Interface AuthenticationRequirements


public interface AuthenticationRequirements
Current requirements for the ongoing authentication flow.

These requirements are initially established based on the authentication request received by the authentication service.

The different authentication requirements are enforced/handled by the authentication service, but they are also made available here in case plugins need to rely on them. For example, when user re-authentication is requested, the authentication service ensures that the applicable authenticators are activated, but an authenticator contacting an external authentication provider may want to relay that information.

Can only be used by Authenticator and Authentication Action plugins.

Since:
6.6.0
  • Method Details

    • shouldForceAuthentication

      boolean shouldForceAuthentication()
      Whether the user should reauthenticate.

      This can be true, for example, when the original request leading to the authentication service was an OpenID Connect request having prompt=login.

      Returns:
      whether the user should be re-authenticated
    • getMaximumAuthenticationAge

      Optional<Long> getMaximumAuthenticationAge()
      Gets the maximum allowed elapsed time since the last time the user was actively authenticated.
      Returns:
      the maximum allowed time since last authentication, in seconds, or empty if it wasn't provided