use of org.apache.cxf.rs.security.jose.jwt.JwtToken in project cxf by apache.
the class JWTClaimsTest method testJWTRoleUsingCustomReturnType.
@org.junit.Test
public void testJWTRoleUsingCustomReturnType() throws Exception {
TokenProvider tokenProvider = new JWTTokenProvider();
TokenProviderParameters providerParameters = createProviderParameters(JWTTokenProvider.JWT_TOKEN_TYPE, null);
ClaimsManager claimsManager = new ClaimsManager();
ClaimsHandler claimsHandler = new CustomClaimsHandler();
claimsManager.setClaimHandlers(Collections.singletonList(claimsHandler));
providerParameters.setClaimsManager(claimsManager);
ClaimCollection claims = new ClaimCollection();
URI role = URI.create("http://schemas.xmlsoap.org/ws/2005/05/identity/claims/role");
Claim claim = new Claim();
claim.setClaimType(role);
claims.add(claim);
providerParameters.setRequestedPrimaryClaims(claims);
Map<String, String> claimTypeMap = new HashMap<>();
claimTypeMap.put(role.toString(), "roles");
DefaultJWTClaimsProvider claimsProvider = new DefaultJWTClaimsProvider();
claimsProvider.setClaimTypeMap(claimTypeMap);
((JWTTokenProvider) tokenProvider).setJwtClaimsProvider(claimsProvider);
assertTrue(tokenProvider.canHandleToken(JWTTokenProvider.JWT_TOKEN_TYPE));
TokenProviderResponse providerResponse = tokenProvider.createToken(providerParameters);
assertTrue(providerResponse != null);
assertTrue(providerResponse.getToken() != null && providerResponse.getTokenId() != null);
String token = (String) providerResponse.getToken();
assertNotNull(token);
JwsJwtCompactConsumer jwtConsumer = new JwsJwtCompactConsumer(token);
JwtToken jwt = jwtConsumer.getJwtToken();
assertEquals(jwt.getClaim("roles"), "DUMMY");
}
use of org.apache.cxf.rs.security.jose.jwt.JwtToken in project cxf by apache.
the class JWTClaimsTest method testJWTClaims.
/**
* Test the creation of a JWTToken with various claims set by a ClaimsHandler.
*/
@org.junit.Test
public void testJWTClaims() throws Exception {
TokenProvider tokenProvider = new JWTTokenProvider();
TokenProviderParameters providerParameters = createProviderParameters(JWTTokenProvider.JWT_TOKEN_TYPE, null);
ClaimsManager claimsManager = new ClaimsManager();
ClaimsHandler claimsHandler = new CustomClaimsHandler();
claimsManager.setClaimHandlers(Collections.singletonList(claimsHandler));
providerParameters.setClaimsManager(claimsManager);
ClaimCollection claims = createClaims();
providerParameters.setRequestedPrimaryClaims(claims);
assertTrue(tokenProvider.canHandleToken(JWTTokenProvider.JWT_TOKEN_TYPE));
TokenProviderResponse providerResponse = tokenProvider.createToken(providerParameters);
assertTrue(providerResponse != null);
assertTrue(providerResponse.getToken() != null && providerResponse.getTokenId() != null);
String token = (String) providerResponse.getToken();
assertNotNull(token);
JwsJwtCompactConsumer jwtConsumer = new JwsJwtCompactConsumer(token);
JwtToken jwt = jwtConsumer.getJwtToken();
assertEquals(jwt.getClaim(ClaimTypes.EMAILADDRESS.toString()), "alice@cxf.apache.org");
assertEquals(jwt.getClaim(ClaimTypes.FIRSTNAME.toString()), "alice");
assertEquals(jwt.getClaim(ClaimTypes.LASTNAME.toString()), "doe");
}
use of org.apache.cxf.rs.security.jose.jwt.JwtToken in project cxf by apache.
the class JWTProviderActAsTest method testJWTActAsUsernameToken.
