Package net.shibboleth.idp.authn.impl
Class FinalizeMultiFactorAuthentication
- java.lang.Object
-
- net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
-
- org.opensaml.profile.action.AbstractProfileAction
-
- org.opensaml.profile.action.AbstractConditionalProfileAction
-
- net.shibboleth.idp.profile.AbstractProfileAction
-
- net.shibboleth.idp.authn.AbstractAuthenticationAction
-
- net.shibboleth.idp.authn.impl.FinalizeMultiFactorAuthentication
-
- All Implemented Interfaces:
net.shibboleth.utilities.java.support.component.Component,net.shibboleth.utilities.java.support.component.DestructableComponent,net.shibboleth.utilities.java.support.component.InitializableComponent,org.opensaml.profile.action.ProfileAction,Aware,MessageSource,MessageSourceAware,Action
public class FinalizeMultiFactorAuthentication extends net.shibboleth.idp.authn.AbstractAuthenticationActionAn authentication action that completes MFA by producing a finalAuthenticationResultout of whatever constituent parts and pieces exist, by means of an overridable function, storing it in theAuthenticationContextand preparing a freshSubjectCanonicalizationContextto operate on.- Event:
EventIds.PROCEED_EVENT_ID,EventIds.INVALID_PROFILE_CTX,AuthnEventIds.INVALID_AUTHN_CTX- Precondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class).getSubcontext( MultiFactorAuthenticationContext.class) != null- Postcondition:
ProfileRequestContext.getSubcontext(AuthenticationContext.class).getAuthenticationResult() != null
,ProfileRequestContext.getSubcontext(SubjectCanonicalizationContext.class) != null
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static classFinalizeMultiFactorAuthentication.DefaultResultMergingStrategyDefault merging strategy to combine individualAuthenticationResultobjects into a single result.
-
Field Summary
Fields Modifier and Type Field Description private org.slf4j.LoggerlogClass logger.private net.shibboleth.idp.authn.context.MultiFactorAuthenticationContextmfaContextA subordinateMultiFactorAuthenticationContext, if any.private Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.context.MultiFactorAuthenticationContext>multiFactorContextLookupStrategyLookup function for the context to evaluate.private Function<org.opensaml.profile.context.ProfileRequestContext,String>requesterLookupStrategyFunction used to obtain the requester ID.private Function<org.opensaml.profile.context.ProfileRequestContext,String>responderLookupStrategyFunction used to obtain the responder ID.private Predicate<org.opensaml.profile.context.ProfileRequestContext>resultCachingPredicatePredicate to apply when setting AuthenticationResult cacheability.private Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.AuthenticationResult>resultMergingStrategyStrategy function to produce a final, merged result.
-
Constructor Summary
Constructors Constructor Description FinalizeMultiFactorAuthentication()Constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description protected voiddoExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext, net.shibboleth.idp.authn.context.AuthenticationContext authenticationContext)protected voiddoInitialize()protected booleandoPreExecute(org.opensaml.profile.context.ProfileRequestContext profileRequestContext, net.shibboleth.idp.authn.context.AuthenticationContext authenticationContext)voidsetMultiFactorContextLookupStrategy(Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.context.MultiFactorAuthenticationContext> strategy)Set the lookup strategy to use for the context to evaluate.voidsetRequesterLookupStrategy(Function<org.opensaml.profile.context.ProfileRequestContext,String> strategy)Set the strategy used to locate the requester ID for canonicalization.voidsetResponderLookupStrategy(Function<org.opensaml.profile.context.ProfileRequestContext,String> strategy)Set the strategy used to locate the responder ID for canonicalization.voidsetResultCachingPredicate(Predicate<org.opensaml.profile.context.ProfileRequestContext> predicate)Set predicate to apply to determine cacheability ofAuthenticationResult.voidsetResultMergingStrategy(Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.AuthenticationResult> strategy)Set the result merging strategy to use.-
Methods inherited from class net.shibboleth.idp.authn.AbstractAuthenticationAction
doExecute, doPreExecute, setAuthenticationContextLookupStrategy
-
Methods inherited from class net.shibboleth.idp.profile.AbstractProfileAction
doExecute, execute, getMessage, getMessage, getMessage, getProfileContextLookupStrategy, getRequestContext, getResult, setMessageSource, setProfileContextLookupStrategy
-
Methods inherited from class org.opensaml.profile.action.AbstractConditionalProfileAction
getActivationCondition, setActivationCondition
-
Methods inherited from class org.opensaml.profile.action.AbstractProfileAction
doPostExecute, doPostExecute, execute, getHttpServletRequest, getHttpServletResponse, getLogPrefix, setHttpServletRequest, setHttpServletResponse
-
Methods inherited from class net.shibboleth.utilities.java.support.component.AbstractInitializableComponent
destroy, doDestroy, initialize, isDestroyed, isInitialized
-
-
-
-
Field Detail
-
log
@Nonnull private final org.slf4j.Logger log
Class logger.
