#define __shibsp_app_h__
#include <shibsp/util/PropertySet.h>
-#include <saml/saml2/metadata/MetadataProvider.h>
-#include <xmltooling/security/TrustEngine.h>
-#include <xmltooling/validation/Validator.h>
+
+#include <set>
+#ifndef SHIBSP_LITE
+# include <saml/binding/MessageEncoder.h>
+# include <saml/saml2/metadata/MetadataProvider.h>
+# include <xmltooling/security/CredentialResolver.h>
+# include <xmltooling/security/TrustEngine.h>
+#endif
+#include <xmltooling/io/HTTPRequest.h>
+#include <xmltooling/util/Threads.h>
namespace shibsp {
+#ifndef SHIBSP_LITE
+ class SHIBSP_API AttributeExtractor;
+ class SHIBSP_API AttributeFilter;
+ class SHIBSP_API AttributeResolver;
+#endif
+ class SHIBSP_API Attribute;
class SHIBSP_API Handler;
class SHIBSP_API ServiceProvider;
+ class SHIBSP_API SessionInitiator;
+ class SHIBSP_API SPRequest;
+
+#if defined (_MSC_VER)
+ #pragma warning( push )
+ #pragma warning( disable : 4251 )
+#endif
/**
* Interface to a Shibboleth Application instance.
* of session management and policy.
*/
class SHIBSP_API Application : public virtual PropertySet
+#ifndef SHIBSP_LITE
+ ,public virtual opensaml::MessageEncoder::ArtifactGenerator
+#endif
{
MAKE_NONCOPYABLE(Application);
protected:
- Application() {}
+ /**
+ * Constructor.
+ *
+ * @param sp parent ServiceProvider instance
+ */
+ Application(const ServiceProvider* sp);
+
+ /** Pointer to parent SP instance. */
+ const ServiceProvider* m_sp;
+
+ /** Shared lock for manipulating application state. */
+ mutable xmltooling::RWLock* m_lock;
+
+ /** Pairs of raw and normalized CGI header names to clear. */
+ mutable std::vector< std::pair<std::string,std::string> > m_unsetHeaders;
+
public:
- virtual ~Application() {}
+ virtual ~Application();
/**
* Returns the owning ServiceProvider instance.
*
* @return a locked ServiceProvider
*/
- virtual const ServiceProvider& getServiceProvider() const=0;
+ const ServiceProvider& getServiceProvider() const {
+ return *m_sp;
+ }
/**
* Returns the Application's ID.
*
* @return the ID
*/
- virtual const char* getId() const=0;
+ virtual const char* getId() const {
+ return getString("id").second;
+ }
/**
* Returns a unique hash for the Application.
*
- * @return a value resulting from a hash of the Application's ID
+ * @return a value resulting from a computation over the Application's configuration
*/
virtual const char* getHash() const=0;
*/
virtual std::pair<std::string,const char*> getCookieNameProps(const char* prefix) const;
+#ifndef SHIBSP_LITE
/**
* Returns a MetadataProvider for use with this Application.
*
+ * @param required true iff an exception should be thrown if no MetadataProvider is available
* @return a MetadataProvider instance, or NULL
*/
- virtual opensaml::saml2md::MetadataProvider* getMetadataProvider() const=0;
+ virtual opensaml::saml2md::MetadataProvider* getMetadataProvider(bool required=true) const=0;
/**
* Returns a TrustEngine for use with this Application.
*
+ * @param required true iff an exception should be thrown if no TrustEngine is available
* @return a TrustEngine instance, or NULL
*/
- virtual xmltooling::TrustEngine* getTrustEngine() const=0;
-
+ virtual xmltooling::TrustEngine* getTrustEngine(bool required=true) const=0;
+
+ /**
+ * Returns an AttributeExtractor for use with this Application.
+ *
+ * @return an AttributeExtractor, or NULL
+ */
+ virtual AttributeExtractor* getAttributeExtractor() const=0;
+
/**
- * Returns configuration properties governing security interactions with a peer entity.
