
- true iff execution should continue
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnRegistrationContext context) Description copied from class:AbstractWebAuthnActionPerforms this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<WebAuthnRegistrationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-