Class AttributeSourcedSubjectCanonicalization

  • All Implemented Interfaces:
    net.shibboleth.utilities.java.support.component.Component, net.shibboleth.utilities.java.support.component.DestructableComponent, net.shibboleth.utilities.java.support.component.InitializableComponent, org.opensaml.profile.action.ProfileAction, Aware, MessageSource, MessageSourceAware, Action

    public class AttributeSourcedSubjectCanonicalization
    extends net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction
    An action that extracts a resolved IdPAttribute value from an AttributeContext child obtained via lookup function (by default a child of the SubjectCanonicalizationContext), and uses it as the result of subject canonicalization.

    This action operates on a set of previously resolved attributes that are presumed to have been generated based in some fashion on the content of the SubjectCanonicalizationContext.

    String and scoped attribute values are supported.

    Event:
    EventIds.PROCEED_EVENT_ID, AuthnEventIds.INVALID_SUBJECT
    Precondition:
    ProfileRequestContext.getSubcontext(SubjectCanonicalizationContext.class) != null
    Postcondition:
    SubjectCanonicalizationContext.getPrincipalName() != null
      || SubjectCanonicalizationContext.getException() != null
    • Field Summary

      Fields 
      Modifier and Type Field Description
      private Function<org.opensaml.profile.context.ProfileRequestContext,​net.shibboleth.idp.attribute.context.AttributeContext> attributeContextLookupStrategy
      Lookup strategy for AttributeContext to read from.
      private net.shibboleth.idp.attribute.context.AttributeContext attributeCtx
      The context to read from.
      private List<String> attributeSourceIds
      Ordered list of attributes to look for and read from.
      private char delimiter
      Delimiter to use for scoped attribute serialization.
      private org.slf4j.Logger log
      Class logger.
    • Method Summary

      All Methods Instance Methods Concrete Methods 
      Modifier and Type Method Description
      protected void doExecute​(org.opensaml.profile.context.ProfileRequestContext profileRequestContext, net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)
      protected void doInitialize()
      protected boolean doPreExecute​(org.opensaml.profile.context.ProfileRequestContext profileRequestContext, net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)
      void setAttributeContextLookupStrategy​(Function<org.opensaml.profile.context.ProfileRequestContext,​net.shibboleth.idp.attribute.context.AttributeContext> strategy)
      Set the lookup strategy for the AttributeContext to read from.
      void setAttributeSourceIds​(List<String> ids)
      Set the attribute IDs to read from in order of preference.
      void setScopedDelimiter​(char ch)
      Set the delimiter to use for serializing scoped attribute values.
      • Methods inherited from class net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction

        applyTransforms, doExecute, doPreExecute, setLookupStrategy, setLowercase, setTransforms, setTrim, setUppercase
      • Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction

        doExecute, execute, getMessage, getMessage, getMessage, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy
      • Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction

        getActivationCondition, setActivationCondition
      • Methods inherited from class org.opensaml.profile.action.AbstractProfileAction

        doPostExecute, doPostExecute, execute, getHttpServletRequest, getHttpServletResponse, getLogPrefix, setHttpServletRequest, setHttpServletResponse
      • Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent

        destroy, doDestroy, initialize, isDestroyed, isInitialized
      • Methods inherited from interface net.shibboleth.utilities.java.support.component.InitializableComponent

        initialize, isInitialized
    • Field Detail

      • log

        @Nonnull
        private final org.slf4j.Logger log
        Class logger.
      • delimiter

        private char delimiter
        Delimiter to use for scoped attribute serialization.
      • attributeSourceIds

        @Nonnull
        @NonnullElements
        private List<String> attributeSourceIds
        Ordered list of attributes to look for and read from.
      • attributeContextLookupStrategy

        @Nonnull
        private Function<org.opensaml.profile.context.ProfileRequestContext,​net.shibboleth.idp.attribute.context.AttributeContext> attributeContextLookupStrategy
        Lookup strategy for AttributeContext to read from.
      • attributeCtx

        @Nullable
        private net.shibboleth.idp.attribute.context.AttributeContext attributeCtx
        The context to read from.
    • Constructor Detail

      • AttributeSourcedSubjectCanonicalization

        public AttributeSourcedSubjectCanonicalization()
        Constructor.
    • Method Detail

      • setScopedDelimiter

        public void setScopedDelimiter​(char ch)
        Set the delimiter to use for serializing scoped attribute values.
        Parameters:
        ch - delimiter to use
      • setAttributeSourceIds

        public void setAttributeSourceIds​(@Nonnull @NonnullElements
                                          List<String> ids)
        Set the attribute IDs to read from in order of preference.
        Parameters:
        ids - attribute IDs to read from
      • setAttributeContextLookupStrategy

        public void setAttributeContextLookupStrategy​(@Nonnull
                                                      Function<org.opensaml.profile.context.ProfileRequestContext,​net.shibboleth.idp.attribute.context.AttributeContext> strategy)
        Set the lookup strategy for the AttributeContext to read from.
        Parameters:
        strategy - lookup strategy
      • doInitialize

        protected void doInitialize()
                             throws net.shibboleth.utilities.java.support.component.ComponentInitializationException
        Overrides:
        doInitialize in class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
        Throws:
        net.shibboleth.utilities.java.support.component.ComponentInitializationException
      • doPreExecute

        protected boolean doPreExecute​(@Nonnull
                                       org.opensaml.profile.context.ProfileRequestContext profileRequestContext,
                                       @Nonnull
                                       net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)
        Overrides:
        doPreExecute in class net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction
      • doExecute

        protected void doExecute​(@Nonnull
                                 org.opensaml.profile.context.ProfileRequestContext profileRequestContext,
                                 @Nonnull
                                 net.shibboleth.idp.authn.context.SubjectCanonicalizationContext c14nContext)
        Overrides:
        doExecute in class net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction