Revision: 1950
Author: olavmrk
Date: Wed Nov 4 05:53:09 2009
Log: saml2: Support new endpoint format.
http://code.google.com/p/simplesamlphp/source/detail?r=1950
Modified:
/trunk/modules/saml2/lib/Message.php
/trunk/www/saml2/idp/SSOService.php
/trunk/www/saml2/idp/SingleLogoutService.php
/trunk/www/saml2/idp/SingleLogoutServiceiFrame.php
/trunk/www/saml2/idp/idpInitSingleLogoutServiceiFrame.php
/trunk/www/saml2/sp/initSLO.php
=======================================
--- /trunk/modules/saml2/lib/Message.php Mon Oct 5 03:53:43 2009
+++ /trunk/modules/saml2/lib/Message.php Wed Nov 4 05:53:09 2009
@@ -378,9 +378,12 @@
'AllowCreate' => TRUE,
));
}
+
+ $dst = $idpMetadata->getDefaultEndpoint('SingleSignOnService',
array(SAML2_Const::BINDING_HTTP_REDIRECT));
+ $dst = $dst['Location'];
$ar->setIssuer($spMetadata->getString('entityid'));
-
$ar->setDestination($idpMetadata->getString('SingleSignOnService'));
+ $ar->setDestination($dst);
$ar->setForceAuthn($spMetadata->getBoolean('ForceAuthn',
FALSE));
$ar->setIsPassive($spMetadata->getBoolean('IsPassive', FALSE));
@@ -399,10 +402,13 @@
*/
public static function buildLogoutRequest(SimpleSAML_Configuration
$srcMetadata, SimpleSAML_Configuration $dstMetadata) {
+ $dst = $dstMetadata->getDefaultEndpoint('SingleLogoutService',
array(SAML2_Const::BINDING_HTTP_REDIRECT));
+ $dst = $dst['Location'];
+
$lr = new SAML2_LogoutRequest();
$lr->setIssuer($srcMetadata->getString('entityid'));
-
$lr->setDestination($dstMetadata->getString('SingleLogoutService'));
+ $lr->setDestination($dst);
self::addRedirectSign($srcMetadata, $dstMetadata, $lr);
@@ -417,15 +423,17 @@
* @param SimpleSAML_Configuration $dstpMetadata The metadata of the
recipient.
*/
public static function buildLogoutResponse(SimpleSAML_Configuration
$srcMetadata, SimpleSAML_Configuration $dstMetadata) {
+
+ $dst = $dstMetadata->getDefaultEndpoint('SingleLogoutService',
array(SAML2_Const::BINDING_HTTP_REDIRECT));
+ if (isset($dst['ResponseLocation'])) {
+ $dst = $dst['ResponseLocation'];
+ } else {
+ $dst = $dst['Location'];
+ }
$lr = new SAML2_LogoutResponse();
$lr->setIssuer($srcMetadata->getString('entityid'));
-
- $dst = $dstMetadata->getString('SingleLogoutServiceResponse',
NULL);
- if ($dst === NULL) {
- $dst = $dstMetadata->getString('SingleLogoutService');
- }
$lr->setDestination($dst);
self::addRedirectSign($srcMetadata, $dstMetadata, $lr);
=======================================
--- /trunk/www/saml2/idp/SSOService.php Wed Nov 4 05:51:14 2009
+++ /trunk/www/saml2/idp/SSOService.php Wed Nov 4 05:53:09 2009
@@ -73,8 +73,8 @@
if (array_key_exists('ConsumerURL', $requestcache)) {
$consumerURL = $requestcache['ConsumerURL'];
} else {
- $urlArray =
$spMetadata->getArrayizeString('AssertionConsumerService');
- $consumerURL = $urlArray[0];
+ $consumerURL =
$spMetadata->getDefaultEndpoint('AssertionConsumerService',
array(SAML2_Const::BINDING_HTTP_POST));
+ $consumerURL = $consumerURL['Location'];
}
$ar = sspmod_saml2_Message::buildResponse($idpMetadata,
$spMetadata,
$consumerURL);
@@ -149,13 +149,22 @@
$consumerURL = $authnrequest->getAssertionConsumerServiceURL();
if ($consumerURL !== NULL) {
- $consumerArray =
$spMetadata->getArrayizeString('AssertionConsumerService');
- if (in_array($consumerURL, $consumerArray, TRUE)) {
+ $found = FALSE;
+ foreach
($spMetadata->getEndpoints('AssertionConsumerService') as $ep) {
+ if ($ep['Binding'] !==
SAML2_Const::BINDING_HTTP_POST) {
+ continue;
+ }
+ if ($ep['Location'] !== $consumerURL) {
+ continue;
+ }
$requestcache['ConsumerURL'] = $consumerURL;
- } else {
+ break;
+ }
+
+ if (!$found) {
SimpleSAML_Logger::warning('Authentication
request from ' .
var_export($issuer, TRUE) .
