Class ServerQDLScriptHandler
- java.lang.Object
-
- org.oa4mp.server.loader.oauth2.claims.ServerQDLScriptHandler
-
- All Implemented Interfaces:
Serializable,PayloadHandler
public class ServerQDLScriptHandler extends Object implements PayloadHandler
This is a handler for all scripts that the user may set in the configuration. These scripts are run before any that the client defines so this is the first handler if present. Mostly this is vessel for conveying the scripts.Created by Jeff Gaynor
on 4/30/22 at 5:52 AM- See Also:
- Serialized Form
-
-
Constructor Summary
Constructors Constructor Description ServerQDLScriptHandler(ServerQDLScriptHandlerConfig config)
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidaddRequestState(edu.uiuc.ncsa.security.util.scripting.ScriptRunRequest req)For the server script, request everything.voidcheckClaims()Called after the runner has gotten the claims so that this class can check integrity.org.kordamp.json.JSONObjectexecute(ClaimSource source, org.kordamp.json.JSONObject claims)Runs this specific claim source against the internal state of this class.voidfinish(String execPhase)Called at the very end of all processing, this lets the handler, clean up or whatever it needs to do.org.kordamp.json.JSONObjectgetAtData()org.kordamp.json.JSONObjectgetExtendedAttributes()Gets the extended attributes from the current transaction.org.kordamp.json.JSONObjectgetPayload()The payload for this is the actual token created (payload is the middle of a JWT, e.g.)ServerQDLScriptHandlerConfiggetPhCfg()intgetResponseCode()org.kordamp.json.JSONObjectgetRTData()TokenImplgetSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key)TokenImplgetSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key, String headerType)Take the payload of this and sign it with the given key, using the header as needed.List<ClaimSource>getSources()Must be empty since there are no sourcesorg.kordamp.json.JSONObjectgetUserMetaData()voidhandleResponse(edu.uiuc.ncsa.security.util.scripting.ScriptRunResponse resp)This takes the response from a script and unmarshalls the resourcesbooleanhasScript()voidinit()Creates and initializes the claims object this class manages.voidrefresh()If the claims need to be updated (e.g. for a refresh and the timestamps need adjusting) this method needs to be called.voidrefreshAccountingInformation()This is used on refresh only.voidsaveState(String execPhase)Called at the end of each block, this lets the handler save its state.voidsetAccountingInformation()This sets the accounting information (such as the expiration and such) for a token.voidsetAtData(org.kordamp.json.JSONObject atData)voidsetClaims(org.kordamp.json.JSONObject claims)voidsetExtendedAttributes(org.kordamp.json.JSONObject extendedAttributes)voidsetPayload(org.kordamp.json.JSONObject payload)voidsetPhCfg(PayloadHandlerConfig phCfg)voidsetResponseCode(int responseCode)voidsetRTData(org.kordamp.json.JSONObject rtData)
-
-
-
Constructor Detail
-
ServerQDLScriptHandler
public ServerQDLScriptHandler(ServerQDLScriptHandlerConfig config)
-
-
Method Detail
-
init
public void init() throws ThrowableDescription copied from interface:PayloadHandlerCreates and initializes the claims object this class manages.- Specified by:
initin interfacePayloadHandler- Throws:
Throwable
-
refresh
public void refresh() throws ThrowableDescription copied from interface:PayloadHandlerIf the claims need to be updated (e.g. for a refresh and the timestamps need adjusting) this method needs to be called. It's contract is to reget all of the claims.- Specified by:
refreshin interfacePayloadHandler- Throws:
Throwable
-
addRequestState
public void addRequestState(edu.uiuc.ncsa.security.util.scripting.ScriptRunRequest req) throws ThrowableFor the server script, request everything. This allows for complete access as needed, so if a script, e.g., wants to set up all values in the pre_auth stage, it can do it once and be done, rather than require it to set it in increments.- Specified by:
addRequestStatein interfacePayloadHandler- Parameters:
req-- Throws:
Throwable
-
getRTData
public org.kordamp.json.JSONObject getRTData()
-
setRTData
public void setRTData(org.kordamp.json.JSONObject rtData)
-
checkClaims
public void checkClaims() throws ThrowableDescription copied from interface:PayloadHandlerCalled after the runner has gotten the claims so that this class can check integrity. For instance, an OIDC server would need to see that the subject is set properly. SciTokens needs to check that its scopes (aka resource permissions) were set- Specified by:
checkClaimsin interfacePayloadHandler- Throws:
