/*
* Copyright 2001-2007 Internet2
- *
+ *
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
#include "internal.h"
#include "exceptions.h"
+#include "version.h"
#include "AccessControl.h"
#include "Application.h"
#include "RequestMapper.h"
#include "ServiceProvider.h"
#include "SessionCache.h"
#include "SPConfig.h"
+#include "SPRequest.h"
#include "handler/SessionInitiator.h"
#include "remoting/ListenerService.h"
#include "util/DOMPropertySet.h"
#endif
#include <xercesc/util/XMLUniDefs.hpp>
#include <xmltooling/XMLToolingConfig.h>
+#include <xmltooling/version.h>
#include <xmltooling/util/NDC.h>
#include <xmltooling/util/ReloadableXMLFile.h>
#include <xmltooling/util/XMLHelper.h>
# include "attribute/resolver/AttributeResolver.h"
# include "security/PKIXTrustEngine.h"
# include <saml/SAMLConfig.h>
+# include <saml/version.h>
# include <saml/binding/ArtifactMap.h>
# include <saml/binding/SAMLArtifact.h>
# include <saml/saml1/core/Assertions.h>
using namespace xmltooling;
using namespace std;
+#ifndef min
+# define min(a,b) (((a) < (b)) ? (a) : (b))
+#endif
+
namespace {
#if defined (_MSC_VER)
public:
XMLApplication(const ServiceProvider*, const DOMElement* e, const XMLApplication* base=NULL);
~XMLApplication() { cleanup(); }
-
+
const char* getHash() const {return m_hash.c_str();}
#ifndef SHIBSP_LITE
return (m_remoteUsers.empty() && m_base) ? m_base->getRemoteUserAttributeIds() : m_remoteUsers;
}
+ void clearHeader(SPRequest& request, const char* rawname, const char* cginame) const;
+ void setHeader(SPRequest& request, const char* name, const char* value) const;
+ string getSecureHeader(const SPRequest& request, const char* name) const;
+
const SessionInitiator* getDefaultSessionInitiator() const;
const SessionInitiator* getSessionInitiatorById(const char* id) const;
const Handler* getDefaultAssertionConsumerService() const;
}
// Provides filter to exclude special config elements.
- short acceptNode(const DOMNode* node) const;
-
+#ifdef SHIBSP_XERCESC_SHORT_ACCEPTNODE
+ short
+#else
+ FilterAction
+#endif
+ acceptNode(const DOMNode* node) const;
+
private:
void cleanup();
const XMLApplication* m_base;
string m_hash;
+ std::pair<std::string,std::string> m_attributePrefix;
#ifndef SHIBSP_LITE
MetadataProvider* m_metadata;
TrustEngine* m_trust;
// maps unique indexes to consumer services
map<unsigned int,const Handler*> m_acsIndexMap;
-
+
// pointer to default consumer service
const Handler* m_acsDefault;
public:
XMLConfigImpl(const DOMElement* e, bool first, const XMLConfig* outer, Category& log);
~XMLConfigImpl();
-
+
RequestMapper* m_requestMapper;
map<string,Application*> m_appmap;
#ifndef SHIBSP_LITE
map< string,pair< PropertySet*,vector<const SecurityPolicyRule*> > > m_policyMap;
vector< pair< string, pair<string,string> > > m_transportOptions;
#endif
-
+
// Provides filter to exclude special config elements.
- short acceptNode(const DOMNode* node) const;
+#ifdef SHIBSP_XERCESC_SHORT_ACCEPTNODE
+ short
+#else
+ FilterAction
+#endif
+ acceptNode(const DOMNode* node) const;
void setDocument(DOMDocument* doc) {
m_document = doc;
#endif
{
}
-
+
void init() {
load();
}
class SHIBSP_DLLLOCAL PolicyNodeFilter : public DOMNodeFilter
{
public:
- short acceptNode(const DOMNode* node) const {
+#ifdef SHIBSP_XERCESC_SHORT_ACCEPTNODE
+ short
+#else
+ FilterAction
+#endif
+ acceptNode(const DOMNode* node) const {
return FILTER_REJECT;
}
};
m_hash += (DIGITS[0x0F & *ch]);
}
+ // Populate prefix pair.
