Package net.shibboleth.oidc.profile.impl
Class PopulateJWTEncryptionParameters
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.oidc.profile.impl.PopulateJWTEncryptionParameters
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,ProfileAction,Aware,MessageSource,MessageSourceAware,Action
Action that resolves and populates
EncryptionParameters on an SecurityParametersContext
created/accessed via a lookup function, by default on a child of the outbound message context.
The resolution process is contingent on the active profile configuration requesting encryption.
The default, per-RelyingParty, and default per-profile EncryptionConfiguration
objects are input to the resolution process, along with the relying party's client metadata, any static
credentials configured on the relying party, and the OpenID Provider metadata (which in most cases
will be the source of the eventual encryption key)
- Since:
- 2.2.0
- Event:
EventIds.PROCEED_EVENT_ID,EventIds.INVALID_PROFILE_CTX,EventIds.INVALID_SEC_CFG- Postcondition:
- set the encryption parameters onto the security parameters context
-
Field Summary
FieldsModifier and TypeFieldDescriptionStrategy used to look up a per-requestEncryptionConfigurationlist.private EncryptionParametersResolverResolver for parameters to store into context.private SecurityParametersContextContext to populate.private booleanWhether encryption is optional.private Predicate<ProfileRequestContext>Predicate to determine how to proceed if no encryption parameters are resolved.private StringA friendly name to log as the subject of encryption parameter resolution.private final org.slf4j.LoggerClass logger.Strategy used to look up a OIDC client metadata context.Strategy used to look up a OIDC provider metadata context.Lookup function for relying party context.Strategy used to look up theSecurityParametersContextto extract parameters from. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprivate CriteriaSetbuildCriteriaSet(ProfileRequestContext profileRequestContext, List<EncryptionConfiguration> encryptionConfigurations) Build the criteria used as input to theEncryptionParametersResolver.protected voiddoExecute(ProfileRequestContext profileRequestContext) protected voidprotected booleandoPreExecute(ProfileRequestContext profileRequestContext) voidsetClientMetadataContextLookupStrategy(Function<ProfileRequestContext, OIDCMetadataContext> strategy) Set lookup strategy forOIDCMetadataContextfor input to resolution.voidsetConfigurationLookupStrategy(Function<ProfileRequestContext, List<EncryptionConfiguration>> strategy) Set the strategy used to look up a per-requestEncryptionConfigurationlist.voidsetEncryptionOptional(boolean flag) Sets the boolean condition to apply to determine how to proceed if encryption parameter resolution fails.voidSets the condition to apply to determine how to proceed if encryption parameter resolution fails.voidSet the encParamsresolver to use for the parameters to store into the context.voidsetForFriendlyName(String name) Set the friendly name to log as the subject of encryption parameter resolution.voidsetProviderMetadataContextLookupStrategy(Function<ProfileRequestContext, OIDCProviderMetadataContext> strategy) Set lookup strategy forOIDCProviderMetadataContextfor input to resolution.voidSet lookup strategy for relying party context.voidsetSecurityParametersContextLookupStrategy(Function<ProfileRequestContext, SecurityParametersContext> strategy) Set the lookup strategy to locate the security parameters context.Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
forFriendlyName
A friendly name to log as the subject of encryption parameter resolution. -
encryptionOptionalPredicate
Predicate to determine how to proceed if no encryption parameters are resolved. -
securityParametersContextLookupStrategy
@Nonnull private Function<ProfileRequestContext,SecurityParametersContext> securityParametersContextLookupStrategyStrategy used to look up theSecurityParametersContextto extract parameters from. -
configurationLookupStrategy
@NonnullAfterInit private Function<ProfileRequestContext,List<EncryptionConfiguration>> configurationLookupStrategyStrategy used to look up a per-requestEncryptionConfigurationlist. -
encParamsresolver
Resolver for parameters to store into context. -
oidcClientMetadataContextLookupStrategy
@Nullable private Function<ProfileRequestContext,OIDCMetadataContext> oidcClientMetadataContextLookupStrategyStrategy used to look up a OIDC client metadata context. -
oidcProviderMetadataContextLookupStrategy
@Nullable private Function<ProfileRequestContext,OIDCProviderMetadataContext> oidcProviderMetadataContextLookupStrategyStrategy used to look up a OIDC provider metadata context. -
relyingPartyContextLookupStrategy
@Nonnull private Function<ProfileRequestContext,RelyingPartyContext> relyingPartyContextLookupStrategyLookup function for relying party context. -
encryptionOptional
private boolean encryptionOptionalWhether encryption is optional. -
encryptionContext
Context to populate.
-
-
Constructor Details
-
PopulateJWTEncryptionParameters
public PopulateJWTEncryptionParameters()Constructor.
-
-
Method Details
-
setRelyingPartyContextLookupStrategy
public void setRelyingPartyContextLookupStrategy(@Nonnull Function<ProfileRequestContext, RelyingPartyContext> strategy) Set lookup strategy for relying party context.- Parameters:
strategy- lookup strategy
-
setSecurityParametersContextLookupStrategy
public void setSecurityParametersContextLookupStrategy(Function<ProfileRequestContext, SecurityParametersContext> strategy) Set the lookup strategy to locate the security parameters context.- Parameters:
strategy- the lookup strategy
-
setClientMetadataContextLookupStrategy
public void setClientMetadataContextLookupStrategy(@Nullable Function<ProfileRequestContext, OIDCMetadataContext> strategy) Set lookup strategy forOIDCMetadataContextfor input to resolution.- Parameters:
strategy- lookup strategy
-
setProviderMetadataContextLookupStrategy
public void setProviderMetadataContextLookupStrategy(@Nullable Function<ProfileRequestContext, OIDCProviderMetadataContext> strategy) Set lookup strategy forOIDCProviderMetadataContextfor input to resolution.- Parameters:
strategy- lookup strategy
-
setForFriendlyName
Set the friendly name to log as the subject of encryption parameter resolution.- Parameters:
name- the friendly name
-
setConfigurationLookupStrategy
public void setConfigurationLookupStrategy(@Nonnull Function<ProfileRequestContext, List<EncryptionConfiguration>> strategy) Set the strategy used to look up a per-requestEncryptionConfigurationlist.- Parameters:
strategy- lookup strategy
-
setEncryptionParametersResolver
Set the encParamsresolver to use for the parameters to store into the context.- Parameters:
newResolver- encParamsresolver to use
-
setEncryptionOptionalPredicate
Sets the condition to apply to determine how to proceed if encryption parameter resolution fails.- Parameters:
condition- condition to set
-
setEncryptionOptional
public void setEncryptionOptional(boolean flag) Sets the boolean condition to apply to determine how to proceed if encryption parameter resolution fails.- Parameters:
flag- the flag to set
-
doInitialize
- Overrides:
doInitializein classAbstractInitializableComponent- Throws:
ComponentInitializationException
-
doPreExecute
- Overrides:
doPreExecutein classAbstractConditionalProfileAction
-
doExecute
- Overrides:
doExecutein classAbstractProfileAction
-
buildCriteriaSet
@Nonnull private CriteriaSet buildCriteriaSet(@Nonnull ProfileRequestContext profileRequestContext, @Nonnull List<EncryptionConfiguration> encryptionConfigurations) Build the criteria used as input to theEncryptionParametersResolver.- Parameters:
profileRequestContext- current profile request contextencryptionConfigurations- active configurations- Returns:
- the criteria set to use
-