Throwable
-
getSources
public List<ClaimSource> getSources() throws Throwable
Must be empty since there are no sources- Specified by:
getSourcesin interfacePayloadHandler- Returns:
- Throws:
Throwable
-
execute
public org.kordamp.json.JSONObject execute(ClaimSource source, org.kordamp.json.JSONObject claims) throws Throwable
Description copied from interface:PayloadHandlerRuns this specific claim source against the internal state of this class. Note that the contract is that it returns the updated claims and if there are no new claims, it should just return its claims argument.- Specified by:
executein interfacePayloadHandler- Returns:
- Throws:
Throwable
-
finish
public void finish(String execPhase) throws Throwable
Description copied from interface:PayloadHandlerCalled at the very end of all processing, this lets the handler, clean up or whatever it needs to do. It is called beforePayloadHandler.saveState(String)()}.- Specified by:
finishin interfacePayloadHandler- Parameters:
execPhase- - the current execution phase.- Throws:
Throwable
-
saveState
public void saveState(String execPhase) throws Throwable
Description copied from interface:PayloadHandlerCalled at the end of each block, this lets the handler save its state. Note that for OA4MP, the state is saved in the transaction which is saved once after the handlers run. Only put actual save code in here if needed, since it is apt to get called a lot.- Specified by:
saveStatein interfacePayloadHandler- Throws:
Throwable
-
getUserMetaData
public org.kordamp.json.JSONObject getUserMetaData()
-
setClaims
public void setClaims(org.kordamp.json.JSONObject claims)
-
getExtendedAttributes
public org.kordamp.json.JSONObject getExtendedAttributes()
Gets the extended attributes from the current transaction. SeeOA2ServiceTransaction.getExtendedAttributes()for more.- Specified by:
getExtendedAttributesin interfacePayloadHandler- Returns:
-
setExtendedAttributes
public void setExtendedAttributes(org.kordamp.json.JSONObject extendedAttributes)
-
setAccountingInformation
public void setAccountingInformation()
Description copied from interface:PayloadHandlerThis sets the accounting information (such as the expiration and such) for a token. This is called when a token is created or refreshed.- Specified by:
setAccountingInformationin interfacePayloadHandler
-
refreshAccountingInformation
public void refreshAccountingInformation()
Description copied from interface:PayloadHandlerThis is used on refresh only. It will reset all the standard accounting information (such as timestamps) for an existing claims object.Usage
Create an instance of the handler with the constructor for any state, then invoke this method.- Specified by:
refreshAccountingInformationin interfacePayloadHandler
-
getPhCfg
public ServerQDLScriptHandlerConfig getPhCfg()
- Specified by:
getPhCfgin interfacePayloadHandler
-
setPhCfg
public void setPhCfg(PayloadHandlerConfig phCfg)
- Specified by:
setPhCfgin interfacePayloadHandler
-
hasScript
public boolean hasScript()
- Specified by:
hasScriptin interfacePayloadHandler
-
setResponseCode
public void setResponseCode(int responseCode)
- Specified by:
setResponseCodein interfacePayloadHandler
-
getResponseCode
public int getResponseCode()
- Specified by:
getResponseCodein interfacePayloadHandler
-
getAtData
public org.kordamp.json.JSONObject getAtData()
-
setAtData
public void setAtData(org.kordamp.json.JSONObject atData)
-
handleResponse
public void handleResponse(edu.uiuc.ncsa.security.util.scripting.ScriptRunResponse resp) throws ThrowableDescription copied from interface:PayloadHandlerThis takes the response from a script and unmarshalls the resources- Specified by:
handleResponsein interfacePayloadHandler- Throws:
Throwable
-
getPayload
public org.kordamp.json.JSONObject getPayload()
Description copied from interface:PayloadHandlerThe payload for this is the actual token created (payload is the middle of a JWT, e.g.)- Specified by:
getPayloadin interfacePayloadHandler- Returns:
-
setPayload
public void setPayload(org.kordamp.json.JSONObject payload)
- Specified by:
setPayloadin interfacePayloadHandler
-
getSignedPayload
public TokenImpl getSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key)
- Specified by:
getSignedPayloadin interfacePayloadHandler
-
getSignedPayload
public TokenImpl getSignedPayload(edu.uiuc.ncsa.security.util.jwk.JSONWebKey key, String headerType)
Description copied from interface:PayloadHandlerTake the payload of this and sign it with the given key, using the header as needed.- Specified by:
getSignedPayloadin interfacePayloadHandler- Returns:
-
-