Class NimbusClient
- java.lang.Object
-
- net.shibboleth.idp.plugin.authn.duo.AbstractDuoOIDCClient
-
- net.shibboleth.idp.plugin.authn.duo.nimbus.impl.NimbusClient
-
- All Implemented Interfaces:
DuoOIDCClient,DuoOIDCClientCapabilities
@ThreadSafe @Immutable public final class NimbusClient extends AbstractDuoOIDCClient
A Duo client using the Nimbus OIDC library.
-
-
Field Summary
Fields Modifier and Type Field Description private static StringCLIENT_ASSERTION_TYPEThe only supported client assertion type.private DuoOIDCIntegrationduoIntegrationThe integration to help generate the JWT.private org.apache.http.client.HttpClienthttpClientHttpClient for contacting Duo.private HttpClientSecurityParametershttpClientSecurityParametersHTTP client security parameters.private static StringHTTPSThe HTTPS scheme.private org.slf4j.LoggerlogClass logger.private com.fasterxml.jackson.databind.ObjectMapperobjectMapperJSON object mapper.
-
Constructor Summary
Constructors Constructor Description NimbusClient(DuoOIDCIntegration integration, org.apache.http.client.HttpClient client, HttpClientSecurityParameters params, com.fasterxml.jackson.databind.ObjectMapper oMapper)Package-private Constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description StringcreateAuthUrl(String username, String state, String nonce, String redirectURIOverride)com.nimbusds.jwt.JWTexchangeAuthorizationCodeFor2FAResult(String code, String username, String redirectURIOverride)private <T> TexecuteRequest(org.apache.http.client.methods.HttpUriRequest request, com.fasterxml.jackson.core.type.TypeReference<T> wrapperTypeRef)Performs a call to a Duo OIDC endpoint.DuoHealthCheckhealthCheck()booleanisSupportsNonce()-
Methods inherited from class net.shibboleth.idp.plugin.authn.duo.AbstractDuoOIDCClient
getCapabilities, getClientId
-
-
-
-
Field Detail
-
CLIENT_ASSERTION_TYPE
@Nonnull @NotEmpty private static final String CLIENT_ASSERTION_TYPE
The only supported client assertion type.- See Also:
- Constant Field Values
-
HTTPS
@Nonnull @NotEmpty private static final String HTTPS
The HTTPS scheme.- See Also:
- Constant Field Values
-
log
@Nonnull private final org.slf4j.Logger log
Class logger.
-
duoIntegration
@Nonnull private final DuoOIDCIntegration duoIntegration
The integration to help generate the JWT.
-
httpClient
@Nonnull private final org.apache.http.client.HttpClient httpClient
HttpClient for contacting Duo.
-
httpClientSecurityParameters
@Nullable private final HttpClientSecurityParameters httpClientSecurityParameters
HTTP client security parameters.
-
objectMapper
@Nonnull private final com.fasterxml.jackson.databind.ObjectMapper objectMapper
JSON object mapper.
-
-
Constructor Detail
-
NimbusClient
NimbusClient(@Nonnull DuoOIDCIntegration integration, @Nonnull org.apache.http.client.HttpClient client, @Nullable HttpClientSecurityParameters params, @Nonnull com.fasterxml.jackson.databind.ObjectMapper oMapper)Package-private Constructor.Should only be instantiated by the
NimbusClientFactory.- Parameters:
integration- the integration to create the client for, nevernullclient- the Http client to use to execute HTTP requests, nevernullparams- any security parameters to use for the Http client, can benull.oMapper- the JSON object mapper, nevernull.
-
-
Method Detail
-
healthCheck
@Nonnull public DuoHealthCheck healthCheck() throws DuoClientException
- Throws:
DuoClientException
-
createAuthUrl
@Nonnull public String createAuthUrl(@Nonnull @NotEmpty String username, @Nonnull @NotEmpty String state, @Nullable String nonce, @Nullable String redirectURIOverride) throws DuoClientException
- Throws:
DuoClientException
-
exchangeAuthorizationCodeFor2FAResult
public com.nimbusds.jwt.JWT exchangeAuthorizationCodeFor2FAResult(@Nonnull String code, @Nonnull String username, @Nullable String redirectURIOverride) throws DuoClientException- Throws:
DuoClientException
-
executeRequest
private <T> T executeRequest(@Nonnull org.apache.http.client.methods.HttpUriRequest request, @Nonnull com.fasterxml.jackson.core.type.TypeReference<T> wrapperTypeRef) throws DuoClientExceptionPerforms a call to a Duo OIDC endpoint. Iff successful, the JSON response is mapped into the appropriate type.- Type Parameters:
T- the response type- Parameters:
request- the prepared HTTP requestwrapperTypeRef- the type to deserialise the JSON into- Returns:
- the response type, never
null. - Throws:
DuoClientException- if there is an error producing a response
-
isSupportsNonce
public boolean isSupportsNonce()
-
-