Class IDTokenHandler
- java.lang.Object
-
- org.oa4mp.server.loader.oauth2.claims.AbstractPayloadHandler
-
- org.oa4mp.server.loader.oauth2.claims.IDTokenHandler
-
- All Implemented Interfaces:
Serializable,IDTokenHandlerInterface,PayloadHandler,OA2Scopes
public class IDTokenHandler extends AbstractPayloadHandler implements IDTokenHandlerInterface
Created by Jeff Gaynor
on 2/16/20 at 6:51 AM- See Also:
- Serialized Form
-
-
Nested Class Summary
-
Nested classes/interfaces inherited from interface org.oa4mp.delegation.server.OA2Scopes
OA2Scopes.ScopeUtil
-
-
Field Summary
Fields Modifier and Type Field Description static StringID_TOKEN_BASIC_HANDLER_TYPEstatic StringID_TOKEN_DEFAULT_HANDLER_TYPEprotected Stringissuer-
Fields inherited from class org.oa4mp.server.loader.oauth2.claims.AbstractPayloadHandler
client, oa2se, payload, request, transaction
-
Fields inherited from interface org.oa4mp.delegation.server.OA2Scopes
basicScopes, EDU_PERSON_ORC_ID, nonPublicScopes, SCOPE_ADDRESS, SCOPE_CILOGON_INFO, SCOPE_EMAIL, SCOPE_MYPROXY, SCOPE_OFFLINE_ACCESS, SCOPE_OPENID, SCOPE_PHONE, SCOPE_PROFILE, SCOPE_TOKEN_MANAGER, SCOPE_USER_INFO
-
-
Constructor Summary
Constructors Constructor Description IDTokenHandler(PayloadHandlerConfigImpl payloadHandlerConfig)
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidaddRequestState(edu.uiuc.ncsa.security.util.scripting.ScriptRunRequest req)Marshall any resources this script needs to make a request.protected voidcheckClaim(org.kordamp.json.JSONObject claims, String claimKey)Enforces that the claim exists in the claims argument.voidcheckClaims()Called after the runner has gotten the claims so that this class can check integrity.protected voidcheckRequiredScopes(OA2ServiceTransaction t)Use this to check for any requires scopes that the request must have.org.kordamp.json.JSONObjectexecute(ClaimSource source, org.kordamp.json.JSONObject claims)Runs this specific claim source against the internal state of this class.voidfinish(String execPhase)For CIL-499.org.kordamp.json.JSONObjectgetPayload()The payload for this is the actual token created (payload is the middle of a JWT, e.g.)Collection<String>getScopes()Contract is to return the current scopes.IDTokenImplgetSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key)IDTokenImplgetSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key, String headerType)Take the payload of this and sign it with the given key, using the header as needed.List<ClaimSource>getSources()These are the sources that the runner will use to populate the claimsorg.kordamp.json.JSONObjectgetUserMetaData()voidhandleResponse(edu.uiuc.ncsa.security.util.scripting.ScriptRunResponse resp)This takes the response from a script and unmarshalls the resourcesvoidinit()Creates and initializes the claims object this class manages.protected voidNEWrefreshAccountingInformation()protected voidpermissiveFinish(Collection<String> configuredScopes, String execPhase)Permissive finish = whittle down certain claims that are not explicit, and pass back everything else.voidrefreshAccountingInformation()This is used on refresh only.protected voidrestrictiveFinish(Collection<String> scopes, String execPhase)Restrictive finish = user must explicitly request things and will be limited to them.voidsaveState(String execPhase)Called at the end of each block, this lets the handler save its state.voidsetAccountingInformation()This sets the accounting information (such as the expiration and such) for a token.protected voidsetCurrentClaim(org.kordamp.json.JSONObject currentClaims, org.kordamp.json.JSONObject finalClaims, String key)protected voidsetIssuer(javax.servlet.http.HttpServletRequest request)voidsetUserMetaData(org.kordamp.json.JSONObject userMetaData)-
Methods inherited from class org.oa4mp.server.loader.oauth2.claims.AbstractPayloadHandler
doServerVariables, doSubstitution, getExtendedAttributes, getPhCfg, getResponseCode, getTXRecord, hasScript, hasTXRecord, isEmpty, listToString, refresh, setExtendedAttributes, setPayload, setPhCfg, setResponseCode
-
-
-
-
Field Detail
-
issuer
protected String issuer
-
ID_TOKEN_DEFAULT_HANDLER_TYPE
public static final String ID_TOKEN_DEFAULT_HANDLER_TYPE
- See Also:
- Constant Field Values
-
ID_TOKEN_BASIC_HANDLER_TYPE
public static final String ID_TOKEN_BASIC_HANDLER_TYPE
- See Also:
- Constant Field Values
-
-
Constructor Detail
-
IDTokenHandler
public IDTokenHandler(PayloadHandlerConfigImpl payloadHandlerConfig)
-
-
Method Detail
-
getPayload
public org.kordamp.json.JSONObject getPayload()
Description copied from interface:PayloadHandlerThe payload for this is the actual token created (payload is the middle of a JWT, e.g.)- Specified by:
getPayloadin interfacePayloadHandler- Returns:
-
getUserMetaData
public org.kordamp.json.JSONObject getUserMetaData()
- Specified by:
getUserMetaDatain interfaceIDTokenHandlerInterface
-
setUserMetaData
public void setUserMetaData(org.kordamp.json.JSONObject userMetaData)
- Specified by:
setUserMetaDatain interfaceIDTokenHandlerInterface
-
setIssuer
protected void setIssuer(javax.servlet.http.HttpServletRequest request)
-
init
public void init() throws ThrowableDescription copied from interface:PayloadHandlerCreates and initializes the claims object this class manages.- Specified by:
initin interfacePayloadHandler- Throws:
Throwable
-
refreshAccountingInformation
public void refreshAccountingInformation()
Description copied from interface:PayloadHandlerThis is used on refresh only. It will reset all the standard accounting information (such as timestamps) for an existing claims object.Usage
