Include locally resolved attributes in composite name token
authorLuke Howard <lukeh@padl.com>
Sat, 26 Mar 2011 03:19:07 +0000 (14:19 +1100)
committerLuke Howard <lukeh@padl.com>
Sat, 26 Mar 2011 03:19:07 +0000 (14:19 +1100)
util_attr.cpp
util_saml.cpp
util_shib.cpp

index a24064a..10f1ad4 100644 (file)
@@ -265,6 +265,17 @@ gss_eap_attr_ctx::initFromGssContext(const gss_cred_id_t cred,
     return ret;
 }
 
+#define UPDATE_REMAIN(n)    do {                \
+        p += (n);                               \
+        remain -= (n);                          \
+    } while (0)
+
+#define CHECK_REMAIN(n)     do {                \
+        if (remain < (n)) {                     \
+            return false;                       \
+        }                                       \
+    } while (0)
+
 /*
  * Initialize a context from an exported context or name token
  */
@@ -272,33 +283,62 @@ bool
 gss_eap_attr_ctx::initFromBuffer(const gss_buffer_t buffer)
 {
     bool ret;
-    gss_eap_attr_provider *primaryProvider = getPrimaryProvider();
-    gss_buffer_desc primaryBuf;
+    size_t remain = buffer->length;
+    unsigned char *p = (unsigned char *)buffer->value;
+    bool didInit[ATTR_TYPE_MAX + 1];
 
-    if (buffer->length < 4)
-        return false;
+    memset(didInit, 0, sizeof(didInit));
 
-    m_flags = load_uint32_be(buffer->value);
+    /* flags */
+    CHECK_REMAIN(4);
+    m_flags = load_uint32_be(p);
+    UPDATE_REMAIN(4);
 
-    primaryBuf.length = buffer->length - 4;
-    primaryBuf.value = (char *)buffer->value + 4;
+    while (remain) {
+        OM_uint32 type;
+        gss_buffer_desc providerToken;
+        gss_eap_attr_provider *provider;
 
-    ret = primaryProvider->initFromBuffer(this, &primaryBuf);
-    if (ret == false)
-        return ret;
+        /* TLV encoding of provider type, length, value */
+        CHECK_REMAIN(4);
+        type = load_uint32_be(p);
+        UPDATE_REMAIN(4);
 
-    for (unsigned int i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
-        gss_eap_attr_provider *provider;
+        CHECK_REMAIN(4);
+        providerToken.length = load_uint32_be(p);
+        UPDATE_REMAIN(4);
 
-        if (!providerEnabled(i)) {
-            releaseProvider(i);
+        CHECK_REMAIN(providerToken.length);
+        providerToken.value = p;
+        UPDATE_REMAIN(providerToken.length);
+
+        if (type < ATTR_TYPE_MIN || type > ATTR_TYPE_MAX ||
+            didInit[type])
+            return false;
+
+        if (!providerEnabled(type)) {
+            releaseProvider(type);
             continue;
         }
 
-        provider = m_providers[i];
-        if (provider == primaryProvider)
+        provider = m_providers[type];
+
+        ret = provider->initFromBuffer(this, &providerToken);
+        if (ret == false) {
+            releaseProvider(type);
+            break;
+        }
+        didInit[type] = true;
+    }
+
+    for (size_t i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
+        gss_eap_attr_provider *provider;
+
+        if (didInit[i])
             continue;
 
+        provider = m_providers[i];
+
         ret = provider->initFromGssContext(this,
                                            GSS_C_NO_CREDENTIAL,
                                            GSS_C_NO_CONTEXT);
@@ -555,23 +595,47 @@ gss_eap_attr_ctx::releaseAnyNameMapping(gss_buffer_t type_id,
 void
 gss_eap_attr_ctx::exportToBuffer(gss_buffer_t buffer) const
 {
-    const gss_eap_attr_provider *primaryProvider = getPrimaryProvider();
-    gss_buffer_desc tmp;
-    unsigned char *p;
     OM_uint32 tmpMinor;
+    gss_buffer_desc providerTokens[ATTR_TYPE_MAX + 1];
+    size_t length = 4; /* m_flags */
+    unsigned char *p;
+
+    memset(providerTokens, 0, sizeof(providerTokens));
+
+    for (size_t i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
+        gss_eap_attr_provider *provider = m_providers[i];
 
