Package org.cyclos.impl.access
Class OidcServiceImpl
- java.lang.Object
-
- org.cyclos.impl.AbstractServerComponent
-
- org.cyclos.impl.AbstractNetworkedServerComponent
-
- org.cyclos.impl.BaseServiceImpl
-
- org.cyclos.impl.access.OidcServiceImpl
-
- All Implemented Interfaces:
OidcServiceLocal,OidcService,Service
@Service public class OidcServiceImpl extends BaseServiceImpl implements OidcServiceLocal
Local interface forOidcService
-
-
Field Summary
-
Fields inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
authHandler, conversionHandler, customFieldValueHandler, entityManagerHandler, groupsHandler, productsHandler, restBeanPropertyMapping, userLocatorHandler
-
Fields inherited from class org.cyclos.impl.AbstractServerComponent
accountHandler, configurationHandler, dataTranslationHandler, notificationHandler, profileFieldHandler, transactionHandler, translationHandler
-
-
Constructor Summary
Constructors Constructor Description OidcServiceImpl()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description AuthorizeResponseapprove(ConsentParams params)Approves the given authorization request.AuthorizeResponseauthorize(AuthorizeRequest request)Performs the OAuth2 / OpenID connect authorization request.com.nimbusds.jose.jwk.RSAKeycreateKey(Date date)Creates a new signing RSA JSON Web Key with the given base date Should only be called from testsAuthorizeResponsedeny(String locator)Denies the given authorization request.OidcAccessTokenfindAccessToken(Network network, String remoteAddress, String accessToken)Returns an access token using the token valueConsentDatagetConsentData(String locator)Returns data to be displayed in a consent page.com.nimbusds.jose.jwk.RSAKeygetKey(String kid)Returns a signing RSA JSON Web Key by key idOpenidConfigurationgetOpenidConfiguration()Returns the OpenID Connect configuration to be returned on .well-known/openid-configurationcom.nimbusds.jose.jwk.JWKSetgetPublicKeys()Returns the public keys for this networkvoidinitialize()longpurgeAuthorizations()Removes all authorizations that don't have a refresh token and don't have any access tokens (either never generated or already purged).longpurgeExpiredTokens()Removes all access tokens that have already expiredprotected voidregisterNetworkMappings(NetworkPathRegistry networkPathRegistry)Needs to be overridden by subclasses to register the path up to the networkvoidrevoke(@NotNull RevokeRequest params)Performs the OAuth2 token revocation request.TokenResponsetoken(@NotNull TokenRequest params)Performs the OAuth2 / OpenID connect token request.Map<String,Object>userInfo()Returns the authenticated user claims-
Methods inherited from class org.cyclos.impl.BaseServiceImpl
initializeNetworkMappings
-
Methods inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
canManage, checkManagesUser, checkPermission, checkRelatesToUser, checkValue, clearAlreadyValidated, getBaseEntityManagerHandler, getConfiguration, getLoggedBasicUser, getLoggedUser, getProducts, getTranslatedName, getTranslatedValue, hasPermission, hasValue, inSameNetwork, inSameNetworkOrGlobal, isAdmin, isAlreadyValidated, isBroker, isGlobalAdmin, isGlobalAdminInNetwork, isGuest, isLoggedIn, isMember, isMemberOnly, isNetworkAdmin, isOperator, isRelatedToUser, isSystem, isUserManager, isUserManagerOf, message, message, permission, permission, permissionOptionalValue, permissionOptionalValue, toDate, toDateTime, validate
-
Methods inherited from class org.cyclos.impl.AbstractServerComponent
dataTranslationProxy, delete, detach, find, flush, from, getApplicationContext, getFormatter, getFormatter, getFormatter, getLogger, getRemoteAddress, getSessionData, mailContentBuilder, message, message, persist, processBatch, processBatch, refresh, remove, selectFrom, subQuery, update
-
-
-
-
Method Detail
-
approve
public AuthorizeResponse approve(ConsentParams params) throws FrameworkException
Description copied from interface:OidcServiceApproves the given authorization request. The request is obtained from the locator parameter, while the user is authenticated via user / password with any allowed principal types and access password for the main channel.- Specified by:
