Class WebAuthnAuthenticator
java.lang.Object
org.keycloak.authentication.authenticators.browser.WebAuthnAuthenticator
- All Implemented Interfaces:
Authenticator,CredentialValidator<WebAuthnCredentialProvider>,Provider
- Direct Known Subclasses:
WebAuthnPasswordlessAuthenticator
public class WebAuthnAuthenticator
extends Object
implements Authenticator, CredentialValidator<WebAuthnCredentialProvider>
Authenticator for WebAuthn authentication, which will be typically used when WebAuthn is used as second factor.
-
Field Summary
Fields -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidaction(AuthenticationFlowContext context) Called from a form action invocation.voidauthenticate(AuthenticationFlowContext context) Initial call for the authenticator.voidclose()booleanconfiguredFor(KeycloakSession session, RealmModel realm, UserModel user) Is this authenticator configured for this user.protected jakarta.ws.rs.core.ResponsecreateErrorResponse(AuthenticationFlowContext context, String errorCase) fillContextForm(AuthenticationFlowContext context) getCredentialProvider(KeycloakSession session) protected StringgetRequiredActions(KeycloakSession session) Overwrite this if the authenticator is associated withprotected StringgetRpID(AuthenticationFlowContext context) protected WebAuthnPolicybooleanDoes this authenticator require that the user has already been identified? That AuthenticatorContext.getUser() is not null?protected voidsetErrorResponse(AuthenticationFlowContext context, String errorCase, String errorMessage) voidsetRequiredActions(KeycloakSession session, RealmModel realm, UserModel user) Set actions to configure authenticatorprotected booleanMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.keycloak.authentication.Authenticator
areRequiredActionsEnabledMethods inherited from interface org.keycloak.authentication.CredentialValidator
getCredentials, getType
-
Field Details
-
session
-
-
Constructor Details
-
WebAuthnAuthenticator
-
-
Method Details
-
authenticate
Description copied from interface:AuthenticatorInitial call for the authenticator. This method should check the current HTTP request to determine if the request satisfies the Authenticator's requirements. If it doesn't, it should send back a challenge response by calling the AuthenticationFlowContext.challenge(Response). If this challenge is a authentication, the action URL of the form must point to /realms/{realm}/login-actions/authenticate?code={session-code}&execution={executionId} or /realms/{realm}/login-actions/registration?code={session-code}&execution={executionId} {session-code} pertains to the code generated from AuthenticationFlowContext.generateAccessCode(). The {executionId} pertains to the AuthenticationExecutionModel.getId() value obtained from AuthenticationFlowContext.getExecution(). The action URL will invoke the action() method described below.- Specified by:
authenticatein interfaceAuthenticator
-
fillContextForm
-
getWebAuthnPolicy
-
getRpID
-
getCredentialType
-
shouldDisplayAuthenticators
-
action
Description copied from interface:AuthenticatorCalled from a form action invocation.- Specified by:
actionin interfaceAuthenticator
-
requiresUser
public boolean requiresUser()Description copied from interface:AuthenticatorDoes this authenticator require that the user has already been identified? That AuthenticatorContext.getUser() is not null?- Specified by:
requiresUserin interfaceAuthenticator- Returns:
-
configuredFor
Description copied from interface:AuthenticatorIs this authenticator configured for this user.- Specified by:
configuredForin interfaceAuthenticator- Returns:
-
setRequiredActions
Description copied from interface:AuthenticatorSet actions to configure authenticator- Specified by:
setRequiredActionsin interfaceAuthenticator
-
getRequiredActions
Description copied from interface:AuthenticatorOverwrite this if the authenticator is associated with- Specified by:
getRequiredActionsin interfaceAuthenticator- Returns:
-
close
public void close() -
getCredentialProvider
- Specified by:
getCredentialProviderin interfaceCredentialValidator<WebAuthnCredentialProvider>
-
setErrorResponse
protected void setErrorResponse(AuthenticationFlowContext context, String errorCase, String errorMessage) -
createErrorResponse
protected jakarta.ws.rs.core.Response createErrorResponse(AuthenticationFlowContext context, String errorCase)
-