use of org.wso2.carbon.identity.oauth2.RequestObjectException in project identity-inbound-auth-oauth by wso2-extensions.
the class OIDCRequestObjectUtil method buildRequestObject.
/**
* Fetch and invoke the matched request builder class based on the identity.xml configurations.
* Build and validate the Request Object extracted from request information
*
* @param oauthRequest authorization request
* @throws RequestObjectException
*/
public static RequestObject buildRequestObject(OAuthAuthzRequest oauthRequest, OAuth2Parameters oAuth2Parameters) throws RequestObjectException {
/*
So that the request is a valid OAuth 2.0 Authorization Request, values for the response_type and client_id
parameters MUST be included using the OAuth 2.0 request syntax, since they are REQUIRED by OAuth 2.0.
The values for these parameters MUST match those in the Request Object, if present
*/
RequestObject requestObject;
RequestObjectBuilder requestObjectBuilder;
String requestObjType;
if (isRequestParameter(oauthRequest)) {
requestObjectBuilder = getRequestObjectBuilder(REQUEST_PARAM_VALUE_BUILDER);
requestObjType = REQUEST;
} else if (isRequestUri(oauthRequest)) {
requestObjectBuilder = getRequestObjectBuilder(REQUEST_URI_PARAM_VALUE_BUILDER);
requestObjType = REQUEST_URI;
} else {
// Unsupported request object type.
return null;
}
if (requestObjectBuilder == null) {
String error = "Unable to build the OIDC Request Object from:";
if (LoggerUtils.isDiagnosticLogsEnabled()) {
Map<String, Object> params = new HashMap<>();
params.put(REQUEST, oauthRequest.getParam(REQUEST));
params.put(REQUEST_URI, oauthRequest.getParam(REQUEST_URI));
LoggerUtils.triggerDiagnosticLogEvent(OAuthConstants.LogConstants.OAUTH_INBOUND_SERVICE, params, OAuthConstants.LogConstants.FAILED, "Server error occurred.", "parse-request-object", null);
}
throw new RequestObjectException(OAuth2ErrorCodes.SERVER_ERROR, error + requestObjType);
}
requestObject = requestObjectBuilder.buildRequestObject(oauthRequest.getParam(requestObjType), oAuth2Parameters);
RequestObjectValidator requestObjectValidator = OAuthServerConfiguration.getInstance().getRequestObjectValidator();
validateRequestObjectSignature(oAuth2Parameters, requestObject, requestObjectValidator);
if (!requestObjectValidator.validateRequestObject(requestObject, oAuth2Parameters)) {
throw new RequestObjectException(OAuth2ErrorCodes.INVALID_REQUEST, "Invalid parameters " + "found in the Request Object.");
}
if (log.isDebugEnabled()) {
log.debug("Successfully build and and validated request Object for: " + requestObjType);
}
return requestObject;
}
Aggregations