+ m_attributePrefix.second = "HTTP_";
+ pair<bool,const char*> prefix = getString("attributePrefix");
+ if (prefix.first) {
+ m_attributePrefix.first = prefix.second;
+ const char* pch = prefix.second;
+ while (*pch) {
+ m_attributePrefix.second += (isalnum(*pch) ? toupper(*pch) : '_');
+ pch++;
+ }
+ }
+
// Load attribute ID lists for REMOTE_USER and header clearing.
if (conf.isEnabled(SPConfig::InProcess)) {
pair<bool,const char*> attributes = getString("REMOTE_USER");
attributes = getString("unsetHeaders");
if (attributes.first) {
- string transformedprefix("HTTP_");
+ string transformedprefix(m_attributePrefix.second);
const char* pch;
- pair<bool,const char*> prefix = getString("metadataAttributePrefix");
+ prefix = getString("metadataAttributePrefix");
if (prefix.first) {
pch = prefix.second;
while (*pch) {
transformed += (isalnum(*pch) ? toupper(*pch) : '_');
pch++;
}
- m_unsetHeaders.push_back(pair<string,string>(start,string("HTTP_") + transformed));
+
+ m_unsetHeaders.push_back(pair<string,string>(m_attributePrefix.first + start, m_attributePrefix.second + transformed));
if (prefix.first)
- m_unsetHeaders.push_back(pair<string,string>(string(prefix.second) + start, transformedprefix + transformed));
+ m_unsetHeaders.push_back(pair<string,string>(m_attributePrefix.first + prefix.second + start, transformedprefix + transformed));
start = pos ? pos+1 : NULL;
}
free(dup);
- m_unsetHeaders.push_back(pair<string,string>("Shib-Application-ID","HTTP_SHIB_APPLICATION_ID"));
+ m_unsetHeaders.push_back(pair<string,string>(m_attributePrefix.first + "Shib-Application-ID", m_attributePrefix.second + "SHIB_APPLICATION_ID"));
}
}
m_acsBindingMap[handler->getString("Binding").second].push_back(handler);
#endif
m_acsIndexMap[handler->getUnsignedInt("index").second]=handler;
-
+
if (!hardACS) {
pair<bool,bool> defprop=handler->getBool("isDefault");
if (defprop.first) {
continue;
}
handler=conf.ArtifactResolutionServiceManager.newPlugin(bindprop.get(),make_pair(child, getId()));
-
+
if (!hardArt) {
pair<bool,bool> defprop=handler->getBool("isDefault");
if (defprop.first) {
catch (exception& ex) {
log.error("caught exception processing handler element: %s", ex.what());
}
-
+
child = XMLHelper::getNextSiblingElement(child);
}
Locker extlock(m_attrExtractor);
m_attrExtractor->getAttributeIds(unsetHeaders);
}
+ else if (m_base && m_base->m_attrExtractor) {
+ Locker extlock(m_base->m_attrExtractor);
+ m_base->m_attrExtractor->getAttributeIds(unsetHeaders);
+ }
if (m_attrResolver) {
Locker reslock(m_attrResolver);
m_attrResolver->getAttributeIds(unsetHeaders);
}
- if (unsetHeaders.empty()) {
- if (m_base)
- m_unsetHeaders.insert(m_unsetHeaders.end(), m_base->m_unsetHeaders.begin(), m_base->m_unsetHeaders.end());
- else
- m_unsetHeaders.push_back(pair<string,string>("Shib-Application-ID","HTTP_SHIB_APPLICATION_ID"));
+ else if (m_base && m_base->m_attrResolver) {
+ Locker extlock(m_base->m_attrResolver);
+ m_base->m_attrResolver->getAttributeIds(unsetHeaders);
}
- else {
- string transformedprefix("HTTP_");
+ if (!unsetHeaders.empty()) {
+ string transformedprefix(m_attributePrefix.second);
const char* pch;
pair<bool,const char*> prefix = getString("metadataAttributePrefix");
if (prefix.first) {
transformed += (isalnum(*pch) ? toupper(*pch) : '_');
pch++;
}
- m_unsetHeaders.push_back(pair<string,string>(*hdr, string("HTTP_") + transformed));
+ m_unsetHeaders.push_back(pair<string,string>(m_attributePrefix.first + *hdr, m_attributePrefix.second + transformed));
if (prefix.first)
- m_unsetHeaders.push_back(pair<string,string>(string(prefix.second) + *hdr, transformedprefix + transformed));
