Revision: 1950
Author: olavmrk
Date: Wed Nov  4 05:53:09 2009
Log: saml2: Support new endpoint format.
http://code.google.com/p/simplesamlphp/source/detail?r=1950

Modified:
  /trunk/modules/saml2/lib/Message.php
  /trunk/www/saml2/idp/SSOService.php
  /trunk/www/saml2/idp/SingleLogoutService.php
  /trunk/www/saml2/idp/SingleLogoutServiceiFrame.php
  /trunk/www/saml2/idp/idpInitSingleLogoutServiceiFrame.php
  /trunk/www/saml2/sp/initSLO.php

=======================================
--- /trunk/modules/saml2/lib/Message.php        Mon Oct  5 03:53:43 2009
+++ /trunk/modules/saml2/lib/Message.php        Wed Nov  4 05:53:09 2009
@@ -378,9 +378,12 @@
                                'AllowCreate' => TRUE,
                        ));
                }
+
+               $dst = $idpMetadata->getDefaultEndpoint('SingleSignOnService',  
array(SAML2_Const::BINDING_HTTP_REDIRECT));
+               $dst = $dst['Location'];

                $ar->setIssuer($spMetadata->getString('entityid'));
-               
$ar->setDestination($idpMetadata->getString('SingleSignOnService'));
+               $ar->setDestination($dst);

                $ar->setForceAuthn($spMetadata->getBoolean('ForceAuthn', 
FALSE));
                $ar->setIsPassive($spMetadata->getBoolean('IsPassive', FALSE));
@@ -399,10 +402,13 @@
         */
        public static function buildLogoutRequest(SimpleSAML_Configuration  
$srcMetadata, SimpleSAML_Configuration $dstMetadata) {

+               $dst = $dstMetadata->getDefaultEndpoint('SingleLogoutService',  
array(SAML2_Const::BINDING_HTTP_REDIRECT));
+               $dst = $dst['Location'];
+
                $lr = new SAML2_LogoutRequest();

                $lr->setIssuer($srcMetadata->getString('entityid'));
-               
$lr->setDestination($dstMetadata->getString('SingleLogoutService'));
+               $lr->setDestination($dst);

                self::addRedirectSign($srcMetadata, $dstMetadata, $lr);

@@ -417,15 +423,17 @@
         * @param SimpleSAML_Configuration $dstpMetadata  The metadata of the  
recipient.
         */
        public static function buildLogoutResponse(SimpleSAML_Configuration  
$srcMetadata, SimpleSAML_Configuration $dstMetadata) {
+
+               $dst = $dstMetadata->getDefaultEndpoint('SingleLogoutService',  
array(SAML2_Const::BINDING_HTTP_REDIRECT));
+               if (isset($dst['ResponseLocation'])) {
+                       $dst = $dst['ResponseLocation'];
+               } else {
+                       $dst = $dst['Location'];
+               }

                $lr = new SAML2_LogoutResponse();

                $lr->setIssuer($srcMetadata->getString('entityid'));
-
-               $dst = $dstMetadata->getString('SingleLogoutServiceResponse', 
NULL);
-               if ($dst === NULL) {
-                       $dst = $dstMetadata->getString('SingleLogoutService');
-               }
                $lr->setDestination($dst);

                self::addRedirectSign($srcMetadata, $dstMetadata, $lr);
=======================================
--- /trunk/www/saml2/idp/SSOService.php Wed Nov  4 05:51:14 2009
+++ /trunk/www/saml2/idp/SSOService.php Wed Nov  4 05:53:09 2009
@@ -73,8 +73,8 @@
                if (array_key_exists('ConsumerURL', $requestcache)) {
                        $consumerURL = $requestcache['ConsumerURL'];
                } else {
-                       $urlArray = 
$spMetadata->getArrayizeString('AssertionConsumerService');
-                       $consumerURL = $urlArray[0];
+                       $consumerURL =  
$spMetadata->getDefaultEndpoint('AssertionConsumerService',  
array(SAML2_Const::BINDING_HTTP_POST));
+                       $consumerURL = $consumerURL['Location'];
                }

                $ar = sspmod_saml2_Message::buildResponse($idpMetadata, 
$spMetadata,  
$consumerURL);
@@ -149,13 +149,22 @@

                $consumerURL = $authnrequest->getAssertionConsumerServiceURL();
                if ($consumerURL !== NULL) {
-                       $consumerArray =  
$spMetadata->getArrayizeString('AssertionConsumerService');
-                       if (in_array($consumerURL, $consumerArray, TRUE)) {
+                       $found = FALSE;
+                       foreach 
($spMetadata->getEndpoints('AssertionConsumerService') as $ep) {
+                               if ($ep['Binding'] !== 
SAML2_Const::BINDING_HTTP_POST) {
+                                       continue;
+                               }
+                               if ($ep['Location'] !== $consumerURL) {
+                                       continue;
+                               }
                                $requestcache['ConsumerURL'] = $consumerURL;
-                       } else {
+                               break;
+                       }
+
+                       if (!$found) {
                                SimpleSAML_Logger::warning('Authentication 
request from ' .  
var_export($issuer, TRUE) .
                                        ' contains invalid 
AssertionConsumerService URL. Was ' .
-                                       var_export($consumerURL, TRUE) . ', 
could be ' .  
var_export($consumerArray, TRUE) . '.');
+                                       var_export($consumerURL, TRUE) . '.');
                        }
                }

