Class AuthenticationAudienceClaimsValidator
- java.lang.Object
-
- net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
-
- net.shibboleth.utilities.java.support.component.AbstractIdentifiedInitializableComponent
-
- net.shibboleth.utilities.java.support.component.AbstractIdentifiableInitializableComponent
-
- net.shibboleth.oidc.jwt.claims.AbstractClaimsValidator
-
- net.shibboleth.oidc.security.jwt.claims.impl.AudienceClaimsValidator
-
- net.shibboleth.oidc.security.jwt.claims.impl.AuthenticationAudienceClaimsValidator
-
- All Implemented Interfaces:
ClaimsValidator,Component,DestructableComponent,IdentifiableComponent,IdentifiedComponent,InitializableComponent
@ThreadSafeAfterInit public class AuthenticationAudienceClaimsValidator extends AudienceClaimsValidator
Verifies the Audience (aud) claim contains the appropriate value in JWT authentication. This validator extends the functionality ofAudienceClaimsValidatorwith two features. First, it contains a configurable strategy for resolving responder ID that may be used in the audience claim. Second, it can be configured to replace configurable substrings from the audience claim into a configurable replacement. This is useful when token endpoint URL is desired to be accepted in some other endpoints. TheAudienceClaimsValidator.resolveAcceptedAudiences(JWTClaimsSet, ProfileRequestContext)is expected to return the endpoint URL used in the HTTP request containing the JWT authentication.- Since:
- 2.2.0
-
-
Field Summary
Fields Modifier and Type Field Description private StringendpointReplacementThe replacement substring for the endpoint containing any ones configured atendpointTargets.private List<String>endpointTargetsThe substrings to replace from resolved endpoint with one configured atendpointReplacement.private Function<ProfileRequestContext,String>responderIdLookupStrategyLookup function for the responder identifier.
-
Constructor Summary
Constructors Constructor Description AuthenticationAudienceClaimsValidator()Constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description protected Set<String>resolveAcceptedAudiences(com.nimbusds.jwt.JWTClaimsSet claims, ProfileRequestContext context)Resolve the set of accepted audiences.voidsetEndpointReplacement(String path)Set the replacement substring for the endpoint containing any ones configured atendpointTargets.voidsetEndpointTargets(List<String> paths)Set the substrings to replace from resolved endpoint with one configured atendpointReplacement.voidsetResponderIdLookupStrategy(Function<ProfileRequestContext,String> strategy)Set the lookup function for the responder identifier.-
Methods inherited from class net.shibboleth.oidc.security.jwt.claims.impl.AudienceClaimsValidator
doInitialize, doValidate, setAdditionalAudiencesLookupStrategy, setAllowMissing, setAudienceLookupStrategy, setExtraAudienceValidation
-
Methods inherited from class net.shibboleth.oidc.jwt.claims.AbstractClaimsValidator
setActivationCondition, validate
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractIdentifiableInitializableComponent
setId
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractIdentifiedInitializableComponent
getId
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, initialize, isDestroyed, isInitialized
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface net.shibboleth.utilities.java.support.component.IdentifiableComponent
setId
-
Methods inherited from interface net.shibboleth.utilities.java.support.component.IdentifiedComponent
getId
-
-
-
-
Field Detail
-
responderIdLookupStrategy
@Nonnull private Function<ProfileRequestContext,String> responderIdLookupStrategy
Lookup function for the responder identifier.
-
endpointTargets
@Nonnull private List<String> endpointTargets
The substrings to replace from resolved endpoint with one configured atendpointReplacement.
-
endpointReplacement
@Nullable private String endpointReplacement
The replacement substring for the endpoint containing any ones configured atendpointTargets.
-
-
Method Detail
-
setResponderIdLookupStrategy
public void setResponderIdLookupStrategy(@Nonnull Function<ProfileRequestContext,String> strategy)Set the lookup function for the responder identifier.- Parameters:
strategy- What to set.
-
setEndpointTargets
public void setEndpointTargets(@Nonnull List<String> paths)Set the substrings to replace from resolved endpoint with one configured atendpointReplacement.- Parameters:
paths- What to set.
-
setEndpointReplacement
public void setEndpointReplacement(@Nullable String path)Set the replacement substring for the endpoint containing any ones configured atendpointTargets.- Parameters:
path- What to set.
-
resolveAcceptedAudiences
@Nonnull @NotEmpty protected Set<String> resolveAcceptedAudiences(@Nonnull com.nimbusds.jwt.JWTClaimsSet claims, @Nonnull ProfileRequestContext context) throws JWTValidationException
Resolve the set of accepted audiences. The accepted audience resolved by the super-classAudienceClaimsValidatoris expected to be an endpoint URL of the HTTP request containing the JWT authentication. IfendpointTargetsandendpointReplacementare configured, they're exploited in adding the an additional accepted audience. The responder ID is also included to the accepted audience values.- Overrides:
resolveAcceptedAudiencesin classAudienceClaimsValidator- Parameters:
claims- the claims fed for the audience lookup strategycontext- the profile request context fed for the audience lookup strategy- Returns:
- the set containing the accepted audience values
- Throws:
JWTValidationException- if the audience value could not be resolved via lookup strategy
-
-