/**
* Create a JWT Token with ActAs from a UsernameToken
*/
@org.junit.Test
public void testJWTActAsUsernameToken() throws Exception {
TokenProvider tokenProvider = new JWTTokenProvider();
UsernameTokenType usernameToken = new UsernameTokenType();
AttributedString username = new AttributedString();
username.setValue("bob");
usernameToken.setUsername(username);
JAXBElement<UsernameTokenType> usernameTokenType = new JAXBElement<UsernameTokenType>(QNameConstants.USERNAME_TOKEN, UsernameTokenType.class, usernameToken);
TokenProviderParameters providerParameters = createProviderParameters(JWTTokenProvider.JWT_TOKEN_TYPE, usernameTokenType);
// Principal must be set in ReceivedToken/ActAs
providerParameters.getTokenRequirements().getActAs().setPrincipal(new CustomTokenPrincipal(username.getValue()));
assertTrue(tokenProvider.canHandleToken(JWTTokenProvider.JWT_TOKEN_TYPE));
TokenProviderResponse providerResponse = tokenProvider.createToken(providerParameters);
assertTrue(providerResponse != null);
assertTrue(providerResponse.getToken() != null && providerResponse.getTokenId() != null);
String token = (String) providerResponse.getToken();
assertNotNull(token);
// Validate the token
JwsJwtCompactConsumer jwtConsumer = new JwsJwtCompactConsumer(token);
JwtToken jwt = jwtConsumer.getJwtToken();
Assert.assertEquals("technical-user", jwt.getClaim(JwtConstants.CLAIM_SUBJECT));
Assert.assertEquals("bob", jwt.getClaim("ActAs"));
}
use of org.apache.cxf.rs.security.jose.jwt.JwtToken in project cxf by apache.
the class JWTProviderActAsTest method testJWTActAsAssertion.
/**
* Create a JWT Token with ActAs from a SAML Assertion
*/
@org.junit.Test
public void testJWTActAsAssertion() throws Exception {
TokenProvider tokenProvider = new JWTTokenProvider();
String user = "bob";
Element saml1Assertion = getSAMLAssertion(user);
TokenProviderParameters providerParameters = createProviderParameters(JWTTokenProvider.JWT_TOKEN_TYPE, saml1Assertion);
// Principal must be set in ReceivedToken/ActAs
providerParameters.getTokenRequirements().getActAs().setPrincipal(new CustomTokenPrincipal(user));
assertTrue(tokenProvider.canHandleToken(JWTTokenProvider.JWT_TOKEN_TYPE));
TokenProviderResponse providerResponse = tokenProvider.createToken(providerParameters);
assertTrue(providerResponse != null);
assertTrue(providerResponse.getToken() != null && providerResponse.getTokenId() != null);
String token = (String) providerResponse.getToken();
assertNotNull(token);
// Validate the token
JwsJwtCompactConsumer jwtConsumer = new JwsJwtCompactConsumer(token);
JwtToken jwt = jwtConsumer.getJwtToken();
Assert.assertEquals("technical-user", jwt.getClaim(JwtConstants.CLAIM_SUBJECT));
Assert.assertEquals("bob", jwt.getClaim("ActAs"));
}
use of org.apache.cxf.rs.security.jose.jwt.JwtToken in project cxf by apache.
the class JWTProviderLifetimeTest method testJWTProviderLifetime.
/**
* Issue JWT token with a lifetime configured in JWTTokenProvider
* No specific lifetime requested
*/
@org.junit.Test
public void testJWTProviderLifetime() throws Exception {
long providerLifetime = 10 * 600L;
JWTTokenProvider tokenProvider = new JWTTokenProvider();
DefaultJWTClaimsProvider claimsProvider = new DefaultJWTClaimsProvider();
claimsProvider.setLifetime(providerLifetime);
tokenProvider.setJwtClaimsProvider(claimsProvider);
TokenProviderParameters providerParameters = createProviderParameters(JWTTokenProvider.JWT_TOKEN_TYPE);
TokenProviderResponse providerResponse = tokenProvider.createToken(providerParameters);
assertTrue(providerResponse != null);
assertTrue(providerResponse.getToken() != null && providerResponse.getTokenId() != null);
long duration = Duration.between(providerResponse.getCreated(), providerResponse.getExpires()).getSeconds();
assertEquals(providerLifetime, duration);
String token = (String) providerResponse.getToken();
assertNotNull(token);
JwsJwtCompactConsumer jwtConsumer = new JwsJwtCompactConsumer(token);
JwtToken jwt = jwtConsumer.getJwtToken();
assertEquals(jwt.getClaim(JwtConstants.CLAIM_ISSUED_AT), providerResponse.getCreated().getEpochSecond());
Instant now = Instant.now();
Long expiry = (Long) jwt.getClaim(JwtConstants.CLAIM_EXPIRY);
Instant.ofEpochSecond(expiry).isAfter(now);
}
Aggregations