approvein interfaceOidcService- Throws:
FrameworkException
-
authorize
public AuthorizeResponse authorize(AuthorizeRequest request) throws FrameworkException, OidcException
Description copied from interface:OidcServicePerforms the OAuth2 / OpenID connect authorization request. The result is the redirect URL for the user to get the login / consent.- Specified by:
authorizein interfaceOidcService- Throws:
OidcException- If any parameter or state is invalidFrameworkException
-
createKey
public com.nimbusds.jose.jwk.RSAKey createKey(Date date)
Description copied from interface:OidcServiceLocalCreates a new signing RSA JSON Web Key with the given base date Should only be called from tests- Specified by:
createKeyin interfaceOidcServiceLocal
-
deny
public AuthorizeResponse deny(String locator) throws FrameworkException
Description copied from interface:OidcServiceDenies the given authorization request. The request is obtained from the locator parameter, while the user is authenticated via user / password with any allowed principal types and access password for the main channel.- Specified by:
denyin interfaceOidcService- Throws:
FrameworkException
-
findAccessToken
public OidcAccessToken findAccessToken(Network network, String remoteAddress, String accessToken)
Description copied from interface:OidcServiceLocalReturns an access token using the token value- Specified by:
findAccessTokenin interfaceOidcServiceLocal
-
getConsentData
public ConsentData getConsentData(String locator) throws FrameworkException
Description copied from interface:OidcServiceReturns data to be displayed in a consent page. The request needs to be pending authorization, or anEntityNotFoundExceptionis thrown.- Specified by:
getConsentDatain interfaceOidcService- Throws:
FrameworkException
-
getKey
public com.nimbusds.jose.jwk.RSAKey getKey(String kid)
Description copied from interface:OidcServiceLocalReturns a signing RSA JSON Web Key by key id- Specified by:
getKeyin interfaceOidcServiceLocal
-
getOpenidConfiguration
public OpenidConfiguration getOpenidConfiguration() throws FrameworkException
Description copied from interface:OidcServiceReturns the OpenID Connect configuration to be returned on .well-known/openid-configuration- Specified by:
getOpenidConfigurationin interfaceOidcService- Throws:
FrameworkException
-
getPublicKeys
public com.nimbusds.jose.jwk.JWKSet getPublicKeys() throws FrameworkExceptionDescription copied from interface:OidcServiceReturns the public keys for this network- Specified by:
getPublicKeysin interfaceOidcService- Throws:
FrameworkException
-
initialize
@PostConstruct public void initialize()
-
purgeAuthorizations
public long purgeAuthorizations()
Description copied from interface:OidcServiceLocalRemoves all authorizations that don't have a refresh token and don't have any access tokens (either never generated or already purged).- Specified by:
purgeAuthorizationsin interfaceOidcServiceLocal
-
purgeExpiredTokens
public long purgeExpiredTokens()
Description copied from interface:OidcServiceLocalRemoves all access tokens that have already expired- Specified by:
purgeExpiredTokensin interfaceOidcServiceLocal
-
revoke
public void revoke(@NotNull @NotNull RevokeRequest params)Description copied from interface:OidcServicePerforms the OAuth2 token revocation request.- Specified by:
revokein interfaceOidcService
-
token
public TokenResponse token(@NotNull @NotNull TokenRequest params) throws FrameworkException, OidcException
Description copied from interface:OidcServicePerforms the OAuth2 / OpenID connect token request.- Specified by:
tokenin interfaceOidcService- Throws:
FrameworkExceptionOidcException
-
userInfo
public Map<String,Object> userInfo() throws FrameworkException
Description copied from interface:OidcServiceReturns the authenticated user claims- Specified by:
userInfoin interfaceOidcService- Throws:
FrameworkException
-
registerNetworkMappings
protected void registerNetworkMappings(NetworkPathRegistry networkPathRegistry)
Description copied from class:BaseServiceImplNeeds to be overridden by subclasses to register the path up to the network- Specified by:
registerNetworkMappingsin classBaseServiceImpl
-
-