Class OpenIdProvider
java.lang.Object
io.goobi.viewer.model.security.authentication.HttpAuthenticationProvider
io.goobi.viewer.model.security.authentication.OpenIdProvider
- All Implemented Interfaces:
IAuthenticationProvider
OpenIdProvider class.
-
Field Summary
Fields inherited from class io.goobi.viewer.model.security.authentication.HttpAuthenticationProvider
addUserToGroups, connectionManager, DEFAULT_EMAIL, image, label, name, redirectUrl, timeoutMillis, type, TYPE_USER_PASSWORD, url
-
Constructor Summary
-
Method Summary
Modifier and TypeMethodDescriptionboolean
allowsEmailChange.boolean
allowsNicknameChange.boolean
Check whether this authentication service allows user to edit their password or to reset itcompleteLogin
(org.json.JSONObject json, javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response) Tries to find or create a validUser
based on the given json object.Getter for the fieldclientId
.Getter for the fieldclientSecret
.Getter for the fieldoAuthAccessToken
.Getter for the fieldoAuthState
.getScope()
Returns a future containing the login result upon completion.void
logout()
Logs the user outvoid
setoAuthAccessToken
(String oAuthAccessToken) Setter for the fieldoAuthAccessToken
.void
setoAuthState
(String oAuthState) Setter for the fieldoAuthState
.setRedirectionEndpoint
(String redirectionEndpoint) setThirdPartyVariables
(String thirdPartyLoginUrl, String thirdPartyLoginApiKey, String thirdPartyLoginScope, String thirdPartyLoginReqParamDef, String thirdPartyLoginClaim) setTokenEndpoint
(String tokenEndpoint) Methods inherited from class io.goobi.viewer.model.security.authentication.HttpAuthenticationProvider
get, getAddUserToGroups, getImage, getImageUrl, getLabel, getName, getRedirectUrl, getTimeoutMillis, getType, getUrl, post, setAddUserToGroups, setRedirectUrl
-
Field Details
-
TYPE_OPENID
ConstantTYPE_OPENID="openId"
- See Also:
-
-
Constructor Details
-
Method Details
-
getClientId
Getter for the field
clientId
.- Returns:
- the clientId
-
getClientSecret
Getter for the field
clientSecret
.- Returns:
- the clientSecret
-
getTokenEndpoint
- Returns:
- the tokenEndpoint
-
setTokenEndpoint
- Parameters:
tokenEndpoint
- the tokenEndpoint to set- Returns:
- this
-
getRedirectionEndpoint
- Returns:
- the redirectionEndpoint
-
setRedirectionEndpoint
- Parameters:
redirectionEndpoint
- the redirectionEndpoint to set- Returns:
- this
-
getScope
- Returns:
- the scope
-
setScope
- Parameters:
scope
- the scope to set- Returns:
- this
-
getThirdPartyLoginUrl
-
getThirdPartyLoginApiKey
-
getThirdPartyLoginScope
-
getThirdPartyLoginReqParamDef
-
getThirdPartyLoginClaim
-
setThirdPartyVariables
-
login
public CompletableFuture<LoginResult> login(String loginName, String password) throws AuthenticationProviderException Returns a future containing the login result upon completion. The result optionally contains the logged inUser
as well as theHttpServletRequest
andHttpServletResponse
to be used to complete the login and possible request forwarding If an error occurs and the request can not be processed, anAuthenticationException
must be thrown. If a login has been refused, the exact reasons can be determined using the methodsUser.isActive()
,User.isSuspended()
andLoginResult.isRefused()
- Parameters:
loginName
- aString
object.password
- A string to be used as a password or similar for login. If the provider does not require such a string, this can be left empty or null- Returns:
- A
CompletableFuture
which is resolved once login is completed and contains aLoginResult
- Throws:
AuthenticationProviderException
- if any.
-
completeLogin
public Future<Boolean> completeLogin(org.json.JSONObject json, javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response) Tries to find or create a validUser
based on the given json object. Generates aLoginResult
containing the given request and response and either an optional containing the user or nothing if no user was found, or aAuthenticationProviderException
if an internal error occured during login If this method is not called withinHttpAuthenticationProvider.getTimeoutMillis()
ms after callinglogin(String, String)
, a loginResponse is created containing an appropriate exception. In any case, the future returned bylogin(String, String)
is resolved.- Parameters:
json
- The server response as json object. If null, the login request is resolved as failurerequest
- aHttpServletRequest
object.response
- aHttpServletResponse
object.- Returns:
- a
Future
object.
-
logout
Logs the user out- Throws:
AuthenticationProviderException
- if any.
-
allowsPasswordChange
public boolean allowsPasswordChange()Check whether this authentication service allows user to edit their password or to reset it- Returns:
- true if the authentication service provides means to change or reset the user password
-
getoAuthState
Getter for the field
oAuthState
.- Returns:
- the oAuthState
-
setoAuthState
Setter for the field
oAuthState
.- Parameters:
oAuthState
- the oAuthState to set
-
getoAuthAccessToken
Getter for the field
oAuthAccessToken
.- Returns:
- the oAuthAccessToken
-
setoAuthAccessToken
Setter for the field
oAuthAccessToken
.- Parameters:
oAuthAccessToken
- the oAuthAccessToken to set
-
allowsNicknameChange
public boolean allowsNicknameChange()allowsNicknameChange.
- Returns:
- true if the nickname may be changed and is not essential for user identification
-
allowsEmailChange
public boolean allowsEmailChange()allowsEmailChange.
- Returns:
- true if the email may be changed and is not essential for user identification
-