Package com.oracle.bmc.auth.internal
Class AbstractFederationClient
- java.lang.Object
-
- com.oracle.bmc.auth.internal.AbstractFederationClient
-
- All Implemented Interfaces:
FederationClient,ProvidesConfigurableRefresh
- Direct Known Subclasses:
ResourcePrincipalsFederationClient,ResourcePrincipalsV3FederationClient,ResourcePrincipalV2FederationClient
public abstract class AbstractFederationClient extends Object implements FederationClient, ProvidesConfigurableRefresh
This class gets a security token from the auth service by signing the request with a PKI issued leaf certificate, passing along a temporary public key that is bounded to the the security token, and the leaf certificate.
-
-
Field Summary
Fields Modifier and Type Field Description protected StringfederationEndpointprotected StringresourcePrincipalTokenEndpointprotected StringresourcePrincipalTokenUrlprotected RestClientrestClientprotected static Function<javax.ws.rs.core.Response,WithHeaders<X509FederationClient.SecurityToken>>SECURITY_TOKEN_FNprotected SecurityTokenAdaptersecurityTokenAdapterprotected SessionKeySuppliersessionKeySupplier
-
Constructor Summary
Constructors Constructor Description AbstractFederationClient(String resourcePrincipalTokenEndpoint, String federationEndpoint, SessionKeySupplier sessionKeySupplier, BasicAuthenticationDetailsProvider basicAuthenticationDetailsProvider, ClientConfigurator clientConfigurator, CircuitBreakerConfiguration circuitBreakerConfiguration)Constructor of AbstractFederationClient.AbstractFederationClient(String resourcePrincipalTokenUrl, String resourcePrincipalTokenEndpoint, String federationEndpoint, SessionKeySupplier sessionKeySupplier, BasicAuthenticationDetailsProvider basicAuthenticationDetailsProvider, ClientConfigurator clientConfigurator, CircuitBreakerConfiguration circuitBreakerConfiguration)Constructor of AbstractFederationClient.
-
Method Summary
All Methods Instance Methods Abstract Methods Concrete Methods Modifier and Type Method Description StringgetSecurityToken()Gets a security token from the federation endpoint.protected SecurityTokenAdaptergetSecurityTokenAdapter()Get securityTokenAdapterprotected abstract SecurityTokenAdaptergetSecurityTokenFromServer()Gets a security token from the federation serverprotected SecurityTokenAdaptergetSecurityTokenFromServerInner(RSAPublicKey publicKey, javax.ws.rs.client.WebTarget target, String securityContext)StringgetStringClaim(String key)Get a claim embedded in the security token.protected javax.ws.rs.core.ResponsemakeCall(javax.ws.rs.client.Invocation.Builder ib, URI requestUri)protected javax.ws.rs.core.ResponsemakeCall(javax.ws.rs.client.Invocation.Builder ib, URI requestUri, GetResourcePrincipalSessionTokenRequest request)protected javax.ws.rs.core.ResponsemakeCallInner(WrappedInvocationBuilder wrappedIb, Object request)StringrefreshAndGetSecurityToken()Gets a security token from the federation endpoint.StringrefreshAndGetSecurityTokenIfExpiringWithin(Duration time)Gets a security token from the federation endpoint if the security token expires within the provided duration.StringrefreshAndGetSecurityTokenIfExpiringWithin(Duration time, boolean refreshKeys)Gets a security token from the federation endpoint if the security token expires within the provided duration and allows to enable/disable refresh of keys.protected StringrefreshAndGetSecurityTokenInner(boolean doFinalTokenValidityCheck, Optional<Duration> time, boolean refreshKeys)
-
-
-
Field Detail
-
SECURITY_TOKEN_FN
protected static final Function<javax.ws.rs.core.Response,WithHeaders<X509FederationClient.SecurityToken>> SECURITY_TOKEN_FN
-
sessionKeySupplier
protected final SessionKeySupplier sessionKeySupplier
-
resourcePrincipalTokenEndpoint
protected final String resourcePrincipalTokenEndpoint
-
resourcePrincipalTokenUrl
protected final String resourcePrincipalTokenUrl
-
federationEndpoint
protected final String federationEndpoint
-
securityTokenAdapter
protected volatile SecurityTokenAdapter securityTokenAdapter
-
restClient
protected final RestClient restClient
-
-
Constructor Detail
-
AbstractFederationClient
public AbstractFederationClient(String resourcePrincipalTokenUrl, String resourcePrincipalTokenEndpoint, String federationEndpoint, SessionKeySupplier sessionKeySupplier, BasicAuthenticationDetailsProvider basicAuthenticationDetailsProvider, ClientConfigurator clientConfigurator, CircuitBreakerConfiguration circuitBreakerConfiguration)
Constructor of AbstractFederationClient.- Parameters:
resourcePrincipalTokenUrl- the url that can provide the resource principal token.resourcePrincipalTokenEndpoint- the endpoint that can provide the resource principal token.federationEndpoint- the endpoint that can provide the resource principal session token.sessionKeySupplier- the session key supplier.basicAuthenticationDetailsProvider- the instance principals authentication details provider.clientConfigurator- the reset client configurator.
