Class ProxyAwareDefaultOIDCAuthenticationContextClassRequestLookupFunction

java.lang.Object
net.shibboleth.oidc.profile.config.navigate.ProxyAwareDefaultOIDCAuthenticationContextClassRequestLookupFunction
All Implemented Interfaces:
Function<ProfileRequestContext,Collection<AuthenticationContextClassReferencePrincipal>>

public class ProxyAwareDefaultOIDCAuthenticationContextClassRequestLookupFunction extends Object implements Function<ProfileRequestContext,Collection<AuthenticationContextClassReferencePrincipal>>
Implements a set of default logic for determining the custom principals to derive the OIDC ACRs from.

This operates for the SAML to OIDC proxy use case. The values returned are empty unless the parent context itself contains a child context carrying particular values. The values are either 'passed through' or mapped by the given principal mappings. All input values are either SAML ACRs or AMRs, and all output values are OIDC ACRs.