Class AddAudienceRestrictionToAssertions

    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Class logger.
      • addingAudiencesToExistingRestriction

        private boolean addingAudiencesToExistingRestriction
        Whether, if an assertion already contains an audience restriction, this action will add its audiences to that restriction or create another one.
      • response

        @Nullable
        private SAMLObject response
        Response to modify.
    • Constructor Detail

      • AddAudienceRestrictionToAssertions

        public AddAudienceRestrictionToAssertions()
        Constructor.
    • Method Detail

      • setResponseLookupStrategy

        public void setResponseLookupStrategy​(@Nonnull
                                              Function<ProfileRequestContext,​SAMLObject> strategy)
        Set the strategy used to locate the Response to operate on.
        Parameters:
        strategy - lookup strategy
      • setAddingAudiencesToExistingRestriction

        public void setAddingAudiencesToExistingRestriction​(boolean addingToExistingRestriction)
        Set whether, if an assertion already contains an audience restriction, this action will add its audiences to that restriction or create another one.
        Parameters:
        addingToExistingRestriction - whether this action will add its audiences to that restriction or create another one
      • setAudienceRestrictionsLookupStrategy

        public void setAudienceRestrictionsLookupStrategy​(@Nonnull
                                                          Function<ProfileRequestContext,​Collection<String>> strategy)
        Set the strategy used to obtain the audience restrictions to apply.
        Parameters:
        strategy - lookup strategy
      • doPreExecute

        protected boolean doPreExecute​(@Nonnull
                                       ProfileRequestContext profileRequestContext)
        Called prior to execution, actions may override this method to perform pre-processing for a request.

        If false is returned, execution will not proceed, and the action should attach an EventContext to the context tree to signal how to continue with overall workflow processing.

        If returning successfully, the last step should be to return the result of the superclass version of this method.

        Overrides:
        doPreExecute in class AbstractConditionalProfileAction
        Parameters:
        profileRequestContext - the current IdP profile request context
        Returns:
        true iff execution should proceed
      • doExecute

        protected void doExecute​(@Nonnull
                                 ProfileRequestContext profileRequestContext)
        Performs this action. Actions must override this method to perform their work.
        Overrides:
        doExecute in class AbstractProfileAction
        Parameters:
        profileRequestContext - the current IdP profile request context
      • addAudienceRestriction

        private void addAudienceRestriction​(@Nonnull
                                            ProfileRequestContext profileRequestContext,
                                            @Nonnull
                                            Conditions conditions)
        Add the audiences obtained from a lookup function to the AudienceRestriction. If no AudienceRestriction exists on the given Conditions one is created and added.
        Parameters:
        profileRequestContext - current profile request context
        conditions - condition that has, or will receive the created, AudienceRestriction
      • getAudienceRestriction

        @Nonnull
        private AudienceRestriction getAudienceRestriction​(@Nonnull
                                                           Conditions conditions)
        Get the AudienceRestriction to which audiences will be added.
        Parameters:
        conditions - existing set of conditions
        Returns:
        the condition to which audiences will be added