Package io.jans.as.server.model.token
Class SpiffeJwtSvidAssertion
java.lang.Object
io.jans.as.server.model.token.SpiffeJwtSvidAssertion
Validates a SPIFFE JWT-SVID client assertion (client_assertion_type =
urn:ietf:params:oauth:client-assertion-type:jwt-spiffe), per draft-ietf-oauth-spiffe-client-auth.
Unlike ClientAssertion (private_key_jwt/client_secret_jwt), the signature here is
verified against the SPIFFE trust domain's JWT-SVID signing keys (fetched from the
admin-configured SPIFFE Bundle Endpoint), not the client's own registered JWKS.
- Author:
- Yuriy Zabrovarnyy
-
Constructor Summary
ConstructorsConstructorDescriptionSpiffeJwtSvidAssertion(io.jans.as.model.configuration.AppConfiguration appConfiguration, io.jans.as.model.crypto.AbstractCryptoProvider cryptoProvider, String clientId, String encodedAssertion) SpiffeJwtSvidAssertion(io.jans.as.model.configuration.AppConfiguration appConfiguration, io.jans.as.model.crypto.AbstractCryptoProvider cryptoProvider, String clientId, String encodedAssertion, io.jans.as.common.model.registration.Client presetClient) -
Method Summary
Modifier and TypeMethodDescriptionio.jans.as.common.model.registration.Clientvoid
-
Constructor Details
-
SpiffeJwtSvidAssertion
-
SpiffeJwtSvidAssertion
public SpiffeJwtSvidAssertion(io.jans.as.model.configuration.AppConfiguration appConfiguration, io.jans.as.model.crypto.AbstractCryptoProvider cryptoProvider, String clientId, String encodedAssertion, io.jans.as.common.model.registration.Client presetClient) - Parameters:
presetClient- the client already resolved by the caller for the sameclientId(e.g.AuthenticationFilterresolving it to check the client's authentication method before constructing this assertion) - reused here instead of repeating the CIMD-or-ClientServicelookup. Passnullto have this class resolve the client itself.
-
-
Method Details
-
getSubjectIdentifier
- Throws:
io.jans.as.model.exception.InvalidJwtException
-
getClient
public io.jans.as.common.model.registration.Client getClient() throws io.jans.as.model.exception.InvalidJwtException- Throws:
io.jans.as.model.exception.InvalidJwtException
-
initAndVerify
public void initAndVerify() throws io.jans.as.model.exception.InvalidJwtException- Throws:
io.jans.as.model.exception.InvalidJwtException
-