Class UserInfoResponseDecoder

java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
net.shibboleth.oidc.profile.decoding.impl.AbstractJSONResponseDecoderFunction<com.nimbusds.openid.connect.sdk.UserInfoResponse>
net.shibboleth.oidc.profile.decoding.impl.UserInfoResponseDecoder
All Implemented Interfaces:
Component, DestructableComponent, InitializableComponent, org.apache.hc.core5.http.io.HttpClientResponseHandler<com.nimbusds.openid.connect.sdk.UserInfoResponse>

public class UserInfoResponseDecoder extends AbstractJSONResponseDecoderFunction<com.nimbusds.openid.connect.sdk.UserInfoResponse>
A UserInfo response decoder. Supports both plain JSON Object and JWT responses.

Importantly,the decoder *must not ever* decode a JWT response as a plain response type, otherwise the signature check may not be performed downstream - although other validation for the plain object type should. That is, we can not rely solely on the content-type header in-case of content-type header injection attacks — the logic that builds either the JWT or plain response should fail, or at least present an invalid UserInfo response token. Any decoding error is logged and null is returned.

  • Field Details

    • USERINFO_ERROR_RESPONSE_HEADER

      @Nonnull public static final String USERINFO_ERROR_RESPONSE_HEADER
      The UserInfo response header that carries error information.
      See Also:
    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
  • Constructor Details

    • UserInfoResponseDecoder

      public UserInfoResponseDecoder()
      Constructor.
  • Method Details

    • doHandleResponse

      public com.nimbusds.openid.connect.sdk.UserInfoResponse doHandleResponse(@Nullable org.apache.hc.core5.http.ClassicHttpResponse httpResponse)
      Description copied from class: AbstractJSONResponseDecoderFunction
      Do the actual response processing and return a result. Overridden by implementation classes.
      Specified by:
      doHandleResponse in class AbstractJSONResponseDecoderFunction<com.nimbusds.openid.connect.sdk.UserInfoResponse>
      Parameters:
      httpResponse - the http response
    • serializeMessageForLogging

      protected String serializeMessageForLogging(@Nullable com.nimbusds.openid.connect.sdk.UserInfoResponse response)
      Serialize the message for logging purposes.

      Default implementation is to return the message object's Object.toString(), but subclasses should override if a better message-specific serialization mechanism exists.

      Overrides:
      serializeMessageForLogging in class AbstractJSONResponseDecoderFunction<com.nimbusds.openid.connect.sdk.UserInfoResponse>
      Parameters:
      response - the response message to serialize
      Returns:
      the serialized message, or null if message can not be serialized