-
AbstractFederationClient
public AbstractFederationClient(String resourcePrincipalTokenEndpoint, String federationEndpoint, SessionKeySupplier sessionKeySupplier, BasicAuthenticationDetailsProvider basicAuthenticationDetailsProvider, ClientConfigurator clientConfigurator, CircuitBreakerConfiguration circuitBreakerConfiguration)
Constructor of AbstractFederationClient.- Parameters:
resourcePrincipalTokenEndpoint- the endpoint that can provide the resource principal token.federationEndpoint- the endpoint that can provide the resource principal session token.sessionKeySupplier- the session key supplier.basicAuthenticationDetailsProvider- the instance principals authentication details provider.clientConfigurator- the reset client configurator.
-
-
Method Detail
-
getSecurityToken
public String getSecurityToken()
Gets a security token from the federation endpoint.May use a cached token if it judged to still be valid.
- Specified by:
getSecurityTokenin interfaceFederationClient- Returns:
- A security token that can be used to authenticate requests.
-
getSecurityTokenAdapter
protected SecurityTokenAdapter getSecurityTokenAdapter()
Get securityTokenAdapter- Returns:
- securityTokenAdapter
-
refreshAndGetSecurityToken
public String refreshAndGetSecurityToken()
Gets a security token from the federation endpoint.This will always retrieve a new token from the federation endpoint and does not use a cached token.
- Specified by:
refreshAndGetSecurityTokenin interfaceFederationClient- Returns:
- A security token that can be used to authenticate requests.
-
refreshAndGetSecurityTokenIfExpiringWithin
public String refreshAndGetSecurityTokenIfExpiringWithin(Duration time, boolean refreshKeys)
Gets a security token from the federation endpoint if the security token expires within the provided duration and allows to enable/disable refresh of keys.This will always retrieve a new token from the federation endpoint and does not use a cached token.
- Specified by:
refreshAndGetSecurityTokenIfExpiringWithinin interfaceProvidesConfigurableRefresh- Parameters:
time- the duration to checkrefreshKeys- boolean value to enable/disable refresh of keys- Returns:
- A security token that can be used to authenticate requests.
-
refreshAndGetSecurityTokenIfExpiringWithin
public String refreshAndGetSecurityTokenIfExpiringWithin(Duration time)
Gets a security token from the federation endpoint if the security token expires within the provided duration.This will always retrieve a new token from the federation endpoint and does not use a cached token.
- Specified by:
refreshAndGetSecurityTokenIfExpiringWithinin interfaceProvidesConfigurableRefresh- Parameters:
time- the duration to check- Returns:
- A security token that can be used to authenticate requests.
-
makeCall
protected javax.ws.rs.core.Response makeCall(javax.ws.rs.client.Invocation.Builder ib, URI requestUri, GetResourcePrincipalSessionTokenRequest request)
-
makeCall
protected javax.ws.rs.core.Response makeCall(javax.ws.rs.client.Invocation.Builder ib, URI requestUri)
-
refreshAndGetSecurityTokenInner
protected String refreshAndGetSecurityTokenInner(boolean doFinalTokenValidityCheck, Optional<Duration> time, boolean refreshKeys)
-
getSecurityTokenFromServer
protected abstract SecurityTokenAdapter getSecurityTokenFromServer()
Gets a security token from the federation server- Returns:
- the security token, which is basically a JWT token string
-
makeCallInner
protected javax.ws.rs.core.Response makeCallInner(WrappedInvocationBuilder wrappedIb, Object request)
-
getStringClaim
public String getStringClaim(String key)
Get a claim embedded in the security token.May use the cached token if it is judged to still be valid.
- Specified by:
getStringClaimin interfaceFederationClient
-
getSecurityTokenFromServerInner
protected SecurityTokenAdapter getSecurityTokenFromServerInner(RSAPublicKey publicKey, javax.ws.rs.client.WebTarget target, String securityContext)
-
-