Class AuthenticationAudienceClaimsValidator

All Implemented Interfaces:
ClaimsValidator, Component, DestructableComponent, IdentifiableComponent, IdentifiedComponent, InitializableComponent

@ThreadSafeAfterInit public class AuthenticationAudienceClaimsValidator extends AudienceClaimsValidator
Verifies the Audience (aud) claim contains the appropriate value in JWT authentication. This validator extends the functionality of AudienceClaimsValidator with two features. First, it contains a configurable strategy for resolving responder ID that may be used in the audience claim. Second, it can be configured to replace configurable substrings from the audience claim into a configurable replacement. This is useful when token endpoint URL is desired to be accepted in some other endpoints. The AudienceClaimsValidator.resolveAcceptedAudiences(JWTClaimsSet, ProfileRequestContext) is expected to return the endpoint URL used in the HTTP request containing the JWT authentication.
Since:
2.2.0
  • Field Details

    • responderIdLookupStrategy

      @Nonnull private Function<ProfileRequestContext,String> responderIdLookupStrategy
      Lookup function for the responder identifier.
    • endpointTargets

      @Nonnull private List<String> endpointTargets
      The substrings to replace from resolved endpoint with one configured at endpointReplacement.
    • endpointReplacement

      @Nullable private String endpointReplacement
      The replacement substring for the endpoint containing any ones configured at endpointTargets.
  • Constructor Details

    • AuthenticationAudienceClaimsValidator

      public AuthenticationAudienceClaimsValidator()
      Constructor.
  • Method Details

    • setResponderIdLookupStrategy

      public void setResponderIdLookupStrategy(@Nonnull Function<ProfileRequestContext,String> strategy)
      Set the lookup function for the responder identifier.
      Parameters:
      strategy - What to set.
    • setEndpointTargets

      public void setEndpointTargets(@Nonnull List<String> paths)
      Set the substrings to replace from resolved endpoint with one configured at endpointReplacement.
      Parameters:
      paths - What to set.
    • setEndpointReplacement

      public void setEndpointReplacement(@Nullable String path)
      Set the replacement substring for the endpoint containing any ones configured at endpointTargets.
      Parameters:
      path - What to set.
    • resolveAcceptedAudiences

      @Nonnull @NotEmpty protected Set<String> resolveAcceptedAudiences(@Nonnull JWTClaimsSet claims, @Nonnull ProfileRequestContext context) throws JWTValidationException
      Resolve the set of accepted audiences. The accepted audience resolved by the super-class AudienceClaimsValidator is expected to be an endpoint URL of the HTTP request containing the JWT authentication. If endpointTargets and endpointReplacement are configured, they're exploited in adding the an additional accepted audience. The responder ID is also included to the accepted audience values.
      Overrides:
      resolveAcceptedAudiences in class AudienceClaimsValidator
      Parameters:
      claims - the claims fed for the audience lookup strategy
      context - the profile request context fed for the audience lookup strategy
      Returns:
      the set containing the accepted audience values
      Throws:
      JWTValidationException - if the audience value could not be resolved via lookup strategy