Create an instance of the handler with the constructor for any state, then invoke this method.- Specified by:
refreshAccountingInformationin interfacePayloadHandler
-
NEWrefreshAccountingInformation
protected void NEWrefreshAccountingInformation()
-
setAccountingInformation
public void setAccountingInformation()
Description copied from interface:PayloadHandlerThis sets the accounting information (such as the expiration and such) for a token. This is called when a token is created or refreshed.- Specified by:
setAccountingInformationin interfacePayloadHandler
-
addRequestState
public void addRequestState(edu.uiuc.ncsa.security.util.scripting.ScriptRunRequest req) throws ThrowableDescription copied from interface:PayloadHandlerMarshall any resources this script needs to make a request. I.e., add specific state (if needed) from this handler to theScriptRunRequest.- Specified by:
addRequestStatein interfacePayloadHandler- Throws:
Throwable
-
handleResponse
public void handleResponse(edu.uiuc.ncsa.security.util.scripting.ScriptRunResponse resp) throws ThrowableDescription copied from interface:PayloadHandlerThis takes the response from a script and unmarshalls the resources- Specified by:
handleResponsein interfacePayloadHandler- Overrides:
handleResponsein classAbstractPayloadHandler- Throws:
Throwable
-
checkClaims
public void checkClaims() throws ThrowableDescription copied from interface:PayloadHandlerCalled after the runner has gotten the claims so that this class can check integrity. For instance, an OIDC server would need to see that the subject is set properly. SciTokens needs to check that its scopes (aka resource permissions) were set- Specified by:
checkClaimsin interfacePayloadHandler- Throws:
Throwable
-
getSources
public List<ClaimSource> getSources() throws Throwable
Description copied from interface:PayloadHandlerThese are the sources that the runner will use to populate the claims- Specified by:
getSourcesin interfacePayloadHandler- Returns:
- Throws:
Throwable
-
finish
public void finish(String execPhase) throws Throwable
For CIL-499. It is possible to remove key claims with functors and return unusable claims objects. This method will check that claims that must be present are there or will raise a server-side exception.- Specified by:
finishin interfacePayloadHandler- Parameters:
execPhase- - the current execution phase.- Throws:
Throwable
-
getScopes
public Collection<String> getScopes()
Contract is to return the current scopes. If these are not overridden, return the original scopes, which as still in effect.- Returns:
-
restrictiveFinish
protected void restrictiveFinish(Collection<String> scopes, String execPhase) throws Throwable
Restrictive finish = user must explicitly request things and will be limited to them. The model here is that the claim source gets whatever, but the results are filtered to a restricted subset.- Parameters:
execPhase-- Throws:
Throwable
-
permissiveFinish
protected void permissiveFinish(Collection<String> configuredScopes, String execPhase) throws Throwable
Permissive finish = whittle down certain claims that are not explicit, and pass back everything else. This is needed for scripting where claims may be simply added. If a client is set to strict scopes, adding claims in a script will have them stripped off. CILogon uses this by default since the scopes they get come from SAML assertions- Parameters:
execPhase-- Throws:
Throwable
-
setCurrentClaim
protected void setCurrentClaim(org.kordamp.json.JSONObject currentClaims, org.kordamp.json.JSONObject finalClaims, String key)
-
saveState
public void saveState(String execPhase) throws Throwable
Description copied from interface:PayloadHandlerCalled at the end of each block, this lets the handler save its state. Note that for OA4MP, the state is saved in the transaction which is saved once after the handlers run. Only put actual save code in here if needed, since it is apt to get called a lot.- Specified by:
saveStatein interfacePayloadHandler- Overrides:
saveStatein classAbstractPayloadHandler- Throws:
Throwable
-
checkRequiredScopes
protected void checkRequiredScopes(OA2ServiceTransaction t) throws Throwable
Use this to check for any requires scopes that the request must have. It is usually best to check these in the transaction since they have been normalized there, but the request is supplied too for completeness.- Parameters:
t-- Throws:
Throwable
-
checkClaim
protected void checkClaim(org.kordamp.json.JSONObject claims, String claimKey)Enforces that the claim exists in the claims argument. This is mostly used for the openid scope. An error is raised if ths claim is missing.- Parameters:
claims-claimKey-
-
execute
public org.kordamp.json.JSONObject execute(ClaimSource source, org.kordamp.json.JSONObject claims) throws Throwable
Description copied from interface:PayloadHandlerRuns this specific claim source against the internal state of this class. Note that the contract is that it returns the updated claims and if there are no new claims, it should just return its claims argument.- Specified by:
executein interfacePayloadHandler- Overrides:
executein classAbstractPayloadHandler- Returns:
- Throws:
Throwable
-
getSignedPayload
public IDTokenImpl getSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key)
- Specified by:
getSignedPayloadin interfacePayloadHandler
-
getSignedPayload
public IDTokenImpl getSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key, String headerType)
Description copied from interface:PayloadHandlerTake the payload of this and sign it with the given key, using the header as needed.- Specified by:
getSignedPayloadin interfacePayloadHandler- Returns:
-
-