Interface AuthnMethod

All Superinterfaces:
org.pf4j.ExtensionPoint

public interface AuthnMethod extends org.pf4j.ExtensionPoint
This interface is an extension point that plugin developers can use to add/override authentication mechanisms exhibited in Casa
  • Method Summary

    Modifier and Type
    Method
    Description
    The qualified name of the Agama flow associated to this authentication method
    Returns a List of BasicCredential instances representing the credentials enrolled by the user (identified with the parameter supplied) for this specific authentication method.
    The URL where users will be taken for enrolling/listing of credentials associated to this authentication method.
    default String
    The resource bundle key (present in file zk-label.properties) used for displaying auxiliary text in the panel of this authentication method.
    The resource bundle key (present in file zk-label.properties) used for displaying the button label of this authentication method shown in the main user page of Gluu Casa.
    The resource bundle key (present in file zk-label.properties) used for displaying the summary text (body) of the panel corresponding to this authentication method in the main user page of Gluu Casa.
    The resource bundle key (present in file zk-label.properties) used for displaying the panel title (header) of this authentication method in the main user page of Gluu Casa.
    int
    The number of credentials enrolled by the user (identified with the parameter supplied) for this specific authentication method.
    The resource bundle key (present in file zk-label.properties) used for displaying the name of this authentication method in Gluu Casa UI.
    default boolean
    Determines whether this authentication method should be treated as one of the potential methods users should be presented for enrolling before trying to add any other credential in the system.
    void
    A method invoked by Casa when a change in the configuration of the associated Agama flow is detected.
  • Method Details

    • getAcr

      String getAcr()
      The qualified name of the Agama flow associated to this authentication method
      Returns:
      A String value
    • getUINameKey

      String getUINameKey()
      The resource bundle key (present in file zk-label.properties) used for displaying the name of this authentication method in Gluu Casa UI. As an example, this is the key that is looked up when rendering the list of authentication mechanisms for the user to pick their 2FA preference.
      Returns:
      A non-null String
    • getPanelTitleKey

      String getPanelTitleKey()
      The resource bundle key (present in file zk-label.properties) used for displaying the panel title (header) of this authentication method in the main user page of Gluu Casa.
      Returns:
      A non-null String
    • getPanelTextKey

      String getPanelTextKey()
      The resource bundle key (present in file zk-label.properties) used for displaying the summary text (body) of the panel corresponding to this authentication method in the main user page of Gluu Casa.
      Returns:
      A non-null String
    • getPanelButtonKey

      String getPanelButtonKey()
      The resource bundle key (present in file zk-label.properties) used for displaying the button label of this authentication method shown in the main user page of Gluu Casa. This button takes the user to the specific page where enrolling/listing of credentials is carried out. Normally, the label should look like "Add/Remove..."
      Returns:
      A non-null String
    • getPageUrl

      String getPageUrl()
      The URL where users will be taken for enrolling/listing of credentials associated to this authentication method. If the implementing class is part of a plugin, this will be interpreted relative to the base URL of the plugin (e.g /pl/PLUGIN-ID/).
      Returns:
      A string representing a relative URL. An empty String "" will work for pointing to index.zul or index.jsp
    • getPanelBottomTextKey

      default String getPanelBottomTextKey()
      The resource bundle key (present in file zk-label.properties) used for displaying auxiliary text in the panel of this authentication method. Override this method only when you want to display a text, otherwise no text will be added to panel.
      Returns:
      A non-null string
    • reloadConfiguration

      void reloadConfiguration()
      A method invoked by Casa when a change in the configuration of the associated Agama flow is detected. This allows developers to re-read configuration parameters part of the flow that may drive the behaviour of the enrollment/listing functionalities or configure any other internal aspect which may result relevant when configuration changes.
    • mayBe2faActivationRequisite

      default boolean mayBe2faActivationRequisite()
      Determines whether this authentication method should be treated as one of the potential methods users should be presented for enrolling before trying to add any other credential in the system. If the method you are implementing is highly accessible (does not entail any important hardware/software constraints), then it is a good candidate. In that case, override this interface method and return true (actually this a default Java interface method that returns false).

      Once a user has enrolled one credential belonging to any method of this kind, they can proceed with any other form of enrollment and activate second factor authentication. The aim is to avoid users locking as much as possible.

      Returns:
      A boolean value
    • getEnrolledCreds

      List<BasicCredential> getEnrolledCreds(String id)
      Returns a List of BasicCredential instances representing the credentials enrolled by the user (identified with the parameter supplied) for this specific authentication method. The list should account only for credentials in a valid state for being displayed in the main user page of Gluu Casa. Because of the nature of certain credential types or authentication methods, credentials may internally handle states (eg compromised, locked, expired, etc.) where they are not deemed as valid.
      Parameters:
      id - User ID (inum)
      Returns:
      Credentials that will be displayed in the summary page of user's credentials
    • getTotalUserCreds

      int getTotalUserCreds(String id)
      The number of credentials enrolled by the user (identified with the parameter supplied) for this specific authentication method. Only credentials in a valid state should be accounted. This method is not called when rendering the summary page of user's credentials but has other internal uses. Ideally it should be implemented without calling the size method of getEnrolledCreds(String) but in a more efficient manner that however, should yield the same integer value.
      Parameters:
      id - User ID (inum)
      Returns:
      An integer value (zero if no credentials)