Class EncryptNameIDs

    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Class logger.
      • message

        @Nullable
        private SAMLObject message
        The message to operate on.
    • Constructor Detail

      • EncryptNameIDs

        public EncryptNameIDs()
        Constructor.
    • Method Detail

      • setExcludedFormats

        public void setExcludedFormats​(@Nonnull @NonnullElements
                                       Collection<String> formats)
        Set the NameID formats to ignore and leave unencrypted.
        Parameters:
        formats - formats to exclude
      • getApplicableParameters

        @Nullable
        protected EncryptionParameters getApplicableParameters​(@Nullable
                                                               EncryptionContext ctx)
        Return the right set of parameters for the operation to be performed, or none if no encryption should occur.
        Specified by:
        getApplicableParameters in class AbstractEncryptAction
        Parameters:
        ctx - possibly null input context to pull parameters from
        Returns:
        the right parameter set, or null for none
      • doPreExecute

        protected boolean doPreExecute​(@Nonnull
                                       ProfileRequestContext profileRequestContext)
        Called prior to execution, actions may override this method to perform pre-processing for a request.

        If false is returned, execution will not proceed, and the action should attach an EventContext to the context tree to signal how to continue with overall workflow processing.

        If returning successfully, the last step should be to return the result of the superclass version of this method.

        Overrides:
        doPreExecute in class AbstractEncryptAction
        Parameters:
        profileRequestContext - the current IdP profile request context
        Returns:
        true iff execution should proceed
      • doExecute

        protected void doExecute​(@Nonnull
                                 ProfileRequestContext profileRequestContext)
        Performs this action. Actions must override this method to perform their work.
        Overrides:
        doExecute in class AbstractProfileAction
        Parameters:
        profileRequestContext - the current IdP profile request context
      • shouldEncrypt

        private boolean shouldEncrypt​(@Nullable
                                      NameID name)
        Return true iff the NameID should be encrypted.
        Parameters:
        name - NameID to check
        Returns:
        true iff encryption should happen
      • processSubject

        private void processSubject​(@Nullable
                                    Subject subject)
                             throws EncryptionException
        Encrypt any NameIDs found in a subject and replace them with the result.
        Parameters:
        subject - subject to operate on
        Throws:
        EncryptionException - if an error occurs
      • processLogoutRequest

        private void processLogoutRequest​(@Nonnull
                                          LogoutRequest request)
                                   throws EncryptionException
        Encrypt a NameID found in a LogoutRequest and replace it with the result.
        Parameters:
        request - request to operate on
        Throws:
        EncryptionException - if an error occurs