-    primaryProvider->exportToBuffer(&tmp);
+        if (provider == NULL)
+            continue;
+
+        provider->exportToBuffer(&providerTokens[i]);
+
+        if (providerTokens[i].value != NULL)
+            length += 8 + providerTokens[i].length;
+    }
 
-    buffer->length = 4 + tmp.length;
-    buffer->value = GSSEAP_MALLOC(buffer->length);
+    buffer->length = length;
+    buffer->value = GSSEAP_MALLOC(length);
     if (buffer->value == NULL)
         throw new std::bad_alloc;
 
     p = (unsigned char *)buffer->value;
     store_uint32_be(m_flags, p);
-    memcpy(p + 4, tmp.value, tmp.length);
+    p += 4;
 
-    gss_release_buffer(&tmpMinor, &tmp);
+    for (size_t i = ATTR_TYPE_MIN; i <= ATTR_TYPE_MAX; i++) {
+        if (providerTokens[i].value == NULL)
+            continue;
+
+        store_uint32_be(i, p);
+        p += 4;
+        store_uint32_be(providerTokens[i].length, p);
+        p += 4;
+        memcpy(p, providerTokens[i].value, providerTokens[i].length);
+        p += providerTokens[i].length;
+
+        gss_release_buffer(&tmpMinor, &providerTokens[i]);
+    }
 }
 
 /*
index 2451c46..ca11172 100644 (file)
@@ -307,37 +307,15 @@ gss_eap_saml_assertion_provider::releaseAnyNameMapping(gss_buffer_t type_id GSSE
 void
 gss_eap_saml_assertion_provider::exportToBuffer(gss_buffer_t buffer) const
 {
-    ostringstream sink;
-    string str;
-
     buffer->length = 0;
     buffer->value = NULL;
-
-    if (m_assertion == NULL)
-        return;
-
-    sink << *m_assertion;
-    str = sink.str();
-
-    duplicateBuffer(str, buffer);
 }
 
 bool
-gss_eap_saml_assertion_provider::initFromBuffer(const gss_eap_attr_ctx *ctx,
-                                                const gss_buffer_t buffer)
+gss_eap_saml_assertion_provider::initFromBuffer(const gss_eap_attr_ctx *ctx GSSEAP_UNUSED,
+                                                const gss_buffer_t buffer GSSEAP_UNUSED)
 {
-    if (!gss_eap_attr_provider::initFromBuffer(ctx, buffer))
-        return false;
-
-    if (buffer->length == 0)
-        return true;
-
-    assert(m_assertion == NULL);
-
-    setAssertion(buffer);
-    /* TODO XXX how to propagate authenticated flag? */
-
-    return true;
+    return false;
 }
 
 bool
@@ -714,10 +692,10 @@ gss_eap_saml_attr_provider::exportToBuffer(gss_buffer_t buffer) const
 }
 
 bool
-gss_eap_saml_attr_provider::initFromBuffer(const gss_eap_attr_ctx *ctx,
-                                           const gss_buffer_t buffer)
+gss_eap_saml_attr_provider::initFromBuffer(const gss_eap_attr_ctx *ctx GSSEAP_UNUSED,
+                                           const gss_buffer_t buffer GSSEAP_UNUSED)
 {
-    return gss_eap_attr_provider::initFromBuffer(ctx, buffer);
+    return false;
 }
 
 bool
index bab284b..b2a83f6 100644 (file)
@@ -401,7 +401,7 @@ gss_eap_shib_attr_provider::exportToBuffer(gss_buffer_t buffer) const
     }
 
     ostringstream sink;
-    sink << attrs;
+    sink << obj;
     string str = sink.str();
 
     duplicateBuffer(str, buffer);