Package org.forgerock.openig.ping
Class PingFederateStatelessAccessTokenResolverHeaplet
java.lang.Object
org.forgerock.openig.heap.GenericHeaplet
org.forgerock.openig.ping.PingFederateStatelessAccessTokenResolverHeaplet
- All Implemented Interfaces:
Heaplet
Creates a
StatelessAccessTokenResolver validating stateless access tokens issued by a PingFederate server,
without any network round-trip to the token provider. PingFederate access tokens are signed JWTs.
Limitation: encrypted access tokens are not supported here — the gateway does not hold the PingFederate private key; encrypted-token support is covered by a dedicated story.
Violations on the token claims are collected and reported together in a single AccessTokenException.
{
"type": "PingFederateStatelessAccessTokenResolver",
"config": {
"pingFederateService": reference [REQUIRED - reference to a PingFederateService declared in the
heap, exposing the PingFederate JWK Set.]
"iss" : string [OPTIONAL - issuer claim value to enforce - no issuer check when
absent or empty.]
"aud" : string [OPTIONAL - audience claim value to enforce - no audience check
when absent or empty. The token's aud
claim may be a string or an array of
strings, and matches when it contains
this value.]
"skewAllowance" : duration [OPTIONAL - clock skew allowance applied to the temporal checks
- defaults to "0 seconds".]
"scope" : object [OPTIONAL - scope claim configuration.]
"claim" : string [OPTIONAL - pointer to the claim holding the scopes -
defaults to "scope".]
"format" : string [OPTIONAL - how the scopes are encoded in the claim, either
"space-delimited" or "json-array" -
defaults to "space-delimited".]
}
}
The example configuration below illustrates a PingFederate stateless access token resolver config:
{
"name": "PingFederateResolver",
"type": "PingFederateStatelessAccessTokenResolver",
"config": {
"pingFederateService": "PingFederateService",
"iss": "https://pingfed.example.com",
"aud": "my-client-id",
"skewAllowance": "1 minute",
"scope": {
"claim": "scope",
"format": "space-delimited"
}
}
}
-
Field Summary
Fields -
Constructor Summary
Constructors -
Method Summary
Methods inherited from class org.forgerock.openig.heap.GenericHeaplet
create, destroy, endpointRegistry, evaluatedWithHeapProperties, expression, getConfig, getHeap, getType, initialBindings, meterRegistryHolder, start
-
Field Details
-
NAME
Heap object name of this resolver.- See Also:
-
-
Constructor Details
-
PingFederateStatelessAccessTokenResolverHeaplet
public PingFederateStatelessAccessTokenResolverHeaplet()
-
-
Method Details
-
create
Description copied from class:GenericHeapletCalled to request the heaplet create an object. Called byHeaplet.create(Name, JsonValue, Heap)after initializing the protected field members. Implementations should parse configuration but not acquire resources, start threads, or log any initialization messages. These tasks should be performed by theGenericHeaplet.start()method.- Specified by:
createin classGenericHeaplet- Returns:
- The created object.
- Throws:
HeapException- if an exception occurred during creation of the heap object or any of its dependencies.
-