+ * Returns an AttributeFilter for use with this Application.
+ *
+ * @return an AttributeFilter, or NULL
+ */
+ virtual AttributeFilter* getAttributeFilter() const=0;
+
+ /**
+ * Returns an AttributeResolver for use with this Application.
+ *
+ * @return an AttributeResolver, or NULL
+ */
+ virtual AttributeResolver* getAttributeResolver() const=0;
+
+ /**
+ * Returns the CredentialResolver instance associated with this Application.
+ *
+ * @return a CredentialResolver, or NULL
+ */
+ virtual xmltooling::CredentialResolver* getCredentialResolver() const=0;
+
+ /**
+ * Returns configuration properties governing security interactions with a peer.
*
* @param provider a peer entity's metadata
* @return the applicable PropertySet
*/
- virtual const PropertySet* getCredentialUse(const opensaml::saml2md::EntityDescriptor* provider) const=0;
+ virtual const PropertySet* getRelyingParty(const opensaml::saml2md::EntityDescriptor* provider) const=0;
+
+ /**
+ * Returns the set of audience values associated with this Application.
+ *
+ * @return set of audience values associated with the Application
+ */
+ virtual const std::vector<const XMLCh*>& getAudiences() const=0;
+#endif
/**
- * Returns the default SessionInitiator Handler when automatically
- * requesting a session.
+ * Returns the designated notification URL, or an empty string if no more locations are specified.
+ *
+ * @param request requested URL to use to fill in missing pieces of notification URL
+ * @param front true iff front channel notification is desired, false iff back channel is desired
+ * @param index zero-based index of URL to return
+ * @return the designated URL, or an empty string
+ */
+ virtual std::string getNotificationURL(const char* request, bool front, unsigned int index) const=0;
+
+ /**
+ * Returns an array of attribute IDs to use as a REMOTE_USER value, in order of preference.
+ *
+ * @return an array of attribute IDs, possibly empty
+ */
+ virtual const std::vector<std::string>& getRemoteUserAttributeIds() const=0;
+
+ /**
+ * Clears any headers that may be used to hold attributes after export.
+ *
+ * @param request SP request to clear
+ */
+ virtual void clearAttributeHeaders(SPRequest& request) const;
+
+ /**
+ * Returns the default SessionInitiator when automatically requesting a session.
*
* @return the default SessionInitiator, or NULL
*/
- virtual const Handler* getDefaultSessionInitiator() const=0;
+ virtual const SessionInitiator* getDefaultSessionInitiator() const=0;
/**
- * Returns a SessionInitiator Handler with a particular ID when automatically
- * requesting a session.
+ * Returns a SessionInitiator with a particular ID when automatically requesting a session.
*
* @param id an identifier unique to the Application
* @return the designated SessionInitiator, or NULL
*/
- virtual const Handler* getSessionInitiatorById(const char* id) const=0;
-
+ virtual const SessionInitiator* getSessionInitiatorById(const char* id) const=0;
+
/**
* Returns the default AssertionConsumerService Handler
* for use in AuthnRequest messages.
virtual const Handler* getHandler(const char* path) const=0;
/**
- * Returns the set of audience values associated with this Application.
- *
- * @return set of audience values associated with the Application
- */
- virtual const std::vector<const XMLCh*>& getAudiences() const=0;
-
- /**
- * Returns a validator for applying verification rules to incoming SAML tokens.
+ * Returns all registered Handlers.
*
- * <p>The validator must be freed by the caller.
- *
- * @param ts timestamp against which to evaluate the token's validity, or 0 to ignore
- * @param role metadata role of token issuer, if known
- * @return a validator
+ * @param handlers array to populate
*/
- virtual xmltooling::Validator* getTokenValidator(time_t ts=0, const opensaml::saml2md::RoleDescriptor* role=NULL) const=0;
+ virtual void getHandlers(std::vector<const Handler*>& handlers) const=0;
};
+
+#if defined (_MSC_VER)
+ #pragma warning( pop )
+#endif
+
};
#endif /* __shibsp_app_h__ */