Package io.jans.as.server.service.net
Class SectorIdentifierUriService
java.lang.Object
io.jans.as.server.service.net.SectorIdentifierUriService
Shared validation and fetching for client-supplied sector_identifier_uri values, used both at
client registration time (
RegisterParamsValidator) and at authorization time
(RedirectionUriService). Enforces https-only scheme and the requestUriBlockList
before any outbound request is made, to prevent SSRF via sector_identifier_uri.- Author:
- Yuriy Z
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionfetchSectorIdentifierContent(String sectorIdentifierUri) booleanisAllowedSectorIdentifierUri(String sectorIdentifierUri) static booleanisPrivateAddress(InetAddress address)
-
Constructor Details
-
SectorIdentifierUriService
public SectorIdentifierUriService()
-
-
Method Details
-
isAllowedSectorIdentifierUri
-
isPrivateAddress
-
fetchSectorIdentifierContent
-