Interface AuthenticationRequirements
These requirements are initially established based on the authentication request received by the authentication service.
The different authentication requirements are enforced/handled by the authentication service, but they are also made available here in case plugins need to rely on them. For example, when user re-authentication is requested, the authentication service ensures that the applicable authenticators are activated, but an authenticator contacting an external authentication provider may want to relay that information.
Can only be used by Authenticator and Authentication Action plugins.
- Since:
- 6.6.0
-
Method Summary
Modifier and TypeMethodDescriptionGets the maximum allowed elapsed time since the last time the user was actively authenticated.booleanWhether the user should reauthenticate.
-
Method Details
-
shouldForceAuthentication
boolean shouldForceAuthentication()Whether the user should reauthenticate.This can be true, for example, when the original request leading to the authentication service was an OpenID Connect request having
prompt=login.- Returns:
- whether the user should be re-authenticated
-
getMaximumAuthenticationAge
Gets the maximum allowed elapsed time since the last time the user was actively authenticated.- Returns:
- the maximum allowed time since last authentication, in seconds, or empty if it wasn't provided
-