Class StorePublicKeyCredential
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction<T>
net.shibboleth.idp.plugin.authn.webauthn.audit.impl.AbstractWebAuthnAuditingAction<WebAuthnRegistrationContext>
net.shibboleth.idp.plugin.authn.webauthn.admin.impl.StorePublicKeyCredential
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class StorePublicKeyCredential
extends AbstractWebAuthnAuditingAction<WebAuthnRegistrationContext>
An action that adds the public key credential in the registration context to the credential repository.
Importantly, the registration is stored against the username in the context (the authenticated user), not the WebAuthn user.name. This way, even if the user changed the webauthn create request in the browser (e.g. to a different userId), it will still be registered against the authenticated user. This prevents a user from registering a credential against somebody else's account.
- Event:
- {WebAuthnRegistrationEventIds#INVALID_REGISTRATION}
- Precondition:
ProfileRequestContext.getSubcontext(WebAuthnRegistrationContext.class) != null
- Postcondition:
- the credential from the registration context is added to the credential repository
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate final org.slf4j.LoggerClass logger.private WebAuthnCredentialRepositoryThe credential repository to use. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(ProfileRequestContext profileRequestContext, WebAuthnRegistrationContext context) Performs this WebAuthn authentication action using the supplied WebAuthn context.protected voidprivate voidlogRegistration(WebAuthnRegistrationContext context, String username, RegistrationResult registrationResult) Log a successful registration event.Methods inherited from class net.shibboleth.idp.plugin.authn.webauthn.audit.impl.AbstractWebAuthnAuditingAction
auditFailure, auditSuccess, doAudit, doExecute, getAuditContext, getAuditFields, setAuditContextCreationStrategy, setOnFailureAuditHook, setOnSuccessAuditHook, setPopulateAuditContextAction, setWriteAuditLogActionMethods inherited from class net.shibboleth.idp.plugin.authn.webauthn.impl.AbstractWebAuthnAction
doExecute, doPreExecute, doPreExecute, enhancedCredentialRecord, getAaguidMetadata, getAaguidService, getAuthenticatorMetadata, getCredentialRepository, getFidoMetadataService, getWebAuthnClient, setAaguidService, setCredentialRepository, setFidoMetadataService, setWebAuthnClient, setWebAuthnContextLookupStrategyMethods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
repository
The credential repository to use.
-
-
Constructor Details
-
StorePublicKeyCredential
protected StorePublicKeyCredential()Constructor.
-
-
Method Details
-
doInitialize
- Overrides:
doInitializein classAbstractWebAuthnAction<WebAuthnRegistrationContext>- Throws:
ComponentInitializationException
-
doExecute
protected void doExecute(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull WebAuthnRegistrationContext context) Description copied from class:AbstractWebAuthnActionPerforms this WebAuthn authentication action using the supplied WebAuthn context. Implementations should override this method.- Overrides:
doExecutein classAbstractWebAuthnAction<WebAuthnRegistrationContext>- Parameters:
profileRequestContext- the current IdP profile request contextcontext- the WebAuthn context
-
logRegistration
private void logRegistration(@Nonnull WebAuthnRegistrationContext context, @Nullable String username, @Nonnull RegistrationResult registrationResult) Log a successful registration event.- Parameters:
context- the registration contextusername- the username of the user that registered a credentialregistrationResult- the result of registration
-