Package org.cyclos.security.access
Class OidcServiceSecurity
- java.lang.Object
-
- org.cyclos.impl.AbstractServerComponent
-
- org.cyclos.impl.AbstractNetworkedServerComponent
-
- org.cyclos.security.BaseServiceSecurity
-
- org.cyclos.security.access.OidcServiceSecurity
-
- All Implemented Interfaces:
OidcService,Service
@Security public class OidcServiceSecurity extends BaseServiceSecurity implements OidcService
Security layer forOidcService
-
-
Field Summary
-
Fields inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
authHandler, conversionHandler, customFieldValueHandler, entityManagerHandler, groupsHandler, productsHandler, restBeanPropertyMapping, userLocatorHandler
-
Fields inherited from class org.cyclos.impl.AbstractServerComponent
accountHandler, configurationHandler, dataTranslationHandler, notificationHandler, profileFieldHandler, transactionHandler, translationHandler
-
-
Constructor Summary
Constructors Constructor Description OidcServiceSecurity()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description AuthorizeResponseapprove(ConsentParams params)Approves the given authorization request.AuthorizeResponseauthorize(AuthorizeRequest params)Performs the OAuth2 / OpenID connect authorization request.AuthorizeResponsedeny(String locator)Denies the given authorization request.ConsentDatagetConsentData(String locator)Returns data to be displayed in a consent page.OpenidConfigurationgetOpenidConfiguration()Returns the OpenID Connect configuration to be returned on .well-known/openid-configurationcom.nimbusds.jose.jwk.JWKSetgetPublicKeys()Returns the public keys for this networkprotected EntityCheck<?>resolveEntityCheck()Must be implemented in order to return theEntityCheckmanaged by this security component, or null if nonevoidrevoke(RevokeRequest params)Performs the OAuth2 token revocation request.TokenResponsetoken(TokenRequest params)Performs the OAuth2 / OpenID connect token request.Map<String,Object>userInfo()Returns the authenticated user claims-
Methods inherited from class org.cyclos.security.BaseServiceSecurity
checkGuest, checkId, checkIds, checkInternalName, checkLoggedIn, checkManagesUser, checkRelatesToUser, checkScope, checkVO, checkVOs, doInitialize, getEntityCheckRegistry, getUser, initialize
-
Methods inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
canManage, checkManagesUser, checkPermission, checkRelatesToUser, checkValue, clearAlreadyValidated, getBaseEntityManagerHandler, getConfiguration, getLoggedBasicUser, getLoggedUser, getProducts, getTranslatedName, getTranslatedValue, hasPermission, hasValue, inSameNetwork, inSameNetworkOrGlobal, isAdmin, isAlreadyValidated, isBroker, isGlobalAdmin, isGlobalAdminInNetwork, isGuest, isLoggedIn, isMember, isMemberOnly, isNetworkAdmin, isOperator, isRelatedToUser, isSystem, isUserManager, isUserManagerOf, message, message, permission, permission, permissionOptionalValue, permissionOptionalValue, setAlreadyValidated, toDate, toDateTime, validate
-
Methods inherited from class org.cyclos.impl.AbstractServerComponent
dataTranslationProxy, dataTranslationProxy, delete, detach, doDataTranslationProxy, find, flush, from, getApplicationContext, getFormatter, getFormatter, getFormatter, getLogger, getRemoteAddress, getSessionData, mailContentBuilder, message, message, persist, processBatch, processBatch, refresh, remove, selectFrom, subQuery, update
-
-
-
-
Method Detail
-
approve
public AuthorizeResponse approve(ConsentParams params) throws FrameworkException
Description copied from interface:OidcServiceApproves the given authorization request. The request is obtained from the locator parameter, while the user is authenticated via user / password with any allowed principal types and access password for the main channel.- Specified by:
approvein interfaceOidcService- Throws:
FrameworkException
-
authorize
public AuthorizeResponse authorize(AuthorizeRequest params) throws FrameworkException, OidcException
Description copied from interface:OidcServicePerforms the OAuth2 / OpenID connect authorization request. The result is the redirect URL for the user to get the login / consent.- Specified by:
authorizein interfaceOidcService- Throws:
OidcException- If any parameter or state is invalidFrameworkException
-
deny
public AuthorizeResponse deny(String locator) throws FrameworkException
Description copied from interface:OidcServiceDenies the given authorization request. The request is obtained from the locator parameter, while the user is authenticated via user / password with any allowed principal types and access password for the main channel.- Specified by:
denyin interfaceOidcService- Throws:
FrameworkException
-
getConsentData
public ConsentData getConsentData(String locator) throws FrameworkException
Description copied from interface:OidcServiceReturns data to be displayed in a consent page. The request needs to be pending authorization, or anEntityNotFoundExceptionis thrown.- Specified by:
getConsentDatain interfaceOidcService- Throws:
FrameworkException
-
getOpenidConfiguration
public OpenidConfiguration getOpenidConfiguration() throws FrameworkException
Description copied from interface:OidcServiceReturns the OpenID Connect configuration to be returned on .well-known/openid-configuration- Specified by:
getOpenidConfigurationin interfaceOidcService- Throws:
FrameworkException
-
getPublicKeys
public com.nimbusds.jose.jwk.JWKSet getPublicKeys() throws FrameworkExceptionDescription copied from interface:OidcServiceReturns the public keys for this network- Specified by:
getPublicKeysin interfaceOidcService- Throws:
FrameworkException
-
revoke
public void revoke(RevokeRequest params)
Description copied from interface:OidcServicePerforms the OAuth2 token revocation request.- Specified by:
revokein interfaceOidcService
-
token
public TokenResponse token(TokenRequest params) throws FrameworkException
Description copied from interface:OidcServicePerforms the OAuth2 / OpenID connect token request.- Specified by:
tokenin interfaceOidcService- Throws:
FrameworkException
-
userInfo
public Map<String,Object> userInfo() throws FrameworkException, OidcException
Description copied from interface:OidcServiceReturns the authenticated user claims- Specified by:
userInfoin interfaceOidcService- Throws:
FrameworkExceptionOidcException
-
resolveEntityCheck
protected EntityCheck<?> resolveEntityCheck()
Description copied from class:BaseServiceSecurityMust be implemented in order to return theEntityCheckmanaged by this security component, or null if none- Specified by:
resolveEntityCheckin classBaseServiceSecurity
-
-