All Classes and Interfaces
Class
Description
Abstract base class for lookup functions that require access to both
AgentRequestContext
and RelyingPartyContext from a MessageContext.Either the input or output DDF message from the agent.
Abstract class for actions based on the
AuthenticationResponse located under
the InOutOperationContext.getInboundMessageContext().AbstractHttpOAuthAction<T extends com.nimbusds.oauth2.sdk.Response>
An abstract class for OIDC/OAuth actions that make synchronous HTTP requests and return types of
responses.Base class for message handlers that process and apply values of OpenID Connect logout requests.
AbstractProviderMetadataLookupFunction<F extends org.opensaml.messaging.context.BaseContext,ResultType>
An abstract base class for pulling out the OpenID Provider metadata.
Abstract predicate for pulling out the
UserInfoResponseContext.Base class for looking up the UserInfo token response context.
An action that adds, if enabled in profile config, the client address to State Data.
Locates the
ProviderMetadataResolver associated with the Application making an agent request.A strategy function that extracts requested Authentication Context Class References (ACRs)
from the inbound
MessageContext and returns them as a list of ACR objects.Lookup strategy that returns the
OIDCAuthenticationRequest from the outbound message context.A DTO class that carries OIDC specific authentication request information that needs to be recovered to validate the
authentication response.
A
Function that produces StateData representing authentication request state that is required
for validating the authentication response.Lookup function that returns the time at which the RP sent the authentication request, as taken from the
authentication request state object recovered when the response delivered via the Agent.
Get the OAuth 2.0 authorization endpoint from the OpenID Provider metadata.
Has the auth_time claim been requested? This is taken from the authentication request state.
A basic implementation of
OIDCProtocolSupportService.Action that creates a Request Object
JWT, and sets it to the work context
OIDCAuthenticationRequest located under InOutOperationContext.getOutboundMessageContext().A strategy that adapts a
Function into a BiFunction for clientId lookup.A lookup strategy that locates the ClientID, used in a logout request.
A context to hold the browser bound correlation cookie referenced from the OAuth state.
An action that looks up
StateData using a configured lookup strategy and adds it to a
StateDataContext obtained from the profile request context using a configured creation strategy.A default merging strategy for combing claims in the UserInfo response with those from the id_token.
Retrieve the 'display' parameter from either the
DDF if present, or the profile configuration.Function that extracts the UserInfo JWT from the
UserInfoResponseContext iff it is an EncryptedJWT
type.Action to exchange the authorization code in the authentication response for an OAuth access token which
contains an OIDC id_token.
An action that extracts OIDC End-User claims from the combined id_token and UserInfo response claims in the
EndUserClaimsContext.Retrieve the ForceAuthn parameter.
Determine if the id_token_hint parameter should be used based on the relying party configuration setting.
A lookup strategy that locates the ID Token, used as a hint in a logout request, from the
OIDCLogoutContext.An action that creates an
OIDCAuthenticationRequest shell to populate in future steps,
and sets it to the outbound message context.An action that creates an
OIDCLogoutRequest shell to populate in future steps,
and sets it to the outbound message context.An
action that resolves the Client Authentication method for the chosen
OpenID Provider (issuer) from the profile configuration, and adds it to the
OAuth2ClientAuthenticationContext.An
action that resolves the client identifier and redirect URI for the chosen
provider (issuer).Initialize an outbound message context with an OIDC peer entity context ready for an authorization/authentication
request to be built.
An action that initializes the
OIDCPeerEntityContext based on the issuer value from the StateData.Action that adds a
RelyingPartyContext to the current ProfileRequestContext tree via a creation
function.A predicate that determines if the client authentication method chosen is a JWT type.
Extract the
Payload from the Request Object inside the OIDCAuthenticationRequest.Retrieve the 'login_hint' parameter from the
DDF if it is present and
the Hub configuration has not disallowed the Agent from setting it.Activation condition which returns true only if the id_token_hint parameter has not been set.
A strategy to set the logout_hint from a claim inside the ID Token.
A function that returns the
OIDCLogoutRequest from the given MessageContext.A DTO class that carries OIDC specific logout request information that needs to be recovered to validate the
logout response.
A
Function that produces StateData representing logout request state that is required
for validating the logout response (if there is one).Locate the maximum authentication age from the authentication request state.
Retrieve the max_age parameter from the
DDF if present.Lookup strategy that finds the id_token nonce from the
AuthenticationRequestStateData.A simple strategy that uses a secure random implementation to generate a nonce of length 16.
