Class AuthenticationService

java.lang.Object
org.forgerock.openidm.auth.AuthenticationService
All Implemented Interfaces:
org.forgerock.json.resource.SingletonResourceProvider, IdentityProviderListener

public class AuthenticationService extends Object implements org.forgerock.json.resource.SingletonResourceProvider, IdentityProviderListener
Configures the authentication chains based on authentication.json. Example:
     
 {
     "serverAuthConfig" : {
         "sessionModule" : {
             "name" : "JWT_SESSION",
                 "properties" : {
                     "someSetting" : "some-value"
                 }
         },
         "authModules" : [
             {
                 "name" : "IWA",
                 "properties" : {
                     "someSetting" : "some-value"
                 }
             },
             {
                 "name" : "PASSTHROUGH",
                 "properties" : {
                     "someSetting" : "some-value"
                 }
             }
         ]
     }
 }
     
 
  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    static final String
    The className key within an auth module stanza in the authentication config.
    static final String
    The enabled key within an auth module stanza in the authentication config.
    static final String
    The name key within an auth module stanza in the authentication config.
    static final String
    The properties key within an auth module stanza in the authentication config.
    static final String
    The propertyMapping key within an auth module stanza in the authentication config.
    static final String
    The queryOnResource key within an auth module stanza in the authentication config.
    static final String
    The resolvers key within an auth module stanza in the authentication config.
    static final String
    The authModules key in the authentication config.
    The Connection Factory
    static final com.google.common.base.Predicate<org.forgerock.json.JsonValue>
    A Predicate that determines if an auth module is either OPENID_CONNECT or OAUTH
    static final String
    The PID for this Component.
    protected org.forgerock.script.ScriptRegistry
    Script Registry service.
    static final String
    The serverAuthContext key in the authentication config.
    static final String
    The sessionModule key in the authentication config.
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    org.forgerock.util.promise.Promise<org.forgerock.json.resource.ActionResponse,org.forgerock.json.resource.ResourceException>
    actionInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ActionRequest request)
    Action support, including reauthenticate action
    void
    activate(org.osgi.service.component.ComponentContext context)
    Activates this component.
    void
    deactivate(org.osgi.service.component.ComponentContext context)
    Nulls the stored authentication JsonValue.
    Implementation of IdentityProviderListener
    void
    When there is a configuration change on any ProviderConfig, services that have a references to the IdentityProviderService need to be notified that there have been changes.
    org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException>
    patchInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.PatchRequest request)
    org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException>
    readInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ReadRequest request)
    org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException>
    updateInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.UpdateRequest request)

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Field Details

    • PID

      public static final String PID
      The PID for this Component.
      See Also:
    • SERVER_AUTH_CONTEXT_KEY

      public static final String SERVER_AUTH_CONTEXT_KEY
      The serverAuthContext key in the authentication config.
      See Also:
    • SESSION_MODULE_KEY

      public static final String SESSION_MODULE_KEY
      The sessionModule key in the authentication config.
      See Also:
    • AUTH_MODULES_KEY

      public static final String AUTH_MODULES_KEY
      The authModules key in the authentication config.
      See Also:
    • AUTH_MODULE_PROPERTIES_KEY

      public static final String AUTH_MODULE_PROPERTIES_KEY
      The properties key within an auth module stanza in the authentication config.
      See Also:
    • AUTH_MODULE_PROPERTY_MAPPING_KEY

      public static final String AUTH_MODULE_PROPERTY_MAPPING_KEY
      The propertyMapping key within an auth module stanza in the authentication config.
      See Also:
    • AUTH_MODULE_QUERY_ON_RESOURCE

      public static final String AUTH_MODULE_QUERY_ON_RESOURCE
      The queryOnResource key within an auth module stanza in the authentication config.
      See Also:
    • AUTH_MODULE_NAME_KEY

      public static final String AUTH_MODULE_NAME_KEY
      The name key within an auth module stanza in the authentication config.
      See Also:
    • AUTH_MODULE_CLASS_NAME_KEY

      public static final String AUTH_MODULE_CLASS_NAME_KEY
      The className key within an auth module stanza in the authentication config.
      See Also:
    • AUTH_MODULE_CONFIG_ENABLED

      public static final String AUTH_MODULE_CONFIG_ENABLED
      The enabled key within an auth module stanza in the authentication config.
      See Also:
    • AUTH_MODULE_RESOLVERS_KEY

      public static final String AUTH_MODULE_RESOLVERS_KEY
      The resolvers key within an auth module stanza in the authentication config.
      See Also:
    • connectionFactory

      protected IDMConnectionFactory connectionFactory
      The Connection Factory
    • scriptRegistry

      protected volatile org.forgerock.script.ScriptRegistry scriptRegistry
      Script Registry service.
    • oidcAndOauth2Modules

      public static final com.google.common.base.Predicate<org.forgerock.json.JsonValue> oidcAndOauth2Modules
      A Predicate that determines if an auth module is either OPENID_CONNECT or OAUTH
  • Constructor Details

    • AuthenticationService

      public AuthenticationService()
  • Method Details

    • getListenerName

      public String getListenerName()
      Implementation of IdentityProviderListener
      Specified by:
      getListenerName in interface IdentityProviderListener
      Returns:
      name of the listener as a String
    • identityProviderConfigChanged

      public void identityProviderConfigChanged() throws IdentityProviderServiceException
      Description copied from interface: IdentityProviderListener
      When there is a configuration change on any ProviderConfig, services that have a references to the IdentityProviderService need to be notified that there have been changes.
      Specified by:
      identityProviderConfigChanged in interface IdentityProviderListener
      Throws:
      IdentityProviderServiceException - if there are errors in any auth module configuration
    • activate

      public void activate(org.osgi.service.component.ComponentContext context) throws org.forgerock.caf.authentication.api.AuthenticationException, IdentityProviderServiceException
      Activates this component.
      Parameters:
      context - The ComponentContext
      Throws:
      org.forgerock.caf.authentication.api.AuthenticationException
      IdentityProviderServiceException
    • deactivate

      public void deactivate(org.osgi.service.component.ComponentContext context)
      Nulls the stored authentication JsonValue.
      Parameters:
      context - The ComponentContext.
    • actionInstance

      public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ActionResponse,org.forgerock.json.resource.ResourceException> actionInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ActionRequest request)
      Action support, including reauthenticate action
      Specified by:
      actionInstance in interface org.forgerock.json.resource.SingletonResourceProvider
    • patchInstance

      public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> patchInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.PatchRequest request)
      Specified by:
      patchInstance in interface org.forgerock.json.resource.SingletonResourceProvider
    • readInstance

      public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> readInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ReadRequest request)
      Specified by:
      readInstance in interface org.forgerock.json.resource.SingletonResourceProvider
    • updateInstance

      public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> updateInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.UpdateRequest request)
      Specified by:
      updateInstance in interface org.forgerock.json.resource.SingletonResourceProvider