Package org.forgerock.openidm.auth
Class AuthenticationService
java.lang.Object
org.forgerock.openidm.auth.AuthenticationService
- All Implemented Interfaces:
org.forgerock.json.resource.SingletonResourceProvider,IdentityProviderListener
public class AuthenticationService
extends Object
implements org.forgerock.json.resource.SingletonResourceProvider, IdentityProviderListener
Configures the authentication chains based on authentication.json.
Example:
{
"serverAuthConfig" : {
"sessionModule" : {
"name" : "JWT_SESSION",
"properties" : {
"someSetting" : "some-value"
}
},
"authModules" : [
{
"name" : "IWA",
"properties" : {
"someSetting" : "some-value"
}
},
{
"name" : "PASSTHROUGH",
"properties" : {
"someSetting" : "some-value"
}
}
]
}
}
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe className key within an auth module stanza in the authentication config.static final StringThe enabled key within an auth module stanza in the authentication config.static final StringThe name key within an auth module stanza in the authentication config.static final StringThe properties key within an auth module stanza in the authentication config.static final StringThe propertyMapping key within an auth module stanza in the authentication config.static final StringThe queryOnResource key within an auth module stanza in the authentication config.static final StringThe resolvers key within an auth module stanza in the authentication config.static final StringThe authModules key in the authentication config.protected IDMConnectionFactoryThe Connection Factorystatic final com.google.common.base.Predicate<org.forgerock.json.JsonValue>APredicatethat determines if an auth module is either OPENID_CONNECT or OAUTHstatic final StringThe PID for this Component.protected org.forgerock.script.ScriptRegistryScript Registry service.static final StringThe serverAuthContext key in the authentication config.static final StringThe sessionModule key in the authentication config. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionorg.forgerock.util.promise.Promise<org.forgerock.json.resource.ActionResponse,org.forgerock.json.resource.ResourceException> actionInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ActionRequest request) Action support, including reauthenticate actionvoidactivate(org.osgi.service.component.ComponentContext context) Activates this component.voiddeactivate(org.osgi.service.component.ComponentContext context) Nulls the stored authentication JsonValue.Implementation of IdentityProviderListenervoidWhen there is a configuration change on any ProviderConfig, services that have a references to the IdentityProviderService need to be notified that there have been changes.org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> patchInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.PatchRequest request) org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> readInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ReadRequest request) org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> updateInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.UpdateRequest request)
-
Field Details
-
PID
The PID for this Component.- See Also:
-
SERVER_AUTH_CONTEXT_KEY
The serverAuthContext key in the authentication config.- See Also:
-
SESSION_MODULE_KEY
The sessionModule key in the authentication config.- See Also:
-
AUTH_MODULES_KEY
The authModules key in the authentication config.- See Also:
-
AUTH_MODULE_PROPERTIES_KEY
The properties key within an auth module stanza in the authentication config.- See Also:
-
AUTH_MODULE_PROPERTY_MAPPING_KEY
The propertyMapping key within an auth module stanza in the authentication config.- See Also:
-
AUTH_MODULE_QUERY_ON_RESOURCE
The queryOnResource key within an auth module stanza in the authentication config.- See Also:
-
AUTH_MODULE_NAME_KEY
The name key within an auth module stanza in the authentication config.- See Also:
-
AUTH_MODULE_CLASS_NAME_KEY
The className key within an auth module stanza in the authentication config.- See Also:
-
AUTH_MODULE_CONFIG_ENABLED
The enabled key within an auth module stanza in the authentication config.- See Also:
-
AUTH_MODULE_RESOLVERS_KEY
The resolvers key within an auth module stanza in the authentication config.- See Also:
-
connectionFactory
The Connection Factory -
scriptRegistry
protected volatile org.forgerock.script.ScriptRegistry scriptRegistryScript Registry service. -
oidcAndOauth2Modules
public static final com.google.common.base.Predicate<org.forgerock.json.JsonValue> oidcAndOauth2ModulesAPredicatethat determines if an auth module is either OPENID_CONNECT or OAUTH
-
-
Constructor Details
-
AuthenticationService
public AuthenticationService()
-
-
Method Details
-
getListenerName
Implementation of IdentityProviderListener- Specified by:
getListenerNamein interfaceIdentityProviderListener- Returns:
- name of the listener as a String
-
identityProviderConfigChanged
Description copied from interface:IdentityProviderListenerWhen there is a configuration change on any ProviderConfig, services that have a references to the IdentityProviderService need to be notified that there have been changes.- Specified by:
identityProviderConfigChangedin interfaceIdentityProviderListener- Throws:
IdentityProviderServiceException- if there are errors in any auth module configuration
-
activate
public void activate(org.osgi.service.component.ComponentContext context) throws org.forgerock.caf.authentication.api.AuthenticationException, IdentityProviderServiceException Activates this component.- Parameters:
context- The ComponentContext- Throws:
org.forgerock.caf.authentication.api.AuthenticationExceptionIdentityProviderServiceException
-
deactivate
public void deactivate(org.osgi.service.component.ComponentContext context) Nulls the stored authentication JsonValue.- Parameters:
context- The ComponentContext.
-
actionInstance
public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ActionResponse,org.forgerock.json.resource.ResourceException> actionInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ActionRequest request) Action support, including reauthenticate action- Specified by:
actionInstancein interfaceorg.forgerock.json.resource.SingletonResourceProvider
-
patchInstance
public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> patchInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.PatchRequest request) - Specified by:
patchInstancein interfaceorg.forgerock.json.resource.SingletonResourceProvider
-
readInstance
public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> readInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.ReadRequest request) - Specified by:
readInstancein interfaceorg.forgerock.json.resource.SingletonResourceProvider
-
updateInstance
public org.forgerock.util.promise.Promise<org.forgerock.json.resource.ResourceResponse,org.forgerock.json.resource.ResourceException> updateInstance(org.forgerock.services.context.Context context, org.forgerock.json.resource.UpdateRequest request) - Specified by:
updateInstancein interfaceorg.forgerock.json.resource.SingletonResourceProvider
-