+ m_unsetHeaders.push_back(pair<string,string>(m_attributePrefix.first + prefix.second + *hdr, transformedprefix + transformed));
}
- m_unsetHeaders.push_back(pair<string,string>("Shib-Application-ID","HTTP_SHIB_APPLICATION_ID"));
}
+ m_unsetHeaders.push_back(pair<string,string>(m_attributePrefix.first + "Shib-Application-ID", m_attributePrefix.second + "SHIB_APPLICATION_ID"));
}
}
#endif
}
-short XMLApplication::acceptNode(const DOMNode* node) const
+#ifdef SHIBSP_XERCESC_SHORT_ACCEPTNODE
+short
+#else
+DOMNodeFilter::FilterAction
+#endif
+XMLApplication::acceptNode(const DOMNode* node) const
{
const XMLCh* name=node->getLocalName();
if (XMLString::equals(name,ApplicationOverride) ||
{
if (!provider)
return this;
-
+
#ifdef HAVE_GOOD_STL
map<xstring,PropertySet*>::const_iterator i=m_partyMap.find(provider->getEntityID());
if (i!=m_partyMap.end())
{
if (!entityID)
return this;
-
+
#ifdef HAVE_GOOD_STL
map<xstring,PropertySet*>::const_iterator i=m_partyMap.find(entityID);
if (i!=m_partyMap.end())
throw ConfigurationException("Request URL was not absolute.");
const char* handler=locs[index].c_str();
-
+
// Should never happen...
if (!handler || (*handler!='/' && strncmp(handler,"http:",5) && strncmp(handler,"https:",6)))
throw ConfigurationException(
return notifyURL;
}
+void XMLApplication::clearHeader(SPRequest& request, const char* rawname, const char* cginame) const
+{
+ if (!m_attributePrefix.first.empty()) {
+ string temp = m_attributePrefix.first + rawname;
+ string temp2 = m_attributePrefix.second + (cginame + 5);
+ request.clearHeader(temp.c_str(), temp2.c_str());
+ }
+ else if (m_base) {
+ m_base->clearHeader(request, rawname, cginame);
+ }
+ else {
+ request.clearHeader(rawname, cginame);
+ }
+}
+
+void XMLApplication::setHeader(SPRequest& request, const char* name, const char* value) const
+{
+ if (!m_attributePrefix.first.empty()) {
+ string temp = m_attributePrefix.first + name;
+ request.setHeader(temp.c_str(), value);
+ }
+ else if (m_base) {
+ m_base->setHeader(request, name, value);
+ }
+ else {
+ request.setHeader(name, value);
+ }
+}
+
+string XMLApplication::getSecureHeader(const SPRequest& request, const char* name) const
+{
+ if (!m_attributePrefix.first.empty()) {
+ string temp = m_attributePrefix.first + name;
+ return request.getSecureHeader(temp.c_str());
+ }
+ else if (m_base) {
+ return m_base->getSecureHeader(request,name);
+ }
+ else {
+ return request.getSecureHeader(name);
+ }
+}
+
const SessionInitiator* XMLApplication::getDefaultSessionInitiator() const
{
if (m_sessionInitDefault) return m_sessionInitDefault;
}
}
-short XMLConfigImpl::acceptNode(const DOMNode* node) const
+#ifdef SHIBSP_XERCESC_SHORT_ACCEPTNODE
+short
+#else
+DOMNodeFilter::FilterAction
+#endif
+XMLConfigImpl::acceptNode(const DOMNode* node) const
{
if (!XMLString::equals(node->getNamespaceURI(),shibspconstants::SHIB2SPCONFIG_NS))
return FILTER_ACCEPT;
auto_ptr_char path(exts->getAttributeNS(NULL,_path));
try {
if (path.get()) {
- XMLToolingConfig::getConfig().load_library(path.get(),(void*)exts);
+ if (!XMLToolingConfig::getConfig().load_library(path.get(),(void*)exts))
+ throw ConfigurationException("XMLToolingConfig::load_library failed.");
log.debug("loaded %s extension library (%s)", label, path.get());
}
}
log.debug("loading new logging configuration from (%s), check log destination for status of configuration",logpath.get());
XMLToolingConfig::getConfig().log_config(logpath.get());
}
-
+
#ifndef SHIBSP_LITE
if (first)
m_outer->m_tranLog = new TransactionLog();
#endif
}
-
+
+ // Re-log library versions now that logging is set up.
