Repository navigation
Conversation
|
|
Move the repo to the latest framework release, which carries org.wso2.carbon.identity.device.policy, and drop the temporary framework and kernel overrides from the device policy module. The 7.11.x line ships org.wso2.orbit.graalvm.sdk:graal-sdk 25.0.2, so replace the stale org.graalvm.sdk:graal-sdk 22.3.4 management that shadowed the polyglot API, and stub the resolveUser overload added in the same line.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #232 +/- ##
=========================================
Coverage 36.71% 36.71%
Complexity 427 427
=========================================
Files 110 110
Lines 3925 3925
Branches 499 499
=========================================
Hits 1441 1441
Misses 2328 2328
Partials 156 156
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
PR builder started |
|
PR builder completed |
Proposed changes in this pull request
This PR introduces a new component,
org.wso2.carbon.identity.conditional.auth.functions.devicepolicy, which exposes device policy compliance to adaptive authentication scripts as the JS functionisDevicePolicyCompliant. A login script can call it to ask whether the device the user is authenticating from satisfies a named device compliance policy, and branch on the answer — step up to a second factor, redirect the user to a remediation page, or fail the login outright.This is the adaptive authentication surface of the device management set. It holds no device logic of its own: it reads the already-verified device data that the framework captured at authentication initiation, and delegates the decision to
DevicePolicyEvaluatorpublished byorg.wso2.carbon.identity.device.policy. The component exists so that a login script never has to touch a device token, a device registry, or a policy model directly.The change adds the component under
components, registers it in the root POM and in the server feature so it ships with the IS distribution, and adds a TestNG suite covering the function end to end through the sequence handler.The function
isDevicePolicyCompliant(context, policyName)is registered againstJsFunctionRegistry.Subsystem.SEQUENCE_HANDLERat bundle activation, and is available to any adaptive authentication script from that point on.The component
DevicePolicyComplianceFunction— the functional interface the script sees, with thenullmeans compliant contract documented on it.DevicePolicyComplianceFunctionImpl— the implementation, annotated@HostAccess.Exportso the GraalVM engine can reach it.DevicePolicyFunctionsServiceComponent— the OSGi declarative services component. It registers the function on activation and de-registers it on deactivation, and takes mandatory dynamic references toJsFunctionRegistryandDevicePolicyEvaluator. Activation failures are logged rather than propagated, so a problem here cannot take the bundle down with it.DevicePolicyFunctionsServiceHolder— the singleton holding those two services.The bundle exports only the public package and keeps
internalprivate, matching the other function bundles in this repository.When should this PR be merged
This PR should be merged after
org.wso2.carbon.identity.device.policyis merged and released fromcarbon-identity-framework, along with the authentication framework change that addsFrameworkConstants.DEVICE_DATAand the device SPI package.Until then the module resolves only against locally built SNAPSHOTs and will not build on CI. Once those are released, the version overrides described above come out and the module goes back to the shared version properties.
Follow up actions
N/A