Class ReceivedEndpointSecurityHandler
java.lang.Object
net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
org.opensaml.messaging.handler.AbstractMessageHandler
org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler
- All Implemented Interfaces:
Component,DestructableComponent,InitializableComponent,MessageHandler
Message handler which checks the validity of the SAML protocol message receiver
endpoint against requirements indicated in the message.
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate NonnullSupplier<javax.servlet.http.HttpServletRequest>The HttpServletRequest being processed.private org.slf4j.LoggerLogger.private URIComparatorThe URI comparator to use in performing the validation. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voidcheckEndpointURI(MessageContext messageContext, URIComparator comparator) Check the validity of the SAML protocol message receiver endpoint against requirements indicated in the message.protected booleancompareEndpointURIs(String messageDestination, String receiverEndpoint, URIComparator comparator) Compare the message endpoint URI's specified.protected voidprotected voiddoInvoke(MessageContext messageContext) Performs the handler logic.javax.servlet.http.HttpServletRequestGet the HTTP servlet request being processed.NonnullSupplier<javax.servlet.http.HttpServletRequest>Get the supplier for HTTP request if available.Get the URI comparator instance to use.voidsetHttpServletRequestSupplier(NonnullSupplier<javax.servlet.http.HttpServletRequest> requestSupplier) Set the current HTTP request Supplier.voidsetURIComparator(URIComparator comparator) Set the URI comparator instance to use.Methods inherited from class org.opensaml.messaging.handler.AbstractMessageHandler
doPostInvoke, doPostInvoke, doPreInvoke, getActivationCondition, getLogPrefix, invoke, setActivationConditionMethods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.utilities.java.support.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private org.slf4j.Logger logLogger. -
uriComparator
The URI comparator to use in performing the validation. -
httpServletRequestSupplier
@NonnullAfterInit private NonnullSupplier<javax.servlet.http.HttpServletRequest> httpServletRequestSupplierThe HttpServletRequest being processed.
-
-
Constructor Details
-
ReceivedEndpointSecurityHandler
public ReceivedEndpointSecurityHandler()Constructor.
-
-
Method Details
-
getURIComparator
Get the URI comparator instance to use.- Returns:
- the uriComparator.
-
setURIComparator
Set the URI comparator instance to use.- Parameters:
comparator- the new URI comparator to use
-
getHttpServletRequest
Get the HTTP servlet request being processed.- Returns:
- Returns the request.
-
getHttpServletRequestSupplier
@Nullable public NonnullSupplier<javax.servlet.http.HttpServletRequest> getHttpServletRequestSupplier()Get the supplier for HTTP request if available.- Returns:
- current HTTP request
-
setHttpServletRequestSupplier
public void setHttpServletRequestSupplier(@Nullable NonnullSupplier<javax.servlet.http.HttpServletRequest> requestSupplier) Set the current HTTP request Supplier.- Parameters:
requestSupplier- Supplier for the current HTTP request
-
doInitialize
- Overrides:
doInitializein classAbstractInitializableComponent- Throws:
ComponentInitializationException
-
doInvoke
Performs the handler logic.- Specified by:
doInvokein classAbstractMessageHandler- Parameters:
messageContext- the message context on which to invoke the handler- Throws:
MessageHandlerException- if there is an error invoking the handler on the message context
-
compareEndpointURIs
protected boolean compareEndpointURIs(@Nonnull @NotEmpty String messageDestination, @Nonnull @NotEmpty String receiverEndpoint, @Nonnull URIComparator comparator) throws URIException Compare the message endpoint URI's specified.The comparison is performed using the specified instance of
URIComparator.- Parameters:
messageDestination- the intended message destination endpoint URIreceiverEndpoint- the endpoint URI at which the message was receivedcomparator- the comparator instance to use- Returns:
- true if the endpoints are equivalent, false otherwise
- Throws:
URIException- if one of the URI's to evaluate is invalid
-
checkEndpointURI
protected void checkEndpointURI(@Nonnull MessageContext messageContext, @Nonnull URIComparator comparator) throws MessageHandlerException Check the validity of the SAML protocol message receiver endpoint against requirements indicated in the message.- Parameters:
messageContext- current message contextcomparator- the URI comparator instance to use, if null an internal default will be used- Throws:
MessageHandlerException- thrown if the message was received at an endpoint consistent with message requirements, or if there is a problem decoding and processing the message Destination or receiver endpoint information
-