Class ValidateAuthenticatorAttestationResponse
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<WebAuthnRegistrationContext>
net.shibboleth.idp.plugin.authn.webauthn.admin.impl.ValidateAuthenticatorAttestationResponse
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class ValidateAuthenticatorAttestationResponse
extends AbstractWebAuthnAction<WebAuthnRegistrationContext>
Validate the public key registration attempt by delegating the created public key credential to the WebAuthn client.
If valid, store the registration result inside the registration context.
- Event:
- {WebAuthnRegistrationEventIds#INVALID_REGISTRATION}
- Precondition:
ProfileRequestContext.getSubcontext(WebAuthnRegistrationContext.class) != null
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAttestationResponse,com.yubico.webauthn.data.ClientRegistrationExtensionOutputs> The stashed public key credential authenticator attestation response.private final org.slf4j.LoggerClass logger.private com.yubico.webauthn.data.PublicKeyCredentialCreationOptionsThe stashed public key credential creation options used to create a new credential. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, WebAuthnRegistrationContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected booleandoPreExecute(ProfileRequestContext profileRequestContext, WebAuthnRegistrationContext context) Performs this authentication action's pre-execute step.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doInitialize, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
pkCredCreationOptions
@NonnullBeforeExec private com.yubico.webauthn.data.PublicKeyCredentialCreationOptions pkCredCreationOptionsThe stashed public key credential creation options used to create a new credential. -
attestation
@NonnullBeforeExec private com.yubico.webauthn.data.PublicKeyCredential<com.yubico.webauthn.data.AuthenticatorAttestationResponse,com.yubico.webauthn.data.ClientRegistrationExtensionOutputs> attestationThe stashed public key credential authenticator attestation response.
-
-
Constructor Details
-
ValidateAuthenticatorAttestationResponse
public ValidateAuthenticatorAttestationResponse()Constructor.
-
-
Method Details
-
doPreExecute
protected boolean doPreExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnRegistrationContext context) Performs this authentication action's pre-execute step. Default implementation just returns true.- Overrides:
doPreExecutein classAbstractWebAuthnAction<WebAuthnRegistrationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context- Returns:
- true iff execution should continue
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnRegistrationContext context) Description copied from class:AbstractWebAuthnActionPerforms this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<WebAuthnRegistrationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-