Class ValidateTokenClaims

java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
org.opensaml.profile.action.AbstractProfileAction
org.opensaml.profile.action.AbstractConditionalProfileAction
net.shibboleth.idp.profile.AbstractProfileAction
net.shibboleth.sp.oidc.profile.impl.ValidateTokenClaims
All Implemented Interfaces:
net.shibboleth.shared.component.Component, net.shibboleth.shared.component.DestructableComponent, net.shibboleth.shared.component.InitializableComponent, org.opensaml.profile.action.ProfileAction, Aware, MessageSource, MessageSourceAware, Action

public class ValidateTokenClaims extends net.shibboleth.idp.profile.AbstractProfileAction
Action that validates the claims of a JWT using the supplied claims validator. The verifier must be thread-safe and validate.

If validation succeeds, processing continues normally. If validation fails, an OidcEventIds.INVALID_TOKEN event is raised and the validation error is recorded in the agent output under ConsumerConstants.VALIDATION_ERRORS.

A configurable cleanup hook may be invoked after validation completes, regardless of success or failure.

Event:
EventIds.PROCEED_EVENT_ID, AuthnEventIds.INVALID_AUTHN_CTX, OidcEventIds.INVALID_TOKEN
Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class, false) != null
,
JWT.getJWTClaimsSet() != null
  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    private com.nimbusds.jwt.JWTClaimsSet
    The parsed claimset.
    private net.shibboleth.oidc.jwt.claims.ClaimsValidator
    The JWT claims validator used to verify the claimsset.
    private Consumer<org.opensaml.profile.context.ProfileRequestContext>
    A cleanup hook to execute after either a successful or unsuccessful claims validation.
    private Function<org.opensaml.profile.context.ProfileRequestContext,com.nimbusds.jwt.JWT>
    Strategy used to pull out a JWT to validate from the context.
    private final org.slf4j.Logger
    Class logger.
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    protected void
    doExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext)
     
    protected void
    protected boolean
    doPreExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext)
     
    void
    setClaimsValidator(net.shibboleth.oidc.jwt.claims.ClaimsValidator validator)
    Set the JWT claims verifier to use.
    void
    setCleanupHook(Consumer<org.opensaml.profile.context.ProfileRequestContext> hook)
    Set the cleanup hook to execute after either a successful or unsuccessful claims validation.
    void
    setJwtLookupStrategy(Function<org.opensaml.profile.context.ProfileRequestContext,com.nimbusds.jwt.JWT> strategy)
    Set the lookup strategy that locates the JWT to validate from the context.

    Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction

    doExecute, execute, getBean, getBean, getMessage, getMessage, getMessage, getParameter, getParameter, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy

    Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction

    getActivationCondition, setActivationCondition

    Methods inherited from class org.opensaml.profile.action.AbstractProfileAction

    doPostExecute, doPostExecute, ensureHttpServletRequest, ensureHttpServletResponse, execute, getHttpServletRequest, getHttpServletRequestSupplier, getHttpServletResponse, getHttpServletResponseSupplier, getLogPrefix, isPreExecuteCalled, setHttpServletRequestSupplier, setHttpServletResponseSupplier

    Methods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent

    checkComponentActive, checkSetterPreconditions, destroy, doDestroy, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException, initialize, isDestroyed, isInitialized

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait

    Methods inherited from interface net.shibboleth.shared.component.InitializableComponent

    initialize, isInitialized
  • Field Details

    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
    • cleanupHook

      @Nullable private Consumer<org.opensaml.profile.context.ProfileRequestContext> cleanupHook
      A cleanup hook to execute after either a successful or unsuccessful claims validation.
    • claimsSet

      @NonnullBeforeExec private com.nimbusds.jwt.JWTClaimsSet claimsSet
      The parsed claimset.
    • claimsValidator

      @NonnullAfterInit private net.shibboleth.oidc.jwt.claims.ClaimsValidator claimsValidator
      The JWT claims validator used to verify the claimsset.
    • jwtLookupStrategy

      @NonnullAfterInit private Function<org.opensaml.profile.context.ProfileRequestContext,com.nimbusds.jwt.JWT> jwtLookupStrategy
      Strategy used to pull out a JWT to validate from the context.
  • Constructor Details

    • ValidateTokenClaims

      public ValidateTokenClaims()
  • Method Details

    • doInitialize

      protected void doInitialize() throws net.shibboleth.shared.component.ComponentInitializationException
      Overrides:
      doInitialize in class net.shibboleth.shared.component.AbstractInitializableComponent
      Throws:
      net.shibboleth.shared.component.ComponentInitializationException
    • setJwtLookupStrategy

      public void setJwtLookupStrategy(@Nonnull Function<org.opensaml.profile.context.ProfileRequestContext,com.nimbusds.jwt.JWT> strategy)
      Set the lookup strategy that locates the JWT to validate from the context.
      Parameters:
      strategy - the strategy
    • setCleanupHook

      public void setCleanupHook(@Nullable Consumer<org.opensaml.profile.context.ProfileRequestContext> hook)
      Set the cleanup hook to execute after either a successful or unsuccessful claims validation.
      Parameters:
      hook - cleanup hook
    • setClaimsValidator

      public void setClaimsValidator(@Nonnull net.shibboleth.oidc.jwt.claims.ClaimsValidator validator)
      Set the JWT claims verifier to use.
      Parameters:
      validator - the claims validator.
    • doPreExecute

      protected boolean doPreExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext)
      Overrides:
      doPreExecute in class org.opensaml.profile.action.AbstractConditionalProfileAction
    • doExecute

      protected void doExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext)
      Overrides:
      doExecute in class org.opensaml.profile.action.AbstractProfileAction