Revision: 1931
Author: olavmrk
Date: Thu Oct 29 00:06:17 2009
Log: SimpleSAML_Metadata_SAMLParser: Fix bug in signature validation.

The signature validation removes the signature element from the DOM
tree, which causes the metadata parsing to skip the DOM node following
the signature element. Normally this element would be a text node, but
it could also be a SSODescriptor-element.
http://code.google.com/p/simplesamlphp/source/detail?r=1931

Modified:
  /trunk/lib/SimpleSAML/Metadata/SAMLParser.php

=======================================
--- /trunk/lib/SimpleSAML/Metadata/SAMLParser.php       Fri Oct 16 05:45:30 2009
+++ /trunk/lib/SimpleSAML/Metadata/SAMLParser.php       Thu Oct 29 00:06:17 2009
@@ -1406,6 +1406,14 @@
                $entityDescriptor = $element->parentNode;
                assert('$entityDescriptor instanceof DOMElement');

+               /*
+                * Make a copy of the entity descriptor, so that the validator 
can
+                * change the DOM tree in any way it wants.
+                */
+               $doc = new DOMDocument();
+               $entityDescriptor = $doc->importNode($entityDescriptor, TRUE);
+               $doc->appendChild($entityDescriptor);
+
                /* Attempt to check the signature. */
                try {
                        $validator = new 
SimpleSAML_XML_Validator($entityDescriptor, 'ID');

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"simpleSAMLphp commits" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/simplesamlphp-commits?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to