Class ClientCertificateFilter
java.lang.Object
org.forgerock.openig.fapi.certificate.ClientCertificateFilter
- All Implemented Interfaces:
Filter
Filter responsible for initializing the ClientCertificateFapiContext, with a client's TLS
certificate.
This filter is not expected to be instantiated directly as it is managed as part of the core FAPI Filter
chains e.g. FapiDcrFilterChainHeaplet.
-
Constructor Summary
ConstructorsConstructorDescriptionClientCertificateFilter(Expression<Certificate> clientCertificateExpression, boolean isMandatory) ClientCertificateFilterconstructor, though this filter shouldn't be initiated directly as it is managed as part of FAPI filter chains. -
Method Summary
-
Constructor Details
-
ClientCertificateFilter
public ClientCertificateFilter(Expression<Certificate> clientCertificateExpression, boolean isMandatory) ClientCertificateFilterconstructor, though this filter shouldn't be initiated directly as it is managed as part of FAPI filter chains.- Parameters:
clientCertificateExpression- theExpression<Certificate>used to retrieve client certificateisMandatory- boolean to defined if the client certificate is mandatory; iffalse, the client certificate can be missing, otherwise it is required to be present and valid.
-
-
Method Details
-
filter
public Promise<Response,NeverThrowsException> filter(Context context, Request request, Handler next) Description copied from interface:FilterFilters the request and/or response of an exchange. To pass the request to the next filter or handler in the chain, the filter callsnext.handle(context, request).This method may elect not to pass the request to the next filter or handler, and instead handle the request itself. It can achieve this by merely avoiding a call to
next.handle(context, request)and creating its own response object. The filter is also at liberty to replace a response with another of its own by intercepting the response returned by the next handler.
-