A context to store information pertaining to the OAuth2 state parameter.
OIDC related constants.
Constants for OIDC session initiator operations.
Context to handle state for OIDC logout flows.
IdPModule implementation.Details about the SP OIDC protocol plugin.
OIDC subinterface of
ProtocolSupportService to add any OIDC-specific features or services.Handler for inbound OIDC protocol messages that attempts to locate OIDC metadata for a OP (issuer),
and attaches it with a
OIDCMetadataContext as a child of a pre-existing instance of MessageContext.Support class for OIDC related implementations.
Extract the
Payload from the Request Object inside the OIDCAuthenticationRequest.A lookup strategy that retrieves the PKCE Code verifier from the
AuthenticationRequestStateData stored in the
StateDataContext associated with a ProfileRequestContext.A strategy function that looks up
PKCEOptions from a MessageContext
by consulting the OIDCAuthenticationRelyingPartyProfileConfiguration associated
with the current request context.Retrieve the 'post_logout_redirect_uri' parameter from the
SPConstants.TARGET in the DDF if present.Determine if the post_logout_redirect_uri parameter should be set based on relying party configuration settings.
OIDC-specific subclass of a token consumer response action.
Action that adds an inbound
MessageContext and a OIDCPeerEntityContext to the
ProfileRequestContext based on the identity of a relying party.OAuth/OIDC-specific action that processes the state token by setting it as the state value.
Process the end-user claims from the id_token and possible UserInfo claims sets.
Processes a request to potentially initiate a OIDC RP-Initiated logout by examining the input to recover
the required id_token information from the opaque portion of the session created by the token consumer
flow and store in a newly created
OIDCLogoutContext.Retrieve the Prompt parameter from the
DDF.A strategy to locate the end_session_endpoint (logout) of the OP from it's discovery metadata.
A lookup strategy that retrieves the response location from the
AuthenticationRequestStateData stored in the
StateDataContext associated with a ProfileRequestContext, converts it to a redirect_uri
and returns it.Pull a redirect_uri from the Relying Party profile config if present.
Retrieve the 'redirect_uri' parameter from the 'response_url' in the
DDF.Strategy that looks up any requested ACR claims from the saved off authentication request state.
An activation condition that activates if the profile configuration indicates that ACR value in the id_token
should be validated against those in the request.
A lookup strategy that resolves an
OIDCClaimsRequest from the current MessageContext.A predicate that tests whether a request object should be built based on what is configured in the profile
configuration and whether the OP supports it.
Pull out the request object supported signature signing algorithms from the metadata.
Consumer that adds the
JWT back to the Request Object in the OIDCAuthenticationRequest.Is successful TLS credential verification enough to validate the JWT in question or should JWT signature validation
be applied? Defaults to true — signature verification is required.
A strategy function that extracts and validates resource indicators from the inbound
MessageContext and
returns them as a list of URI objects.A lookup strategy that resolves an OpenID Connect
ResponseMode from the
OIDCAuthenticationRelyingPartyProfileConfiguration.A lookup strategy that resolves an OpenID Connect
ResponseType from the
OIDCAuthenticationRelyingPartyProfileConfiguration.A strategy function that extracts Scope from the inbound
MessageContext and returns them as a set of
Strings.A consumer that sets the decoded issuer value onto the
OIDCPeerEntityContext (creating a peer entity
context if none already exists).Function to perform "standard" extraction of data into attributes.
Lookup strategy that extracts the OAuthn 2.0 authentication response 'state' parameter.
A strategy function that looks up the state value from the token stored in the
StateDataContext.A strategy function that extracts ui_locales from the inbound
MessageContext and returns them as a List of
Strings.Request information from the UserInfo OAuth2.0 endpoint using the access_token already present
in the context.
Consumer strategy to update the UserInfo JWT in the
UserInfoResponseContext.Function that extracts the UserInfo claims as a JWT from the
UserInfoResponseContext.Condition that returns true if the UserInfo response was an plain JSON type i.e.
An action that checks the inbound authentication response indicated success as opposed to an error.
Validation action that validates the OAuth Access Token Response against RFC 6749 section 5.1
and OpenID Connect Core 1.0 section 3.1.3.3.
Action that validates the claims of a JWT using the supplied
claims validator.Validate a successful UserInfo JSON Object Response according to section 5.3.2 of OpenID Connect Core 1.0.
Produce a claims set from the JWT claims set without either the validation claims or claims with null values.
Class for getting and printing the version of the plugin.