Class SectorIdentifierUriService

java.lang.Object
io.jans.as.server.service.net.SectorIdentifierUriService

@Named public class SectorIdentifierUriService extends Object
Shared validation and fetching for client-supplied sector_identifier_uri values, used both at client registration time (RegisterParamsValidator) and at authorization time (RedirectionUriService). Enforces https-only scheme and the requestUriBlockList before any outbound request is made, to prevent SSRF via sector_identifier_uri.
Author:
Yuriy Z
  • Constructor Details

    • SectorIdentifierUriService

      public SectorIdentifierUriService()
  • Method Details

    • isAllowedSectorIdentifierUri

      public boolean isAllowedSectorIdentifierUri(String sectorIdentifierUri)
    • isPrivateAddress

      public static boolean isPrivateAddress(InetAddress address)
    • fetchSectorIdentifierContent

      public String fetchSectorIdentifierContent(String sectorIdentifierUri)