Class RelyingPartySigningParametersResolver

All Implemented Interfaces:
SignatureSigningParametersResolver, Resolver<SignatureSigningParameters,CriteriaSet>

public class RelyingPartySigningParametersResolver extends BasicSignatureSigningParametersResolver
A specialization of BasicSignatureSigningParametersResolver which supports selecting signing credentials from client_secret credential criterion (e.g. from the relying party configuration) in addition to the configured signing credentials inside the signing configuration (determined by the superclass).

The OpenID Providers's metadata is also used to filter for those algorithms supported by the OP in addition to those supported by the security configuration.

*

In addition to the Criterion inputs documented in BasicSignatureSigningParametersResolver, the following inputs are also supported:

  • Field Details

    • log

      @Nonnull private final org.slf4j.Logger log
      Logger.
    • providerMetadataAlgorithmLookupStrategy

      @Nonnull private Function<OIDCProviderMetadata,List<String>> providerMetadataAlgorithmLookupStrategy
      A strategy to pull out the correct set of supported algorithms from the OIDCProviderMetadata. By default returns null, signalling 'do not filter'.
  • Constructor Details

    • RelyingPartySigningParametersResolver

      public RelyingPartySigningParametersResolver()
      Constructor.
  • Method Details

    • setProviderMetadataAlgorithmLookupStrategy

      public void setProviderMetadataAlgorithmLookupStrategy(@Nonnull Function<OIDCProviderMetadata,List<String>> strategy)
      Set the strategy used to locate the supported signing algorithms from the OP's metadata for this resolver instance. For example, id_token or request object signing algorithms.
      Parameters:
      strategy - the strategy
    • resolveAndPopulateCredentialAndSignatureAlgorithm

      protected void resolveAndPopulateCredentialAndSignatureAlgorithm(@Nonnull SignatureSigningParameters params, @Nonnull CriteriaSet criteria, @Nonnull Predicate<String> includeExcludePredicate)
      Resolve and populate the signing credential and signature method algorithm URI on the supplied parameters instance.
      Overrides:
      resolveAndPopulateCredentialAndSignatureAlgorithm in class BasicSignatureSigningParametersResolver
      Parameters:
      params - the parameters instance being populated
      criteria - the input criteria being evaluated
      includeExcludePredicate - the include/exclude predicate with which to evaluate the candidate signing method algorithm URIs
    • filterForProviderSupportedAlgorithms

      @Nonnull @NotLive @Unmodifiable private List<String> filterForProviderSupportedAlgorithms(@Nonnull CriteriaSet criteria, @Nonnull List<String> algorithms)
      Filter the set of algorithms against the set supported by the OpenID Provider. Always returns a new list reference. The ordering of the input algorithms should be preserved.
      Parameters:
      criteria - the criteria to extract the OP's metadata from to check supported algorithms.
      algorithms - the current set of supported algorithms
      Returns:
      the current set of supported algorithms filtered by those also supported by the OP.