Package io.jans.as.model.util
Class SpiffeIdUtil
java.lang.Object
io.jans.as.model.util.SpiffeIdUtil
Utility for parsing and matching SPIFFE IDs (spiffe://trust-domain/path), used by SPIFFE-based
client authentication (draft-ietf-oauth-spiffe-client-auth).
- Author:
- Yuriy Zabrovarnyy
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionstatic booleanisValidPresentedSpiffeId(String value) Validates the syntax of a SPIFFE ID as presented in a credential (X.509-SVID URI SAN or JWT-SVID `sub` claim).static booleanisValidRegisteredSpiffeId(String value) Validates the syntax of a `spiffe_id` value as registered in client metadata, which may carry a trailing "/*" for path-segment prefix matching against presented SVIDs.static booleanisWildcard(String registeredSpiffeId) True if the registered `spiffe_id` metadata value is a wildcard pattern (ends with "/*"), meaning multiple concrete SVIDs under that prefix can authenticate as the same client.static booleanMatches a presented (concrete) SPIFFE ID against a registered SPIFFE ID pattern.static StringtrustDomainOf(String spiffeId) Returns the trust domain (authority component, lower-cased) of a SPIFFE ID, e.g.
-
Field Details
-
SCHEME
- See Also:
-
WILDCARD_SUFFIX
- See Also:
-
-
Method Details
-
isValidPresentedSpiffeId
Validates the syntax of a SPIFFE ID as presented in a credential (X.509-SVID URI SAN or JWT-SVID `sub` claim). Presented SPIFFE IDs must be concrete: they must not carry the "/*" wildcard suffix, which is only meaningful in a *registered* client's `spiffe_id` metadata. -
isValidRegisteredSpiffeId
Validates the syntax of a `spiffe_id` value as registered in client metadata, which may carry a trailing "/*" for path-segment prefix matching against presented SVIDs. -
trustDomainOf
Returns the trust domain (authority component, lower-cased) of a SPIFFE ID, e.g. "example.org" for "spiffe://example.org/my-workload". Returns null if the value is not a syntactically valid SPIFFE ID (wildcard suffix, if present, is ignored for this purpose). -
matches
Matches a presented (concrete) SPIFFE ID against a registered SPIFFE ID pattern.A registered pattern with a trailing "/*" matches any presented ID that shares its trust domain and whose path starts with the pattern's path as a full path-segment prefix, e.g. "spiffe://example.org/client/*" matches "spiffe://example.org/client/123" but not "spiffe://example.org/client123". A registered pattern without a wildcard requires an exact match.
-
isWildcard
True if the registered `spiffe_id` metadata value is a wildcard pattern (ends with "/*"), meaning multiple concrete SVIDs under that prefix can authenticate as the same client.
-