-
multiFactorContextLookupStrategy
@Nonnull private Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.context.MultiFactorAuthenticationContext> multiFactorContextLookupStrategy
Lookup function for the context to evaluate.
-
resultMergingStrategy
@NonnullAfterInit private Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.AuthenticationResult> resultMergingStrategy
Strategy function to produce a final, merged result.
-
resultCachingPredicate
@Nullable private Predicate<org.opensaml.profile.context.ProfileRequestContext> resultCachingPredicate
Predicate to apply when setting AuthenticationResult cacheability.
-
requesterLookupStrategy
@Nullable private Function<org.opensaml.profile.context.ProfileRequestContext,String> requesterLookupStrategy
Function used to obtain the requester ID.
-
responderLookupStrategy
@Nullable private Function<org.opensaml.profile.context.ProfileRequestContext,String> responderLookupStrategy
Function used to obtain the responder ID.
-
mfaContext
@Nullable private net.shibboleth.idp.authn.context.MultiFactorAuthenticationContext mfaContext
A subordinateMultiFactorAuthenticationContext, if any.
-
-
Method Detail
-
setMultiFactorContextLookupStrategy
public void setMultiFactorContextLookupStrategy(@Nonnull Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.context.MultiFactorAuthenticationContext> strategy)Set the lookup strategy to use for the context to evaluate.- Parameters:
strategy- lookup strategy
-
setResultMergingStrategy
public void setResultMergingStrategy(@Nullable Function<org.opensaml.profile.context.ProfileRequestContext,net.shibboleth.idp.authn.AuthenticationResult> strategy)Set the result merging strategy to use.- Parameters:
strategy- result merging strategy
-
setResultCachingPredicate
public void setResultCachingPredicate(@Nullable Predicate<org.opensaml.profile.context.ProfileRequestContext> predicate)Set predicate to apply to determine cacheability ofAuthenticationResult.- Parameters:
predicate- predicate to apply, or null
-
setRequesterLookupStrategy
public void setRequesterLookupStrategy(@Nullable Function<org.opensaml.profile.context.ProfileRequestContext,String> strategy)Set the strategy used to locate the requester ID for canonicalization.- Parameters:
strategy- lookup strategy
-
setResponderLookupStrategy
public void setResponderLookupStrategy(@Nullable Function<org.opensaml.profile.context.ProfileRequestContext,String> strategy)Set the strategy used to locate the responder ID for canonicalization.- Parameters:
strategy- lookup strategy
-
doInitialize
protected void doInitialize() throws net.shibboleth.utilities.java.support.component.ComponentInitializationException- Overrides:
doInitializein classnet.shibboleth.utilities.java.support.component.AbstractInitializableComponent- Throws:
net.shibboleth.utilities.java.support.component.ComponentInitializationException
-
doPreExecute
protected boolean doPreExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext, @Nonnull net.shibboleth.idp.authn.context.AuthenticationContext authenticationContext)- Overrides:
doPreExecutein classnet.shibboleth.idp.authn.AbstractAuthenticationAction
-
doExecute
protected void doExecute(@Nonnull org.opensaml.profile.context.ProfileRequestContext profileRequestContext, @Nonnull net.shibboleth.idp.authn.context.AuthenticationContext authenticationContext)- Overrides:
doExecutein classnet.shibboleth.idp.authn.AbstractAuthenticationAction
-
-