From 5f39aeb5907c33e889144b66a65f83909534a3a1 Mon Sep 17 00:00:00 2001 From: Dmitry Telegin Date: Mon, 29 Nov 2021 04:12:40 +0300 Subject: [PATCH] Pre-authorization hook for client policies Closes #9017 --- .../clientpolicy/ClientPolicyEvent.java | 1 + .../oidc/endpoints/AuthorizationEndpoint.java | 7 +++ .../PreAuthorizationRequestContext.java | 51 +++++++++++++++++++ .../executor/RejectRequestExecutor.java | 2 +- .../policies/AbstractClientPoliciesTest.java | 2 +- .../ClientPoliciesExtendedEventTest.java | 29 +++++++++++ .../client/policies/ClientPoliciesTest.java | 5 +- 7 files changed, 93 insertions(+), 4 deletions(-) create mode 100644 services/src/main/java/org/keycloak/services/clientpolicy/context/PreAuthorizationRequestContext.java diff --git a/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java b/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java index b17f8d21cb..90c270164c 100644 --- a/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java +++ b/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java @@ -30,6 +30,7 @@ public enum ClientPolicyEvent { UPDATED, VIEW, UNREGISTER, + PRE_AUTHORIZATION_REQUEST, AUTHORIZATION_REQUEST, IMPLICIT_HYBRID_TOKEN_RESPONSE, TOKEN_REQUEST, diff --git a/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java b/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java index 0e5890f589..7e632d0850 100755 --- a/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java +++ b/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java @@ -45,6 +45,7 @@ import org.keycloak.services.ErrorPageException; import org.keycloak.services.Urls; import org.keycloak.services.clientpolicy.ClientPolicyException; import org.keycloak.services.clientpolicy.context.AuthorizationRequestContext; +import org.keycloak.services.clientpolicy.context.PreAuthorizationRequestContext; import org.keycloak.services.messages.Messages; import org.keycloak.services.resources.LoginActionsService; import org.keycloak.services.util.CacheControlUtil; @@ -144,6 +145,12 @@ public class AuthorizationEndpoint extends AuthorizationEndpointBase { checkSsl(); checkRealm(); + + try { + session.clientPolicy().triggerOnEvent(new PreAuthorizationRequestContext(clientId, params)); + } catch (ClientPolicyException cpe) { + throw new ErrorPageException(session, authenticationSession, cpe.getErrorStatus(), cpe.getErrorDetail()); + } checkClient(clientId); request = AuthorizationEndpointRequestParserProcessor.parseRequest(event, session, client, params, AuthorizationEndpointRequestParserProcessor.EndpointType.OIDC_AUTH_ENDPOINT); diff --git a/services/src/main/java/org/keycloak/services/clientpolicy/context/PreAuthorizationRequestContext.java b/services/src/main/java/org/keycloak/services/clientpolicy/context/PreAuthorizationRequestContext.java new file mode 100644 index 0000000000..41b5ab33c0 --- /dev/null +++ b/services/src/main/java/org/keycloak/services/clientpolicy/context/PreAuthorizationRequestContext.java @@ -0,0 +1,51 @@ +/* + * Copyright 2023 Red Hat, Inc. and/or its affiliates + * and other contributors as indicated by the @author tags. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +package org.keycloak.services.clientpolicy.context; + +import javax.ws.rs.core.MultivaluedMap; + +import org.keycloak.services.clientpolicy.ClientPolicyContext; +import org.keycloak.services.clientpolicy.ClientPolicyEvent; + +/** + * @author Dmitry Telegin + */ +public class PreAuthorizationRequestContext implements ClientPolicyContext { + + private final String clientId; + private final MultivaluedMap requestParameters; + + public PreAuthorizationRequestContext(String clientId, MultivaluedMap requestParameters) { + this.clientId = clientId; + this.requestParameters = requestParameters; + } + + @Override + public ClientPolicyEvent getEvent() { + return ClientPolicyEvent.PRE_AUTHORIZATION_REQUEST; + } + + public String getClientId() { + return clientId; + } + + public MultivaluedMap getRequestParameters() { + return requestParameters; + } + +} diff --git a/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java b/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java index f80337b261..e7b2c6602f 100644 --- a/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java +++ b/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java @@ -38,6 +38,6 @@ public class RejectRequestExecutor implements ClientPolicyExecutorProvider