Class SpiffeJwtSvidAssertion

java.lang.Object
io.jans.as.server.model.token.SpiffeJwtSvidAssertion

public class SpiffeJwtSvidAssertion extends Object
Validates a SPIFFE JWT-SVID client assertion (client_assertion_type = urn:ietf:params:oauth:client-assertion-type:jwt-spiffe), per draft-ietf-oauth-spiffe-client-auth.

Unlike ClientAssertion (private_key_jwt/client_secret_jwt), the signature here is verified against the SPIFFE trust domain's JWT-SVID signing keys (fetched from the admin-configured SPIFFE Bundle Endpoint), not the client's own registered JWKS.

Author:
Yuriy Zabrovarnyy
  • Constructor Details

    • SpiffeJwtSvidAssertion

      public SpiffeJwtSvidAssertion(io.jans.as.model.configuration.AppConfiguration appConfiguration, io.jans.as.model.crypto.AbstractCryptoProvider cryptoProvider, String clientId, String encodedAssertion)
    • SpiffeJwtSvidAssertion

      public SpiffeJwtSvidAssertion(io.jans.as.model.configuration.AppConfiguration appConfiguration, io.jans.as.model.crypto.AbstractCryptoProvider cryptoProvider, String clientId, String encodedAssertion, io.jans.as.common.model.registration.Client presetClient)
      Parameters:
      presetClient - the client already resolved by the caller for the same clientId (e.g. AuthenticationFilter resolving it to check the client's authentication method before constructing this assertion) - reused here instead of repeating the CIMD-or-ClientService lookup. Pass null to have this class resolve the client itself.
  • Method Details

    • getSubjectIdentifier

      public String getSubjectIdentifier() throws io.jans.as.model.exception.InvalidJwtException
      Throws:
      io.jans.as.model.exception.InvalidJwtException
    • getClient

      public io.jans.as.common.model.registration.Client getClient() throws io.jans.as.model.exception.InvalidJwtException
      Throws:
      io.jans.as.model.exception.InvalidJwtException
    • initAndVerify

      public void initAndVerify() throws io.jans.as.model.exception.InvalidJwtException
      Throws:
      io.jans.as.model.exception.InvalidJwtException