Class SpiffeIdUtil

java.lang.Object
io.jans.as.model.util.SpiffeIdUtil

public class SpiffeIdUtil extends Object
Utility for parsing and matching SPIFFE IDs (spiffe://trust-domain/path), used by SPIFFE-based client authentication (draft-ietf-oauth-spiffe-client-auth).
Author:
Yuriy Zabrovarnyy
  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    static final String
     
    static final String
     
  • Method Summary

    Modifier and Type
    Method
    Description
    static boolean
    Validates the syntax of a SPIFFE ID as presented in a credential (X.509-SVID URI SAN or JWT-SVID `sub` claim).
    static boolean
    Validates the syntax of a `spiffe_id` value as registered in client metadata, which may carry a trailing "/*" for path-segment prefix matching against presented SVIDs.
    static boolean
    isWildcard(String registeredSpiffeId)
    True if the registered `spiffe_id` metadata value is a wildcard pattern (ends with "/*"), meaning multiple concrete SVIDs under that prefix can authenticate as the same client.
    static boolean
    matches(String registeredSpiffeId, String presentedSpiffeId)
    Matches a presented (concrete) SPIFFE ID against a registered SPIFFE ID pattern.
    static String
    Returns the trust domain (authority component, lower-cased) of a SPIFFE ID, e.g.

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Field Details

  • Method Details

    • isValidPresentedSpiffeId

      public static boolean isValidPresentedSpiffeId(String value)
      Validates the syntax of a SPIFFE ID as presented in a credential (X.509-SVID URI SAN or JWT-SVID `sub` claim). Presented SPIFFE IDs must be concrete: they must not carry the "/*" wildcard suffix, which is only meaningful in a *registered* client's `spiffe_id` metadata.
    • isValidRegisteredSpiffeId

      public static boolean isValidRegisteredSpiffeId(String value)
      Validates the syntax of a `spiffe_id` value as registered in client metadata, which may carry a trailing "/*" for path-segment prefix matching against presented SVIDs.
    • trustDomainOf

      public static String trustDomainOf(String spiffeId)
      Returns the trust domain (authority component, lower-cased) of a SPIFFE ID, e.g. "example.org" for "spiffe://example.org/my-workload". Returns null if the value is not a syntactically valid SPIFFE ID (wildcard suffix, if present, is ignored for this purpose).
    • matches

      public static boolean matches(String registeredSpiffeId, String presentedSpiffeId)
      Matches a presented (concrete) SPIFFE ID against a registered SPIFFE ID pattern.

      A registered pattern with a trailing "/*" matches any presented ID that shares its trust domain and whose path starts with the pattern's path as a full path-segment prefix, e.g. "spiffe://example.org/client/*" matches "spiffe://example.org/client/123" but not "spiffe://example.org/client123". A registered pattern without a wildcard requires an exact match.

    • isWildcard

      public static boolean isWildcard(String registeredSpiffeId)
      True if the registered `spiffe_id` metadata value is a wildcard pattern (ends with "/*"), meaning multiple concrete SVIDs under that prefix can authenticate as the same client.