Skip to content

Introduce the device policy conditional authentication function - #232

Open
kaviska wants to merge 3 commits into
wso2-extensions:masterfrom
kaviska:device-policy-js-function
Open

kaviska wants to merge 3 commits into
wso2-extensions:masterfrom
kaviska:device-policy-js-function

Conversation

@kaviska

@kaviska kaviska commented Jul 30, 2026

Copy link
Copy Markdown

Proposed changes in this pull request

This PR introduces a new component, org.wso2.carbon.identity.conditional.auth.functions.devicepolicy, which exposes device policy compliance to adaptive authentication scripts as the JS function isDevicePolicyCompliant. A login script can call it to ask whether the device the user is authenticating from satisfies a named device compliance policy, and branch on the answer — step up to a second factor, redirect the user to a remediation page, or fail the login outright.

This is the adaptive authentication surface of the device management set. It holds no device logic of its own: it reads the already-verified device data that the framework captured at authentication initiation, and delegates the decision to DevicePolicyEvaluator published by org.wso2.carbon.identity.device.policy. The component exists so that a login script never has to touch a device token, a device registry, or a policy model directly.

The change adds the component under components, registers it in the root POM and in the server feature so it ships with the IS distribution, and adds a TestNG suite covering the function end to end through the sequence handler.

The function

isDevicePolicyCompliant(context, policyName) is registered against JsFunctionRegistry.Subsystem.SEQUENCE_HANDLER at bundle activation, and is available to any adaptive authentication script from that point on.

The component

  • DevicePolicyComplianceFunction — the functional interface the script sees, with the null means compliant contract documented on it.
  • DevicePolicyComplianceFunctionImpl — the implementation, annotated @HostAccess.Export so the GraalVM engine can reach it.
  • DevicePolicyFunctionsServiceComponent — the OSGi declarative services component. It registers the function on activation and de-registers it on deactivation, and takes mandatory dynamic references to JsFunctionRegistry and DevicePolicyEvaluator. Activation failures are logged rather than propagated, so a problem here cannot take the bundle down with it.
  • DevicePolicyFunctionsServiceHolder — the singleton holding those two services.

The bundle exports only the public package and keeps internal private, matching the other function bundles in this repository.

When should this PR be merged

This PR should be merged after org.wso2.carbon.identity.device.policy is merged and released from carbon-identity-framework, along with the authentication framework change that adds FrameworkConstants.DEVICE_DATA and the device SPI package.

Until then the module resolves only against locally built SNAPSHOTs and will not build on CI. Once those are released, the version overrides described above come out and the module goes back to the shared version properties.

Follow up actions

N/A

@CLAassistant

CLAassistant commented Jul 30, 2026 •

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ Malith-19
❌ kaviska
You have signed the CLA already but the status is still pending? Let us recheck it.

Move the repo to the latest framework release, which carries
org.wso2.carbon.identity.device.policy, and drop the temporary
framework and kernel overrides from the device policy module.

The 7.11.x line ships org.wso2.orbit.graalvm.sdk:graal-sdk 25.0.2,
so replace the stale org.graalvm.sdk:graal-sdk 22.3.4 management
that shadowed the polyglot API, and stub the resolveUser overload
added in the same line.
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 36.71%. Comparing base (7d2673d) to head (5dc69f5).
⚠️ Report is 3 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff            @@
##             master     #232   +/-   ##
=========================================
  Coverage     36.71%   36.71%           
  Complexity      427      427           
=========================================
  Files           110      110           
  Lines          3925     3925           
  Branches        499      499           
=========================================
  Hits           1441     1441           
  Misses         2328     2328           
  Partials        156      156           
Flag Coverage Δ
unit 41.57% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@jenkins-is-staging

Copy link
Copy Markdown

PR builder started
Link: https://github.com/wso2/product-is/actions/runs/35975276412

@jenkins-is-staging

Copy link
Copy Markdown

PR builder completed
Link: https://github.com/wso2/product-is/actions/runs/35975276412
Status: failure

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants