Package net.shibboleth.idp.authn.impl
Class AttributeSourcedSubjectCanonicalization
- java.lang.Object
-
- net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
-
- org.opensaml.profile.action.AbstractProfileAction
-
- org.opensaml.profile.action.AbstractConditionalProfileAction
-
- net.shibboleth.idp.profile.AbstractProfileAction
-
- net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction
-
- net.shibboleth.idp.authn.impl.AttributeSourcedSubjectCanonicalization
-
- All Implemented Interfaces:
net.shibboleth.utilities.java.support.component.Component,net.shibboleth.utilities.java.support.component.DestructableComponent,net.shibboleth.utilities.java.support.component.InitializableComponent,org.opensaml.profile.action.ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class AttributeSourcedSubjectCanonicalization extends net.shibboleth.idp.authn.AbstractSubjectCanonicalizationActionAn action that extracts a resolvedIdPAttributevalue from anAttributeContextchild obtained via lookup function (by default a child of theSubjectCanonicalizationContext), and uses it as the result of subject canonicalization.This action operates on a set of previously resolved attributes that are presumed to have been generated based in some fashion on the content of the
SubjectCanonicalizationContext.String and scoped attribute values are supported.
- Event:
EventIds.PROCEED_EVENT_ID,AuthnEventIds.INVALID_SUBJECT- Precondition:
ProfileRequestContext.getSubcontext(SubjectCanonicalizationContext.class) != null
- Postcondition:
SubjectCanonicalizationContext.getPrincipalName() != null || SubjectCanonicalizationContext.getException() != null
-
-
Field Summary
Fields Modifier and Type Field Description private Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.attribute.context.AttributeContext>attributeContextLookupStrategyLookup strategy forAttributeContextto read from.private net.shibboleth.idp.attribute.context.AttributeContextattributeCtxThe context to read from.private List<String>attributeSourceIdsOrdered list of attributes to look for and read from.private chardelimiterDelimiter to use for scoped attribute serialization.private org.slf4j.LoggerlogClass logger.
-
Constructor Summary
Constructors Constructor Description AttributeSourcedSubjectCanonicalization()Constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description protected voiddoExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext, net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)protected voiddoInitialize()protected booleandoPreExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext, net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)voidsetAttributeContextLookupStrategy(Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.attribute.context.AttributeContext> strategy)Set the lookup strategy for theAttributeContextto read from.voidsetAttributeSourceIds(List<String> ids)Set the attribute IDs to read from in order of preference.voidsetScopedDelimiter(char ch)Set the delimiter to use for serializing scoped attribute values.-
Methods inherited from class net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction
applyTransforms, doExecute, doPreExecute, setLookupStrategy, setLowercase, setTransforms, setTrim, setUppercase
-
Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getMessage, getMessage, getMessage, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy
-
Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationCondition
-
Methods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, execute, getHttpServletRequest, getHttpServletResponse, getLogPrefix, setHttpServletRequest, setHttpServletResponse
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, initialize, isDestroyed, isInitialized
-
-
-
-
Field Detail
-
log
@Nonnull private final org.slf4j.Logger log
Class logger.
-
delimiter
private char delimiter
Delimiter to use for scoped attribute serialization.
-
attributeSourceIds
@Nonnull @NonnullElements private List<String> attributeSourceIds
Ordered list of attributes to look for and read from.
-
attributeContextLookupStrategy
@Nonnull private Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.attribute.context.AttributeContext> attributeContextLookupStrategy
Lookup strategy forAttributeContextto read from.
-
attributeCtx
@Nullable private net.shibboleth.idp.attribute.context.AttributeContext attributeCtx
The context to read from.
-
-
Method Detail
-
setScopedDelimiter
public void setScopedDelimiter(char ch)
Set the delimiter to use for serializing scoped attribute values.- Parameters:
ch- delimiter to use
-
setAttributeSourceIds
public void setAttributeSourceIds(@Nonnull @NonnullElements List<String> ids)Set the attribute IDs to read from in order of preference.- Parameters:
ids- attribute IDs to read from
-
setAttributeContextLookupStrategy
public void setAttributeContextLookupStrategy(@Nonnull Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.attribute.context.AttributeContext> strategy)Set the lookup strategy for theAttributeContextto read from.- Parameters:
strategy- lookup strategy
-
doInitialize
protected void doInitialize() throws net.shibboleth.utilities.java.support.component.ComponentInitializationException- Overrides:
doInitializein classnet.shibboleth.utilities.java.support.component.AbstractInitializableComponent- Throws:
net.shibboleth.utilities.java.support.component.ComponentInitializationException
-
doPreExecute
protected boolean doPreExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext, @Nonnull net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)- Overrides:
doPreExecutein classnet.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction
-
doExecute
protected void doExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext, @Nonnull net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)- Overrides:
doExecutein classnet.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction
-
-