Class AuthenticationAudienceClaimsValidator
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent
net.shibboleth.oidc.jwt.claims.AbstractClaimsValidator
net.shibboleth.oidc.security.jwt.claims.impl.AudienceClaimsValidator
net.shibboleth.oidc.security.jwt.claims.impl.AuthenticationAudienceClaimsValidator
- All Implemented Interfaces:
ClaimsValidator,Component,DestructableComponent,IdentifiableComponent,IdentifiedComponent,InitializableComponent
@ThreadSafeAfterInit
public class AuthenticationAudienceClaimsValidator
extends AudienceClaimsValidator
Verifies the Audience (aud) claim contains the appropriate value in JWT authentication. This validator extends the
functionality of
AudienceClaimsValidator with two features. First, it contains a configurable strategy for
resolving responder ID that may be used in the audience claim. Second, it can be configured to replace configurable
substrings from the audience claim into a configurable replacement. This is useful when token endpoint URL is
desired to be accepted in some other endpoints.
The AudienceClaimsValidator.resolveAcceptedAudiences(JWTClaimsSet, ProfileRequestContext) is expected
to return the endpoint URL used in the HTTP request containing the JWT authentication.- Since:
- 2.2.0
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate StringThe replacement substring for the endpoint containing any ones configured atendpointTargets.The substrings to replace from resolved endpoint with one configured atendpointReplacement.private Function<ProfileRequestContext,String> Lookup function for the responder identifier. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionresolveAcceptedAudiences(JWTClaimsSet claims, ProfileRequestContext context) Resolve the set of accepted audiences.voidsetEndpointReplacement(String path) Set the replacement substring for the endpoint containing any ones configured atendpointTargets.voidsetEndpointTargets(List<String> paths) Set the substrings to replace from resolved endpoint with one configured atendpointReplacement.voidSet the lookup function for the responder identifier.Methods inherited from class net.shibboleth.oidc.security.jwt.claims.impl.AudienceClaimsValidator
doInitialize, doValidate, setAdditionalAudiencesLookupStrategy, setAllowMissing, setAudienceLookupStrategy, setExtraAudienceValidationMethods inherited from class net.shibboleth.oidc.jwt.claims.AbstractClaimsValidator
setActivationCondition, validateMethods inherited from class net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent
setIdMethods inherited from class net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent
ensureId, getId, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentExceptionMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.IdentifiableComponent
setIdMethods inherited from interface net.shibboleth.shared.component.IdentifiedComponent
getId
-
Field Details
-
responderIdLookupStrategy
Lookup function for the responder identifier. -
endpointTargets
The substrings to replace from resolved endpoint with one configured atendpointReplacement. -
endpointReplacement
The replacement substring for the endpoint containing any ones configured atendpointTargets.
-
-
Constructor Details
-
AuthenticationAudienceClaimsValidator
public AuthenticationAudienceClaimsValidator()Constructor.
-
-
Method Details
-
setResponderIdLookupStrategy
Set the lookup function for the responder identifier.- Parameters:
strategy- What to set.
-
setEndpointTargets
Set the substrings to replace from resolved endpoint with one configured atendpointReplacement.- Parameters:
paths- What to set.
-
setEndpointReplacement
Set the replacement substring for the endpoint containing any ones configured atendpointTargets.- Parameters:
path- What to set.
-
resolveAcceptedAudiences
@Nonnull @NotEmpty protected Set<String> resolveAcceptedAudiences(@Nonnull JWTClaimsSet claims, @Nonnull ProfileRequestContext context) throws JWTValidationException Resolve the set of accepted audiences. The accepted audience resolved by the super-classAudienceClaimsValidatoris expected to be an endpoint URL of the HTTP request containing the JWT authentication. IfendpointTargetsandendpointReplacementare configured, they're exploited in adding the an additional accepted audience. The responder ID is also included to the accepted audience values.- Overrides:
resolveAcceptedAudiencesin classAudienceClaimsValidator- Parameters:
claims- the claims fed for the audience lookup strategycontext- the profile request context fed for the audience lookup strategy- Returns:
- the set containing the accepted audience values
- Throws:
JWTValidationException- if the audience value could not be resolved via lookup strategy
-