Interface BackchannelAuthenticatorPluginDescriptor<C extends Configuration>

All Superinterfaces:
PluginDescriptor<C>

public interface BackchannelAuthenticatorPluginDescriptor<C extends Configuration> extends PluginDescriptor<C>
This interface describes the plugin for an authenticator that is capable of both normal as well as backchannel authentication requests.
  • Method Details

    • getBackchannelAuthenticationHandlerType

      Class<? extends BackchannelAuthenticationHandler> getBackchannelAuthenticationHandlerType()
      Return the type of the authentication handler that handles backchannel authentication.

      As this flow does not involve any user interaction, no URI paths whatsoever are included in the response.

      Returns:
      the type of the handler that handles backchannel authentication.
    • getFrontchannelPluginDescriptorReference

      @Nullable default @Nullable Class<? extends AuthenticatorPluginDescriptor<?>> getFrontchannelPluginDescriptorReference()
      When the backchannel authenticator is based on a frontchannel authenticator, return the plugin descriptor of the "linked" frontchannel authenticator.

      If a non-null value is returned, then classes in this plugin may obtain not only the configuration object (of type BackchannelAuthenticatorPluginDescriptor) for this plugin via constructor injection, but also the configuration object specified for the linked frontchannel authenticator, which means that this plugin can, essentially, share the same configuration values with the linked plugin. The ManagedObject of the frontchannel plugin can also be injected into the backchannel authenticator's constructor, allowing the two plugins to also share resources like database connections.

      For this reason, the linked plugin must be placed in the same plugin group as this plugin and, if necessary, both plugins should declare Shared-Session-Sandbox: true in their Manifest (in other words, the two plugins must share the same classpath and, optionally, session data).

      Returns:
      the frontchannel authenticator descriptor type if linked, or null if not.