Class DcrTransportCertValidationFilter

java.lang.Object
org.forgerock.openig.fapi.dcr.certificate.DcrTransportCertValidationFilter
All Implemented Interfaces:
Filter

public final class DcrTransportCertValidationFilter extends Object implements Filter
Filter responsible for validating the inbound request's TLS transport certificate, as found in the ClientCertificateFapiContext.

Note that in the DCR flow, the JWKs to verify the certificate against are obtained as directed by the registration request's software statement. This is managed via a JwkSetService.

This filter is not expected to be instantiated directly as it is managed as part of the core FAPI Filter chain FapiDcrFilterChainHeaplet.

See Also:
  • Constructor Details

    • DcrTransportCertValidationFilter

      public DcrTransportCertValidationFilter(JwkSetService jwkSetService, TransportCertValidator transportCertValidator, boolean allowPingIssuedTestCerts)
      DcrTransportCertValidationFilter constructor.

      This filter is not expected to be instantiated directly as it is managed as part of the core FAPI Filter chain FapiDcrFilterChainHeaplet.

      Parameters:
      jwkSetService - JwkSetService to manage the valid client JwkSet
      transportCertValidator - TransportCertValidator to perform certificate validation
      allowPingIssuedTestCerts - true if PingGateway-issued certs are permissible, otherwise false
  • Method Details

    • filter

      public Promise<Response,NeverThrowsException> filter(Context context, Request request, Handler next)
      Description copied from interface: Filter
      Filters the request and/or response of an exchange. To pass the request to the next filter or handler in the chain, the filter calls next.handle(context, request).

      This method may elect not to pass the request to the next filter or handler, and instead handle the request itself. It can achieve this by merely avoiding a call to next.handle(context, request) and creating its own response object. The filter is also at liberty to replace a response with another of its own by intercepting the response returned by the next handler.

      Specified by:
      filter in interface Filter
      Parameters:
      context - The request context.
      request - The request.
      next - The next filter or handler in the chain to handle the request.
      Returns:
      A Promise representing the response to be returned to the client.