Class ClientCertificateFilter

java.lang.Object
org.forgerock.openig.fapi.certificate.ClientCertificateFilter
All Implemented Interfaces:
Filter

public class ClientCertificateFilter extends Object implements Filter
Filter responsible for initializing the ClientCertificateFapiContext, with a client's TLS certificate.

This filter is not expected to be instantiated directly as it is managed as part of the core FAPI Filter chains e.g. FapiDcrFilterChainHeaplet.

  • Constructor Details

    • ClientCertificateFilter

      public ClientCertificateFilter(Expression<Certificate> clientCertificateExpression, boolean isMandatory)
      ClientCertificateFilter constructor, though this filter shouldn't be initiated directly as it is managed as part of FAPI filter chains.
      Parameters:
      clientCertificateExpression - the Expression<Certificate> used to retrieve client certificate
      isMandatory - boolean to defined if the client certificate is mandatory; if false, the client certificate can be missing, otherwise it is required to be present and valid.
  • Method Details

    • filter

      public Promise<Response,NeverThrowsException> filter(Context context, Request request, Handler next)
      Description copied from interface: Filter
      Filters the request and/or response of an exchange. To pass the request to the next filter or handler in the chain, the filter calls next.handle(context, request).

      This method may elect not to pass the request to the next filter or handler, and instead handle the request itself. It can achieve this by merely avoiding a call to next.handle(context, request) and creating its own response object. The filter is also at liberty to replace a response with another of its own by intercepting the response returned by the next handler.

      Specified by:
      filter in interface Filter
      Parameters:
      context - The request context.
      request - The request.
      next - The next filter or handler in the chain to handle the request.
      Returns:
      A Promise representing the response to be returned to the client.