AttestationBasedClientAuthenticationService

class AttestationBasedClientAuthenticationService @JvmOverloads constructor(acceptedPopMethods: Set<OpenIdConstants.ClientAttestationPopMethod> = setOf(AttestationPopJwt), verifyJwsObject: VerifyJwsObjectFun = VerifyJwsObject(), verifyJwsSignatureWithCnf: VerifyJwsSignatureWithCnfFun = VerifyJwsSignatureWithCnf(), clock: Clock = Clock.System, timeLeeway: Duration = 5.minutes, maxAgePoP: Duration = 10.minutes, issuerIdentifier: String? = null, supportedSigningAlgorithms: Set<JwsAlgorithm.Signature> = DEFAULT_WALLET_ATTESTATION_ALGORITHMS, nonceService: NonceService = DefaultNonceService()) : ClientAuthenticationService(source)

Client authentication service for an OAuth2.0 AS, based on Attestation-Based Client Authentication.

Implemented from:

Constructors

constructor(acceptedPopMethods: Set<OpenIdConstants.ClientAttestationPopMethod> = setOf(AttestationPopJwt), verifyJwsObject: VerifyJwsObjectFun = VerifyJwsObject(), verifyJwsSignatureWithCnf: VerifyJwsSignatureWithCnfFun = VerifyJwsSignatureWithCnf(), clock: Clock = Clock.System, timeLeeway: Duration = 5.minutes, maxAgePoP: Duration = 10.minutes, issuerIdentifier: String? = null, supportedSigningAlgorithms: Set<JwsAlgorithm.Signature> = DEFAULT_WALLET_ATTESTATION_ALGORITHMS, nonceService: NonceService = DefaultNonceService())

Properties

Link copied to clipboard
open override val supportedAuthMethods: Set<String>
Link copied to clipboard
open override val supportedPopSigningAlgs: Set<String>
Link copied to clipboard
open override val supportedSigningAlgs: Set<String>

Functions

Link copied to clipboard
open suspend override fun authenticateClient(httpRequest: RequestInfo?, clientId: String?, validatedClientKey: JsonWebKey?): KmmResult<AuthenticatedClient>

Authenticates the client as defined from a client attestation JWT.

Link copied to clipboard
open suspend override fun getAttestationChallenge(): String

Provide a fresh challenge for attestation PoPs.