Class ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy
- java.lang.Object
-
- net.shibboleth.oidc.security.impl.AbstractEncryptionAlgorithmsLookupStrategy
-
- net.shibboleth.oidc.security.jose.impl.DefaultKeyTransportEncryptionAlgorithmsLookupStrategy
-
- net.shibboleth.oidc.security.jose.impl.ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy
-
- All Implemented Interfaces:
BiFunction<CriteriaSet,Predicate<String>,List<String>>
public class ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy extends DefaultKeyTransportEncryptionAlgorithmsLookupStrategy
A lookup strategy that finds key transport algorithms from local configuration that are compatible with those advertised by the downstream OpenID Provider.The set of supported and configured key transport ('alg') algorithms are derived from the intersection of those supported by local configuration and those supported by the downstream OpenID Provider. The order of those algorithms in the local configuration are preserved. As algorithm 'alg' support is optional in provider metadata, failure to locate them will result in the default behaviour of the parent class being applied (resolve from local configuration). If they are present, but are not compatible with the set configured in the encryption configuration, no algorithms are returned (a failure).
-
-
Field Summary
Fields Modifier and Type Field Description private org.slf4j.LoggerlogLogger.private Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,List<String>>providerKeyTransportAlgorithmsLookupStrategyA strategy to locate the algorithms ('alg') appropriate for the JWT to be encrypted.
-
Constructor Summary
Constructors Constructor Description ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy(Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,List<String>> strategy)Constructor.ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy(Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,List<String>> strategy, AlgorithmRegistry registry)Constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description List<String>apply(CriteriaSet criteria, Predicate<String> includeExcludePredicate)-
Methods inherited from class net.shibboleth.oidc.security.jose.impl.DefaultKeyTransportEncryptionAlgorithmsLookupStrategy
getKeyTransportAlgorithmsFromConfiguration
-
Methods inherited from class net.shibboleth.oidc.security.impl.AbstractEncryptionAlgorithmsLookupStrategy
findAlgorithmIntersection, getAlgorithmRegistry, getAlgorithmRuntimeSupportedPredicate
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface java.util.function.BiFunction
andThen
-
-
-
-
Field Detail
-
log
@Nonnull private final org.slf4j.Logger log
Logger.
-
providerKeyTransportAlgorithmsLookupStrategy
@Nonnull private final Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,List<String>> providerKeyTransportAlgorithmsLookupStrategy
A strategy to locate the algorithms ('alg') appropriate for the JWT to be encrypted. Can returnnullif the metadata does not describe its supported algorithms (which is optional).
-
-
Constructor Detail
-
ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy
public ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy(@Nonnull @ParameterName(name="providerKeyTransportAlgorithmsLookupStrategy") Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,List<String>> strategy, @Nullable @ParameterName(name="AlgorithmRegistry") AlgorithmRegistry registry)
Constructor.- Parameters:
strategy- the strategy used to locate the algorithms ('alg') from the OpenID Provider metadata appropriate for the JWT to be encrypted.registry- the algorithm registry to used when resolving algorithm URIs. Can benull.
-
ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy
public ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy(@Nonnull @ParameterName(name="providerKeyTransportAlgorithmsLookupStrategy") Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,List<String>> strategy)
Constructor.- Parameters:
strategy- the strategy used to locate the algorithms ('alg') from the OpenID Provider metadata appropriate for the JWT to be encrypted.
-
-
Method Detail
-
apply
public List<String> apply(CriteriaSet criteria, Predicate<String> includeExcludePredicate)
- Specified by:
applyin interfaceBiFunction<CriteriaSet,Predicate<String>,List<String>>- Overrides:
applyin classDefaultKeyTransportEncryptionAlgorithmsLookupStrategy
-
-