Class ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy

  • All Implemented Interfaces:
    BiFunction<CriteriaSet,​Predicate<String>,​List<String>>

    public class ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy
    extends DefaultKeyTransportEncryptionAlgorithmsLookupStrategy
    A lookup strategy that finds key transport algorithms from local configuration that are compatible with those advertised by the downstream OpenID Provider.

    The set of supported and configured key transport ('alg') algorithms are derived from the intersection of those supported by local configuration and those supported by the downstream OpenID Provider. The order of those algorithms in the local configuration are preserved. As algorithm 'alg' support is optional in provider metadata, failure to locate them will result in the default behaviour of the parent class being applied (resolve from local configuration). If they are present, but are not compatible with the set configured in the encryption configuration, no algorithms are returned (a failure).

    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Logger.
      • providerKeyTransportAlgorithmsLookupStrategy

        @Nonnull
        private final Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,​List<String>> providerKeyTransportAlgorithmsLookupStrategy
        A strategy to locate the algorithms ('alg') appropriate for the JWT to be encrypted. Can return null if the metadata does not describe its supported algorithms (which is optional).
    • Constructor Detail

      • ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy

        public ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy​(@Nonnull @ParameterName(name="providerKeyTransportAlgorithmsLookupStrategy")
                                                                              Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,​List<String>> strategy,
                                                                              @Nullable @ParameterName(name="AlgorithmRegistry")
                                                                              AlgorithmRegistry registry)
        Constructor.
        Parameters:
        strategy - the strategy used to locate the algorithms ('alg') from the OpenID Provider metadata appropriate for the JWT to be encrypted.
        registry - the algorithm registry to used when resolving algorithm URIs. Can be null.
      • ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy

        public ProviderMetadataKeyTransportEncryptionAlgorithmsLookupStrategy​(@Nonnull @ParameterName(name="providerKeyTransportAlgorithmsLookupStrategy")
                                                                              Function<com.nimbusds.openid.connect.sdk.op.OIDCProviderMetadata,​List<String>> strategy)
        Constructor.
        Parameters:
        strategy - the strategy used to locate the algorithms ('alg') from the OpenID Provider metadata appropriate for the JWT to be encrypted.