+#ifndef SHIBSP_LITE
+ log.info(
+ "Library versions: Xerces-C %s, XML-Security-C %s, XMLTooling-C %s, OpenSAML-C %s, Shibboleth %s",
+ XERCES_FULLVERSIONDOT, XSEC_FULLVERSIONDOT, XMLTOOLING_FULLVERSIONDOT, OPENSAML_FULLVERSIONDOT, SHIBSP_FULLVERSIONDOT
+ );
+#else
+ log.info(
+ "Library versions: Xerces-C %s, XMLTooling-C %s, Shibboleth %s",
+ XERCES_FULLVERSIONDOT, XMLTOOLING_FULLVERSIONDOT, SHIBSP_FULLVERSIONDOT
+ );
+#endif
+
// First load any property sets.
load(e,NULL,this);
// Set clock skew.
pair<bool,unsigned int> skew=getUnsignedInt("clockSkew");
if (skew.first)
- xmlConf.clock_skew_secs=skew.second;
+ xmlConf.clock_skew_secs=min(skew.second,(60*60*24*7*28));
// Extensions
doExtensions(e, "global", log);
if (conf.isEnabled(SPConfig::InProcess))
doExtensions(SHIRE, "in process", log);
-
+
// Instantiate the ListenerService and SessionCache objects.
if (conf.isEnabled(SPConfig::Listener)) {
child=XMLHelper::getFirstChildElement(e,UnixListener);
else {
log.warn("no ReplayCache built, missing conf:ReplayCache element?");
}
-
+
// ArtifactMap
child=XMLHelper::getFirstChildElement(e,_ArtifactMap);
if (child) {
}
}
} // end of first-time-only stuff
-
+
// Back to the fully dynamic stuff...next up is the RequestMapper.
if (conf.isEnabled(SPConfig::RequestMapping)) {
child=XMLHelper::getFirstChildElement(e,_RequestMapper);
throw ConfigurationException("Can't build RequestMapper, missing conf:RequestMapper element?");
}
}
-
+
#ifndef SHIBSP_LITE
// Load security policies.
child = XMLHelper::getLastChildElement(e,SecurityPolicies);
auto_ptr<DOMPropertySet> settings(new DOMPropertySet());
settings->load(child, NULL, &filter);
rules.first = settings.release();
-
+
// Process Rule elements.
const DOMElement* rule = XMLHelper::getFirstChildElement(child,Rule);
while (rule) {
}
rule = XMLHelper::getNextSiblingElement(rule,Rule);
}
-
+
child = XMLHelper::getNextSiblingElement(child,Policy);
}
}
}
XMLApplication* defapp=new XMLApplication(m_outer,child);
m_appmap[defapp->getId()]=defapp;
-
+
// Load any overrides.
child = XMLHelper::getFirstChildElement(child,ApplicationOverride);
while (child) {
{
// Load from source using base class.
pair<bool,DOMElement*> raw = ReloadableXMLFile::load();
-
+
// If we own it, wrap it.
XercesJanitor<DOMDocument> docjanitor(raw.first ? raw.second->getOwnerDocument() : NULL);
XMLConfigImpl* impl = new XMLConfigImpl(raw.second,(m_impl==NULL),this,m_log);
-
+
// If we held the document, transfer it to the impl. If we didn't, it's a no-op.
impl->setDocument(docjanitor.release());