AttestationBasedClientAuthenticationService
class AttestationBasedClientAuthenticationService @JvmOverloads constructor(acceptedPopMethods: Set<OpenIdConstants.ClientAttestationPopMethod> = setOf(AttestationPopJwt), verifyJwsObject: VerifyJwsObjectFun = VerifyJwsObject(), verifyJwsSignatureWithCnf: VerifyJwsSignatureWithCnfFun = VerifyJwsSignatureWithCnf(), clock: Clock = Clock.System, timeLeeway: Duration = 5.minutes, maxAgePoP: Duration = 10.minutes, issuerIdentifier: String? = null, supportedSigningAlgorithms: Set<JwsAlgorithm.Signature> = DEFAULT_WALLET_ATTESTATION_ALGORITHMS, nonceService: NonceService = DefaultNonceService()) : ClientAuthenticationService(source)
Client authentication service for an OAuth2.0 AS, based on Attestation-Based Client Authentication.
Implemented from:
Constructors
Link copied to clipboard
constructor(acceptedPopMethods: Set<OpenIdConstants.ClientAttestationPopMethod> = setOf(AttestationPopJwt), verifyJwsObject: VerifyJwsObjectFun = VerifyJwsObject(), verifyJwsSignatureWithCnf: VerifyJwsSignatureWithCnfFun = VerifyJwsSignatureWithCnf(), clock: Clock = Clock.System, timeLeeway: Duration = 5.minutes, maxAgePoP: Duration = 10.minutes, issuerIdentifier: String? = null, supportedSigningAlgorithms: Set<JwsAlgorithm.Signature> = DEFAULT_WALLET_ATTESTATION_ALGORITHMS, nonceService: NonceService = DefaultNonceService())
Properties
Functions
Link copied to clipboard
open suspend override fun authenticateClient(httpRequest: RequestInfo?, clientId: String?, validatedClientKey: JsonWebKey?): KmmResult<AuthenticatedClient>
Authenticates the client as defined from a client attestation JWT.
Link copied to clipboard
Provide a fresh challenge for attestation PoPs.