Class RestDelegatePkiAuthenticationAction
java.lang.Object
org.elasticsearch.rest.BaseRestHandler
org.elasticsearch.xpack.security.rest.action.SecurityBaseRestHandler
org.elasticsearch.xpack.security.rest.action.RestDelegatePkiAuthenticationAction
- All Implemented Interfaces:
org.elasticsearch.rest.RestHandler
Implements the exchange of an
X509Certificate chain into an access token. The chain is represented as an ordered string array.
Each string in the array is a base64-encoded (Section 4 of RFC4648 - not base64url-encoded) DER PKIX certificate value.
See also TransportDelegatePkiAuthenticationAction.-
Nested Class Summary
Nested classes/interfaces inherited from class org.elasticsearch.rest.BaseRestHandler
org.elasticsearch.rest.BaseRestHandler.RestChannelConsumer, org.elasticsearch.rest.BaseRestHandler.WrapperNested classes/interfaces inherited from interface org.elasticsearch.rest.RestHandler
org.elasticsearch.rest.RestHandler.Route -
Field Summary
FieldsFields inherited from class org.elasticsearch.xpack.security.rest.action.SecurityBaseRestHandler
licenseState, settingsFields inherited from class org.elasticsearch.rest.BaseRestHandler
DEFAULT_INCLUDE_TYPE_NAME_POLICY, INCLUDE_TYPE_NAME_PARAMETER, MULTI_ALLOW_EXPLICIT_INDEX -
Constructor Summary
ConstructorsConstructorDescriptionRestDelegatePkiAuthenticationAction(org.elasticsearch.common.settings.Settings settings, org.elasticsearch.license.XPackLicenseState xPackLicenseState) -
Method Summary
Modifier and TypeMethodDescriptionprotected ExceptioncheckFeatureAvailable(org.elasticsearch.rest.RestRequest request) Check whether the given request is allowed within the current license state and setup, and return the name of any unlicensed feature.getName()protected org.elasticsearch.rest.BaseRestHandler.RestChannelConsumerinnerPrepareRequest(org.elasticsearch.rest.RestRequest request, org.elasticsearch.client.internal.node.NodeClient client) Implementers should implement this method as they normally would forBaseRestHandler.prepareRequest(RestRequest, NodeClient)and ensure that all request parameters are consumed prior to returning a value.List<org.elasticsearch.rest.RestHandler.Route>routes()Methods inherited from class org.elasticsearch.xpack.security.rest.action.SecurityBaseRestHandler
prepareRequestMethods inherited from class org.elasticsearch.rest.BaseRestHandler
getUsageCount, handleRequest, mediaTypesValid, responseParams, responseParams, unrecognizedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.elasticsearch.rest.RestHandler
allowsUnsafeBuffers, allowSystemIndexAccessByDefault, canTripCircuitBreaker, supportsContentStream
-
Field Details
-
logger
protected org.apache.logging.log4j.Logger logger
-
-
Constructor Details
-
RestDelegatePkiAuthenticationAction
public RestDelegatePkiAuthenticationAction(org.elasticsearch.common.settings.Settings settings, org.elasticsearch.license.XPackLicenseState xPackLicenseState)
-
-
Method Details
-
routes
- Specified by:
routesin interfaceorg.elasticsearch.rest.RestHandler- Specified by:
routesin classorg.elasticsearch.rest.BaseRestHandler
-
checkFeatureAvailable
Description copied from class:SecurityBaseRestHandlerCheck whether the given request is allowed within the current license state and setup, and return the name of any unlicensed feature. By default this returns an exception if security is not enabled. Sub-classes can override this method if they have additional requirements.- Overrides:
checkFeatureAvailablein classSecurityBaseRestHandler- Returns:
nullif all required features are available, otherwise an exception to be sent to the requestor
-
innerPrepareRequest
protected org.elasticsearch.rest.BaseRestHandler.RestChannelConsumer innerPrepareRequest(org.elasticsearch.rest.RestRequest request, org.elasticsearch.client.internal.node.NodeClient client) throws IOException Description copied from class:SecurityBaseRestHandlerImplementers should implement this method as they normally would forBaseRestHandler.prepareRequest(RestRequest, NodeClient)and ensure that all request parameters are consumed prior to returning a value. The returned value is not guaranteed to be executed unless security is licensed and all request parameters are known- Specified by:
innerPrepareRequestin classSecurityBaseRestHandler- Throws:
IOException
-
getName
- Specified by:
getNamein classorg.elasticsearch.rest.BaseRestHandler
-