@@ -441,8 +450,8 @@
                if (array_key_exists('ConsumerURL', $requestcache)) {
                        $consumerURL = $requestcache['ConsumerURL'];
                } else {
-                       $urlArray = 
$spMetadata->getArrayizeString('AssertionConsumerService');
-                       $consumerURL = $urlArray[0];
+                       $consumerURL =  
$spMetadata->getDefaultEndpoint('AssertionConsumerService',  
array(SAML2_Const::BINDING_HTTP_POST));
+                       $consumerURL = $consumerURL['Location'];
                }

                $assertion = sspmod_saml2_Message::buildAssertion($idpMetadata, 
 
$spMetadata, $attributes, $consumerURL);
=======================================
--- /trunk/www/saml2/idp/SingleLogoutService.php        Fri Aug 14 04:07:44 2009
+++ /trunk/www/saml2/idp/SingleLogoutService.php        Wed Nov  4 05:53:09 2009
@@ -211,9 +211,9 @@
                continue;
        }

-       $singleLogoutService = $spMetadata->getString('SingleLogoutService',  
NULL);
+       $singleLogoutService =  
$spMetadata->getDefaultEndpoint('SingleLogoutService',  
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
        if ($singleLogoutService === NULL) {
-               SimpleSAML_Logger::info('SAML2.0 - IDP.SingleLogoutService: No  
SingleLogoutService for ' .
+               SimpleSAML_Logger::info('SAML2.0 - IDP.SingleLogoutService: No 
supported  
SingleLogoutService for ' .
                        $spEntityId . '; looking for more SPs.');
                continue;
        }
=======================================
--- /trunk/www/saml2/idp/SingleLogoutServiceiFrame.php  Mon Sep 28 05:16:10  
2009
+++ /trunk/www/saml2/idp/SingleLogoutServiceiFrame.php  Wed Nov  4 05:53:09  
2009
@@ -110,7 +110,7 @@
                }

                try {
-                       $spmetadata = $metadata->getMetaData($spentityid, 
'saml20-sp-remote');
+                       $spMetadata =  
$metadata->getMetaDataConfig($spentityid, 'saml20-sp-remote');
                } catch (Exception $e) {
                        /*
                         * For some reason, the metadata for this SP is no 
longer available.  
Most
@@ -121,7 +121,8 @@
                        continue;
                }

-               if (!isset($spmetadata['SingleLogoutService'])) {
+               $singleLogoutService =  
$spMetadata->getDefaultEndpoint('SingleLogoutService',  
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
+               if ($singleLogoutService === NULL) {
                        /* No logout endpoint. */
                        $listofsps[] = $spentityid;
                        continue;
=======================================
--- /trunk/www/saml2/idp/idpInitSingleLogoutServiceiFrame.php   Mon Sep 28  
05:16:10 2009
+++ /trunk/www/saml2/idp/idpInitSingleLogoutServiceiFrame.php   Wed Nov  4  
05:53:09 2009
@@ -103,7 +103,7 @@
                }

                try {
-                       $spmetadata = $metadata->getMetaData($spentityid, 
'saml20-sp-remote');
+                       $spMetadata =  
$metadata->getMetaDataConfig($spentityid, 'saml20-sp-remote');
                } catch (Exception $e) {
                        /*
                         * For some reason, the metadata for this SP is no 
longer available.  
Most
@@ -114,7 +114,8 @@
                        continue;
                }

-               if (!isset($spmetadata['SingleLogoutService'])) {
+               $singleLogoutService =  
$spMetadata->getDefaultEndpoint('SingleLogoutService',  
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
+               if ($singleLogoutService === NULL) {
                        /* No logout endpoint. */
                        $listofsps[] = $spentityid;
                        continue;
=======================================
--- /trunk/www/saml2/sp/initSLO.php     Fri Aug 14 04:07:44 2009
+++ /trunk/www/saml2/sp/initSLO.php     Wed Nov  4 05:53:09 2009
@@ -28,8 +28,9 @@
                SimpleSAML_Utilities::redirect($returnTo);
        }
        $idpMetadata =  
$metadata->getMetaDataConfig($idpEntityId, 'saml20-idp-remote');
-       if (!$idpMetadata->hasValue('SingleLogoutService')) {
-               SimpleSAML_Logger::info('SAML2.0 - SP.initSLO: No 
SingleLogoutService  
endpoint in IdP.');
+       $SLOendpoint = $idpMetadata->getDefaultEndpoint('SingleLogoutService',  
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
+       if ($SLOendpoint === NULL) {
+               SimpleSAML_Logger::info('SAML2.0 - SP.initSLO: No supported  
SingleLogoutService endpoint in IdP.');
                SimpleSAML_Utilities::redirect($returnTo);
        }


--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"simpleSAMLphp commits" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/simplesamlphp-commits?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to