Class MSEntraJWTSSOProvider
java.lang.Object
org.apache.syncope.core.spring.security.MSEntraJWTSSOProvider
- All Implemented Interfaces:
com.nimbusds.jose.jca.JCAAware<com.nimbusds.jose.jca.JCAContext>
,com.nimbusds.jose.JOSEProvider
,com.nimbusds.jose.JWSProvider
,com.nimbusds.jose.JWSVerifier
,JWTSSOProvider
JWT authorisation for access tokens issued by Microsoft Entra (formerly Azure)
for Microsoft Entra-only applications (v1.0 tokens)
cf. https://learn.microsoft.com/en-us/entra/identity-platform/access-tokens
-
Field Summary
Modifier and TypeFieldDescriptionprotected final String
protected final AuthDataAccessor
protected final String
protected final Duration
protected final String
protected final UserDAO
protected final MSEntraAccessTokenJWSVerifier
-
Constructor Summary
ConstructorDescriptionMSEntraJWTSSOProvider
(UserDAO userDAO, AuthDataAccessor authDataAccessor, String tenantId, String appId, String authUsername, Duration clockSkew, MSEntraAccessTokenJWSVerifier verifier) -
Method Summary
Modifier and TypeMethodDescriptionGives the identifier for the JWT issuer verified by this instance.com.nimbusds.jose.jca.JCAContext
resolve
(com.nimbusds.jwt.JWTClaimsSet jwtClaims) Attempts to resolve the given JWT claims into internalUser
and authorities.Set
<com.nimbusds.jose.JWSAlgorithm> boolean
verify
(com.nimbusds.jose.JWSHeader header, byte[] signingInput, com.nimbusds.jose.util.Base64URL signature)
-
Field Details
-
userDAO
-
authDataAccessor
-
tenantId
-
appId
-
authUsername
-
clockSkew
-
verifier
-
-
Constructor Details
-
MSEntraJWTSSOProvider
public MSEntraJWTSSOProvider(UserDAO userDAO, AuthDataAccessor authDataAccessor, String tenantId, String appId, String authUsername, Duration clockSkew, MSEntraAccessTokenJWSVerifier verifier)
-
-
Method Details
-
getIssuer
Description copied from interface:JWTSSOProvider
Gives the identifier for the JWT issuer verified by this instance.- Specified by:
getIssuer
in interfaceJWTSSOProvider
- Returns:
- identifier for the JWT issuer verified by this instance
-
supportedJWSAlgorithms
- Specified by:
supportedJWSAlgorithms
in interfacecom.nimbusds.jose.JWSProvider
-
getJCAContext
public com.nimbusds.jose.jca.JCAContext getJCAContext()- Specified by:
getJCAContext
in interfacecom.nimbusds.jose.jca.JCAAware<com.nimbusds.jose.jca.JCAContext>
-
verify
public boolean verify(com.nimbusds.jose.JWSHeader header, byte[] signingInput, com.nimbusds.jose.util.Base64URL signature) throws com.nimbusds.jose.JOSEException - Specified by:
verify
in interfacecom.nimbusds.jose.JWSVerifier
- Throws:
com.nimbusds.jose.JOSEException
-
resolve
@Transactional(readOnly=true) public Pair<User,Set<SyncopeGrantedAuthority>> resolve(com.nimbusds.jwt.JWTClaimsSet jwtClaims) Description copied from interface:JWTSSOProvider
Attempts to resolve the given JWT claims into internalUser
and authorities. IMPORTANT: this is not invoked for theadmin
super-user.- Specified by:
resolve
in interfaceJWTSSOProvider
- Parameters:
jwtClaims
- JWT claims- Returns:
- internal User, with authorities, matching the provided JWT claims, if found; otherwise null
-