Class RelyingPartySigningParametersResolver
java.lang.Object
org.opensaml.xmlsec.impl.AbstractSecurityParametersResolver<SignatureSigningParameters>
net.shibboleth.oidc.security.jose.impl.BasicSignatureSigningParametersResolver
net.shibboleth.oidc.security.jose.impl.RelyingPartySigningParametersResolver
- All Implemented Interfaces:
SignatureSigningParametersResolver,Resolver<SignatureSigningParameters,CriteriaSet>
A specialization of
BasicSignatureSigningParametersResolver which supports selecting signing credentials
from client_secret credential criterion (e.g. from the relying party configuration) in addition to the configured
signing credentials inside the signing configuration (determined by the superclass).
The OpenID Providers's metadata is also used to filter for those algorithms supported by the OP in addition to those supported by the security configuration.
*
In addition to the Criterion inputs documented in
BasicSignatureSigningParametersResolver, the following inputs are also supported:
ClientSecretCredentialCriterion- optionalProviderMetadataCriterion- required
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate final org.slf4j.LoggerLogger.A strategy to pull out the correct set of supported algorithms from theOIDCProviderMetadata. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprivate List<com.nimbusds.jose.JWSAlgorithm>Convert the algorithms represented as strings, into NimbusAlgorithms for later comparison.filterForProviderSupportedAlgorithms(CriteriaSet criteria, List<String> algorithms) Filter the set of algorithms against the set supported by the OpenID Provider.protected voidresolveAndPopulateCredentialAndSignatureAlgorithm(SignatureSigningParameters params, CriteriaSet criteria, Predicate<String> includeExcludePredicate) Resolve and populate the signing credential and signature method algorithm URI on the supplied parameters instance.voidsetProviderMetadataAlgorithmLookupStrategy(Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata, List<String>> strategy) Set the strategy used to locate the supported signing algorithms from the OP's metadata for this resolver instance.Methods inherited from class net.shibboleth.oidc.security.jose.impl.BasicSignatureSigningParametersResolver
credentialSupportsSigningAlgorithm, findCompatibleAlgorithmAndCredential, getAlgorithmRegistry, getAlgorithmRuntimeSupportedPredicate, getEffectiveSignatureAlgorithms, getEffectiveSigningCredentials, getIncludeExcludePredicate, logResult, resolve, resolveSingle, setAlgorithmRegistry, validateMethods inherited from class org.opensaml.xmlsec.impl.AbstractSecurityParametersResolver
lookupKeyInfoGenerator, resolveAndPopulateIncludesExcludes, resolveEffectiveExcludes, resolveEffectiveIncludes, resolveIncludeExcludePrecedence, resolveIncludeExcludePredicate
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logLogger. -
providerMetadataAlgorithmLookupStrategy
@Nonnull private Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,List<String>> providerMetadataAlgorithmLookupStrategyA strategy to pull out the correct set of supported algorithms from theOIDCProviderMetadata. By default returns null, signalling 'do not filter'.
-
-
Constructor Details
-
RelyingPartySigningParametersResolver
public RelyingPartySigningParametersResolver()Constructor.
-
-
Method Details
-
setProviderMetadataAlgorithmLookupStrategy
public void setProviderMetadataAlgorithmLookupStrategy(@Nonnull Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata, List<String>> strategy) Set the strategy used to locate the supported signing algorithms from the OP's metadata for this resolver instance. For example, id_token or request object signing algorithms.- Parameters:
strategy- the strategy
-
resolveAndPopulateCredentialAndSignatureAlgorithm
protected void resolveAndPopulateCredentialAndSignatureAlgorithm(@Nonnull SignatureSigningParameters params, @Nonnull CriteriaSet criteria, @Nonnull Predicate<String> includeExcludePredicate) Description copied from class:BasicSignatureSigningParametersResolverResolve and populate the signing credential and signature method algorithm URI on the supplied parameters instance.- Overrides:
resolveAndPopulateCredentialAndSignatureAlgorithmin classBasicSignatureSigningParametersResolver- Parameters:
params- the parameters instance being populatedcriteria- the input criteria being evaluatedincludeExcludePredicate- the include/exclude predicate with which to evaluate the candidate signing method algorithm URIs
-
convertSupportAlgorithmsToJwkAlgorithms
@Nonnull private List<com.nimbusds.jose.JWSAlgorithm> convertSupportAlgorithmsToJwkAlgorithms(@Nonnull List<String> algos) Convert the algorithms represented as strings, into NimbusAlgorithms for later comparison.- Parameters:
algos- the algorithms to convert- Returns:
- the converted algorithms
-
filterForProviderSupportedAlgorithms
private List<String> filterForProviderSupportedAlgorithms(@Nonnull CriteriaSet criteria, @Nonnull List<String> algorithms) Filter the set of algorithms against the set supported by the OpenID Provider. Always returns a new list reference. The ordering of the input algorithms should be preserved.- Parameters:
criteria- the criteria to extract the OP's metadata from to check supported algorithms.algorithms- the current set of supported algorithms- Returns:
- the current set of supported algorithms filtered by those also supported by the OP.
-