' contains invalid
AssertionConsumerService URL. Was ' .
- var_export($consumerURL, TRUE) . ',
could be ' .
var_export($consumerArray, TRUE) . '.');
+ var_export($consumerURL, TRUE) . '.');
}
}
@@ -441,8 +450,8 @@
if (array_key_exists('ConsumerURL', $requestcache)) {
$consumerURL = $requestcache['ConsumerURL'];
} else {
- $urlArray =
$spMetadata->getArrayizeString('AssertionConsumerService');
- $consumerURL = $urlArray[0];
+ $consumerURL =
$spMetadata->getDefaultEndpoint('AssertionConsumerService',
array(SAML2_Const::BINDING_HTTP_POST));
+ $consumerURL = $consumerURL['Location'];
}
$assertion = sspmod_saml2_Message::buildAssertion($idpMetadata,
$spMetadata, $attributes, $consumerURL);
=======================================
--- /trunk/www/saml2/idp/SingleLogoutService.php Fri Aug 14 04:07:44 2009
+++ /trunk/www/saml2/idp/SingleLogoutService.php Wed Nov 4 05:53:09 2009
@@ -211,9 +211,9 @@
continue;
}
- $singleLogoutService = $spMetadata->getString('SingleLogoutService',
NULL);
+ $singleLogoutService =
$spMetadata->getDefaultEndpoint('SingleLogoutService',
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
if ($singleLogoutService === NULL) {
- SimpleSAML_Logger::info('SAML2.0 - IDP.SingleLogoutService: No
SingleLogoutService for ' .
+ SimpleSAML_Logger::info('SAML2.0 - IDP.SingleLogoutService: No
supported
SingleLogoutService for ' .
$spEntityId . '; looking for more SPs.');
continue;
}
=======================================
--- /trunk/www/saml2/idp/SingleLogoutServiceiFrame.php Mon Sep 28 05:16:10
2009
+++ /trunk/www/saml2/idp/SingleLogoutServiceiFrame.php Wed Nov 4 05:53:09
2009
@@ -110,7 +110,7 @@
}
try {
- $spmetadata = $metadata->getMetaData($spentityid,
'saml20-sp-remote');
+ $spMetadata =
$metadata->getMetaDataConfig($spentityid, 'saml20-sp-remote');
} catch (Exception $e) {
/*
* For some reason, the metadata for this SP is no
longer available.
Most
@@ -121,7 +121,8 @@
continue;
}
- if (!isset($spmetadata['SingleLogoutService'])) {
+ $singleLogoutService =
$spMetadata->getDefaultEndpoint('SingleLogoutService',
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
+ if ($singleLogoutService === NULL) {
/* No logout endpoint. */
$listofsps[] = $spentityid;
continue;
=======================================
--- /trunk/www/saml2/idp/idpInitSingleLogoutServiceiFrame.php Mon Sep 28
05:16:10 2009
+++ /trunk/www/saml2/idp/idpInitSingleLogoutServiceiFrame.php Wed Nov 4
05:53:09 2009
@@ -103,7 +103,7 @@
}
try {
- $spmetadata = $metadata->getMetaData($spentityid,
'saml20-sp-remote');
+ $spMetadata =
$metadata->getMetaDataConfig($spentityid, 'saml20-sp-remote');
} catch (Exception $e) {
/*
* For some reason, the metadata for this SP is no
longer available.
Most
@@ -114,7 +114,8 @@
continue;
}
- if (!isset($spmetadata['SingleLogoutService'])) {
+ $singleLogoutService =
$spMetadata->getDefaultEndpoint('SingleLogoutService',
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
+ if ($singleLogoutService === NULL) {
/* No logout endpoint. */
$listofsps[] = $spentityid;
continue;
=======================================
--- /trunk/www/saml2/sp/initSLO.php Fri Aug 14 04:07:44 2009
+++ /trunk/www/saml2/sp/initSLO.php Wed Nov 4 05:53:09 2009
@@ -28,8 +28,9 @@
SimpleSAML_Utilities::redirect($returnTo);
}
$idpMetadata =
$metadata->getMetaDataConfig($idpEntityId, 'saml20-idp-remote');
- if (!$idpMetadata->hasValue('SingleLogoutService')) {
- SimpleSAML_Logger::info('SAML2.0 - SP.initSLO: No
SingleLogoutService
endpoint in IdP.');
+ $SLOendpoint = $idpMetadata->getDefaultEndpoint('SingleLogoutService',
array(SAML2_Const::BINDING_HTTP_REDIRECT), NULL);
+ if ($SLOendpoint === NULL) {
+ SimpleSAML_Logger::info('SAML2.0 - SP.initSLO: No supported
SingleLogoutService endpoint in IdP.');
SimpleSAML_Utilities::redirect($returnTo);
}
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups
"simpleSAMLphp commits" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected]
For more options, visit this group at
http://groups.google.com/group/simplesamlphp-commits?hl=en
-~----------~----~----~----~------~----~------~--~---