Search in sources :

Example 11 with JWTTokenValidator

use of org.apache.cxf.sts.token.validator.jwt.JWTTokenValidator in project cxf by apache.

the class JWTTokenValidatorTest method testJWTWithRoles.

@org.junit.Test
public void testJWTWithRoles() throws Exception {
    // Create
    TokenProvider jwtTokenProvider = new JWTTokenProvider();
    ((JWTTokenProvider) jwtTokenProvider).setSignToken(true);
    JWTClaimsProvider claimsProvider = new RoleJWTClaimsProvider("manager");
    ((JWTTokenProvider) jwtTokenProvider).setJwtClaimsProvider(claimsProvider);
    TokenProviderParameters providerParameters = createProviderParameters();
    assertTrue(jwtTokenProvider.canHandleToken(JWTTokenProvider.JWT_TOKEN_TYPE));
    TokenProviderResponse providerResponse = jwtTokenProvider.createToken(providerParameters);
    assertTrue(providerResponse != null);
    assertTrue(providerResponse.getToken() != null && providerResponse.getTokenId() != null);
    String token = (String) providerResponse.getToken();
    assertNotNull(token);
    assertTrue(token.split("\\.").length == 3);
    // Validate the token
    TokenValidator jwtTokenValidator = new JWTTokenValidator();
    // Set the role
    DefaultJWTRoleParser roleParser = new DefaultJWTRoleParser();
    roleParser.setRoleClaim("role");
    ((JWTTokenValidator) jwtTokenValidator).setRoleParser(roleParser);
    TokenValidatorParameters validatorParameters = createValidatorParameters();
    TokenRequirements tokenRequirements = validatorParameters.getTokenRequirements();
    // Create a ValidateTarget consisting of a JWT Token
    ReceivedToken validateTarget = new ReceivedToken(createTokenWrapper(token));
    tokenRequirements.setValidateTarget(validateTarget);
    validatorParameters.setToken(validateTarget);
    assertTrue(jwtTokenValidator.canHandleToken(validateTarget));
    TokenValidatorResponse validatorResponse = jwtTokenValidator.validateToken(validatorParameters);
    assertTrue(validatorResponse != null);
    assertTrue(validatorResponse.getToken() != null);
    assertTrue(validatorResponse.getToken().getState() == STATE.VALID);
    Principal principal = validatorResponse.getPrincipal();
    assertTrue(principal != null && principal.getName() != null);
    Set<Principal> roles = validatorResponse.getRoles();
    assertTrue(roles != null && !roles.isEmpty());
    assertTrue(roles.iterator().next().getName().equals("manager"));
}
Also used : TokenProviderParameters(org.apache.cxf.sts.token.provider.TokenProviderParameters) TokenProvider(org.apache.cxf.sts.token.provider.TokenProvider) JWTTokenProvider(org.apache.cxf.sts.token.provider.jwt.JWTTokenProvider) JWTTokenValidator(org.apache.cxf.sts.token.validator.jwt.JWTTokenValidator) JWTClaimsProvider(org.apache.cxf.sts.token.provider.jwt.JWTClaimsProvider) DefaultJWTClaimsProvider(org.apache.cxf.sts.token.provider.jwt.DefaultJWTClaimsProvider) TokenRequirements(org.apache.cxf.sts.request.TokenRequirements) JWTTokenValidator(org.apache.cxf.sts.token.validator.jwt.JWTTokenValidator) DefaultJWTRoleParser(org.apache.cxf.sts.token.validator.jwt.DefaultJWTRoleParser) TokenProviderResponse(org.apache.cxf.sts.token.provider.TokenProviderResponse) ReceivedToken(org.apache.cxf.sts.request.ReceivedToken) CustomTokenPrincipal(org.apache.wss4j.common.principal.CustomTokenPrincipal) Principal(java.security.Principal) JWTTokenProvider(org.apache.cxf.sts.token.provider.jwt.JWTTokenProvider)

Aggregations

TokenProviderResponse (org.apache.cxf.sts.token.provider.TokenProviderResponse)11 JWTTokenValidator (org.apache.cxf.sts.token.validator.jwt.JWTTokenValidator)11 TokenProvider (org.apache.cxf.sts.token.provider.TokenProvider)10 JWTTokenProvider (org.apache.cxf.sts.token.provider.jwt.JWTTokenProvider)10 ReceivedToken (org.apache.cxf.sts.request.ReceivedToken)8 TokenRequirements (org.apache.cxf.sts.request.TokenRequirements)8 TokenProviderParameters (org.apache.cxf.sts.token.provider.TokenProviderParameters)8 Principal (java.security.Principal)7 CustomTokenPrincipal (org.apache.wss4j.common.principal.CustomTokenPrincipal)7 PasswordCallbackHandler (org.apache.cxf.sts.common.PasswordCallbackHandler)5 Crypto (org.apache.wss4j.common.crypto.Crypto)5 ArrayList (java.util.ArrayList)3 JAXBElement (javax.xml.bind.JAXBElement)3 WrappedMessageContext (org.apache.cxf.jaxws.context.WrappedMessageContext)3 MessageImpl (org.apache.cxf.message.MessageImpl)3 SecurityContext (org.apache.cxf.security.SecurityContext)3 STSPropertiesMBean (org.apache.cxf.sts.STSPropertiesMBean)3 StaticSTSProperties (org.apache.cxf.sts.StaticSTSProperties)3 DefaultJWTClaimsProvider (org.apache.cxf.sts.token.provider.jwt.DefaultJWTClaimsProvider)3 TokenValidator (org.apache.cxf.sts.token.validator.TokenValidator)3