java.lang.Object
net.shibboleth.idp.plugin.authn.duo.AbstractDuoOIDCClient
net.shibboleth.idp.plugin.authn.duo.nimbus.impl.NimbusClient
All Implemented Interfaces:
DuoOIDCClient, DuoOIDCClientCapabilities

@ThreadSafe @Immutable public final class NimbusClient extends AbstractDuoOIDCClient
A Duo client using the Nimbus OIDC library.
  • Field Details

    • CLIENT_ASSERTION_TYPE

      @Nonnull @NotEmpty private static final String CLIENT_ASSERTION_TYPE
      The only supported client assertion type.
      See Also:
    • HTTPS

      @Nonnull @NotEmpty private static final String HTTPS
      The HTTPS scheme.
      See Also:
    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
    • duoIntegration

      @Nonnull private final DuoOIDCIntegration duoIntegration
      The integration to help generate the JWT.
    • httpClient

      @Nonnull private final org.apache.hc.client5.http.classic.HttpClient httpClient
      HttpClient for contacting Duo.
    • httpClientSecurityParameters

      @Nullable private final HttpClientSecurityParameters httpClientSecurityParameters
      HTTP client security parameters.
    • objectMapper

      @Nonnull private final com.fasterxml.jackson.databind.ObjectMapper objectMapper
      JSON object mapper.
  • Constructor Details

    • NimbusClient

      NimbusClient(@Nonnull DuoOIDCIntegration integration, @Nonnull org.apache.hc.client5.http.classic.HttpClient client, @Nullable HttpClientSecurityParameters params, @Nonnull com.fasterxml.jackson.databind.ObjectMapper oMapper)
      Package-private Constructor.

      Should only be instantiated by the NimbusClientFactory.

      Parameters:
      integration - the integration to create the client for, never null
      client - the Http client to use to execute HTTP requests, never null
      params - any security parameters to use for the Http client, can be null.
      oMapper - the JSON object mapper, never null.
  • Method Details

    • healthCheck

      @Nonnull public DuoHealthCheck healthCheck() throws DuoClientException
      Throws:
      DuoClientException
    • createAuthUrl

      @Nonnull public String createAuthUrl(@Nonnull @NotEmpty String username, @Nonnull @NotEmpty String state, @Nullable String nonce, @Nullable String redirectURIOverride) throws DuoClientException
      Throws:
      DuoClientException
    • exchangeAuthorizationCodeFor2FAResult

      public com.nimbusds.jwt.JWT exchangeAuthorizationCodeFor2FAResult(@Nonnull String code, @Nonnull String username, @Nullable String redirectURIOverride) throws DuoClientException
      Throws:
      DuoClientException
    • executeRequest

      @Nonnull private <T> T executeRequest(@Nonnull org.apache.hc.core5.http.ClassicHttpRequest request, @Nonnull com.fasterxml.jackson.core.type.TypeReference<T> wrapperTypeRef) throws DuoClientException
      Performs a call to a Duo OIDC endpoint. Iff successful, the JSON response is mapped into the appropriate type.
      Type Parameters:
      T - the response type
      Parameters:
      request - the prepared HTTP request
      wrapperTypeRef - the type to deserialise the JSON into
      Returns:
      the response type, never null.
      Throws:
      DuoClientException - if there is an error producing a response
    • isSupportsNonce

      public boolean isSupportsNonce()