Class ValidateTokenClaims
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.sp.oidc.profile.impl.ValidateTokenClaims
- All Implemented Interfaces:
net.shibboleth.shared.component.Component,net.shibboleth.shared.component.DestructableComponent,net.shibboleth.shared.component.InitializableComponent,org.opensaml.profile.action.ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class ValidateTokenClaims
extends net.shibboleth.idp.profile.AbstractProfileAction
Action that validates the claims of a JWT using the supplied
claims validator. The verifier must be thread-safe and validate.
If validation succeeds, processing continues normally. If validation fails,
an OidcEventIds.INVALID_TOKEN event is raised and the validation error
is recorded in the agent output under ConsumerConstants.VALIDATION_ERRORS.
A configurable cleanup hook may be invoked after validation completes, regardless of success or failure.
- Event:
EventIds.PROCEED_EVENT_ID,AuthnEventIds.INVALID_AUTHN_CTX,OidcEventIds.INVALID_TOKEN- Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null
,JWT.getJWTClaimsSet() != null
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate com.nimbusds.jwt.JWTClaimsSetThe parsed claimset.private net.shibboleth.oidc.jwt.claims.ClaimsValidatorThe JWT claims validator used to verify the claimsset.private Consumer<org.opensaml.profile.context.ProfileRequestContext>A cleanup hook to execute after either a successful or unsuccessful claims validation.private Function<org.opensaml.profile.context.ProfileRequestContext,com.nimbusds.jwt.JWT> Strategy used to pull out a JWT to validate from the context.private final org.slf4j.LoggerClass logger. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext) protected voidprotected booleandoPreExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext) voidsetClaimsValidator(net.shibboleth.oidc.jwt.claims.ClaimsValidator validator) Set the JWT claims verifier to use.voidsetCleanupHook(Consumer<org.opensaml.profile.context.ProfileRequestContext> hook) Set the cleanup hook to execute after either a successful or unsuccessful claims validation.voidsetJwtLookupStrategy(Function<org.opensaml.profile.context.ProfileRequestContext, com.nimbusds.jwt.JWT> strategy) Set the lookup strategy that locates the JWT to validate from the context.Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategyMethods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationConditionMethods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplierMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
cleanupHook
A cleanup hook to execute after either a successful or unsuccessful claims validation. -
claimsSet
@NonnullBeforeExec private com.nimbusds.jwt.JWTClaimsSet claimsSetThe parsed claimset. -
claimsValidator
@NonnullAfterInit private net.shibboleth.oidc.jwt.claims.ClaimsValidator claimsValidatorThe JWT claims validator used to verify the claimsset. -
jwtLookupStrategy
@NonnullAfterInit private Function<org.opensaml.profile.context.ProfileRequestContext,com.nimbusds.jwt.JWT> jwtLookupStrategyStrategy used to pull out a JWT to validate from the context.
-
-
Constructor Details
-
ValidateTokenClaims
public ValidateTokenClaims()
-
-
Method Details
-
doInitialize
protected void doInitialize() throws net.shibboleth.shared.component.ComponentInitializationException- Overrides:
doInitializein classnet.shibboleth.shared.component.AbstractInitializableComponent- Throws:
net.shibboleth.shared.component.ComponentInitializationException
-
setJwtLookupStrategy
public void setJwtLookupStrategy(@Nonnull Function<org.opensaml.profile.context.ProfileRequestContext, com.nimbusds.jwt.JWT> strategy) Set the lookup strategy that locates the JWT to validate from the context.- Parameters:
strategy- the strategy
-
setCleanupHook
public void setCleanupHook(@Nullable Consumer<org.opensaml.profile.context.ProfileRequestContext> hook) Set the cleanup hook to execute after either a successful or unsuccessful claims validation.- Parameters:
hook- cleanup hook
-
setClaimsValidator
public void setClaimsValidator(@Nonnull net.shibboleth.oidc.jwt.claims.ClaimsValidator validator) Set the JWT claims verifier to use.- Parameters:
validator- the claims validator.
-
doPreExecute
protected boolean doPreExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext) - Overrides:
doPreExecutein classorg.opensaml.profile.action.AbstractConditionalProfileAction
-
doExecute
protected void doExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext) - Overrides:
doExecutein classorg.opensaml.profile.action.AbstractProfileAction
-