Class PingFederateStatelessAccessTokenResolverHeaplet

java.lang.Object
org.forgerock.openig.heap.GenericHeaplet
org.forgerock.openig.ping.PingFederateStatelessAccessTokenResolverHeaplet
All Implemented Interfaces:
Heaplet

public class PingFederateStatelessAccessTokenResolverHeaplet extends GenericHeaplet
Creates a StatelessAccessTokenResolver validating stateless access tokens issued by a PingFederate server, without any network round-trip to the token provider. PingFederate access tokens are signed JWTs.

Limitation: encrypted access tokens are not supported here — the gateway does not hold the PingFederate private key; encrypted-token support is covered by a dedicated story.

Violations on the token claims are collected and reported together in a single AccessTokenException.

 {
      "type": "PingFederateStatelessAccessTokenResolver",
      "config": {
        "pingFederateService": reference         [REQUIRED - reference to a PingFederateService declared in the
                                                                        heap, exposing the PingFederate JWK Set.]
        "iss"                 : string           [OPTIONAL - issuer claim value to enforce - no issuer check when
                                                                        absent or empty.]
        "aud"                 : string           [OPTIONAL - audience claim value to enforce - no audience check
                                                                        when absent or empty. The token's aud
                                                                        claim may be a string or an array of
                                                                        strings, and matches when it contains
                                                                        this value.]
        "skewAllowance"       : duration         [OPTIONAL - clock skew allowance applied to the temporal checks
                                                                        - defaults to "0 seconds".]
        "scope"               : object           [OPTIONAL - scope claim configuration.]
            "claim"           : string           [OPTIONAL - pointer to the claim holding the scopes -
                                                                        defaults to "scope".]
            "format"          : string           [OPTIONAL - how the scopes are encoded in the claim, either
                                                                        "space-delimited" or "json-array" -
                                                                        defaults to "space-delimited".]
      }
    }
 
 

The example configuration below illustrates a PingFederate stateless access token resolver config:

 {
     "name": "PingFederateResolver",
     "type": "PingFederateStatelessAccessTokenResolver",
     "config": {
         "pingFederateService": "PingFederateService",
         "iss": "https://pingfed.example.com",
         "aud": "my-client-id",
         "skewAllowance": "1 minute",
         "scope": {
             "claim": "scope",
             "format": "space-delimited"
         }
     }
 }
 
 
  • Field Details

  • Constructor Details

    • PingFederateStatelessAccessTokenResolverHeaplet

      public PingFederateStatelessAccessTokenResolverHeaplet()
  • Method Details