2 * Licensed to the University Corporation for Advanced Internet
3 * Development, Inc. (UCAID) under one or more contributor license
4 * agreements. See the NOTICE file distributed with this work for
5 * additional information regarding copyright ownership.
7 * UCAID licenses this file to you under the Apache License,
8 * Version 2.0 (the "License"); you may not use this file except
9 * in compliance with the License. You may obtain a copy of the
12 * http://www.apache.org/licenses/LICENSE-2.0
14 * Unless required by applicable law or agreed to in writing,
15 * software distributed under the License is distributed on an
16 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
17 * either express or implied. See the License for the specific
18 * language governing permissions and limitations under the License.
22 * @file saml/saml1/core/Assertions.h
24 * XMLObjects representing the SAML 1.x Assertions schema.
27 #ifndef __saml1_assertions_h__
28 #define __saml1_assertions_h__
30 #include <saml/Assertion.h>
31 #include <saml/util/SAMLConstants.h>
33 #include <xmltooling/ElementProxy.h>
34 #include <xmltooling/ConcreteXMLObjectBuilder.h>
36 #define DECL_SAML1OBJECTBUILDER(cname) \
37 DECL_XMLOBJECTBUILDER(SAML_API,cname,samlconstants::SAML1_NS,samlconstants::SAML1_PREFIX)
39 namespace xmltooling {
40 class XMLTOOL_API DateTime;
43 namespace xmlsignature {
44 class XMLTOOL_API KeyInfo;
45 class XMLTOOL_API Signature;
51 * @namespace opensaml::saml1
52 * SAML 1.x assertion namespace
57 class SAML_API Assertion;
59 DECL_XMLOBJECT_SIMPLE(SAML_API,AssertionIDReference,AssertionID,SAML 1.x AssertionIDReference element);
60 DECL_XMLOBJECT_SIMPLE(SAML_API,Audience,AudienceURI,SAML 1.x Audience element);
61 DECL_XMLOBJECT_SIMPLE(SAML_API,ConfirmationMethod,Method,SAML 1.x ConfirmationMethod element);
63 BEGIN_XMLOBJECT(SAML_API,Condition,xmltooling::XMLObject,SAML 1.x Condition element);
66 BEGIN_XMLOBJECT(SAML_API,AudienceRestrictionCondition,Condition,SAML 1.x AudienceRestrictionCondition element);
67 DECL_TYPED_CHILDREN(Audience);
68 /** AudienceRestrictionConditionType local name */
69 static const XMLCh TYPE_NAME[];
72 BEGIN_XMLOBJECT(SAML_API,DoNotCacheCondition,Condition,SAML 1.x DoNotCacheCondition element);
73 /** DoNotCacheConditionType local name */
74 static const XMLCh TYPE_NAME[];
77 BEGIN_XMLOBJECT(SAML_API,Conditions,xmltooling::XMLObject,SAML 1.x Conditions element);
78 DECL_DATETIME_ATTRIB(NotBefore,NOTBEFORE);
79 DECL_DATETIME_ATTRIB(NotOnOrAfter,NOTONORAFTER);
80 DECL_TYPED_CHILDREN(AudienceRestrictionCondition);
81 DECL_TYPED_CHILDREN(DoNotCacheCondition);
82 DECL_TYPED_CHILDREN(Condition);
83 /** ConditionsType local name */
84 static const XMLCh TYPE_NAME[];
87 BEGIN_XMLOBJECT(SAML_API,NameIdentifier,xmltooling::XMLObject,SAML 1.x NameIdentifier element);
88 DECL_STRING_ATTRIB(NameQualifier,NAMEQUALIFIER);
89 DECL_STRING_ATTRIB(Format,FORMAT);
90 DECL_SIMPLE_CONTENT(Name);
91 /** NameIdentifierType local name */
92 static const XMLCh TYPE_NAME[];
93 /** Unspecified name format ID */
94 static const XMLCh UNSPECIFIED[];
95 /** Email address name format ID */
96 static const XMLCh EMAIL[];
97 /** X.509 subject name format ID */
98 static const XMLCh X509_SUBJECT[];
99 /** Windows domain qualified name format ID */
100 static const XMLCh WIN_DOMAIN_QUALIFIED[];
103 BEGIN_XMLOBJECT(SAML_API,SubjectConfirmationData,xmltooling::ElementProxy,SAML 1.x SubjectConfirmationData element);
106 BEGIN_XMLOBJECT(SAML_API,SubjectConfirmation,xmltooling::XMLObject,SAML 1.x SubjectConfirmation element);
107 DECL_TYPED_CHILDREN(ConfirmationMethod);
108 DECL_XMLOBJECT_CHILD(SubjectConfirmationData);
109 DECL_TYPED_FOREIGN_CHILD(KeyInfo,xmlsignature);
110 /** SubjectConfirmationType local name */
111 static const XMLCh TYPE_NAME[];
112 /** Deprecated SAML 1.0 Artifact confirmation method */
113 static const XMLCh ARTIFACT01[];
114 /** Artifact confirmation method */
115 static const XMLCh ARTIFACT[];
116 /** Bearer confirmation method */
117 static const XMLCh BEARER[];
118 /** Holder of key confirmation method */
119 static const XMLCh HOLDER_KEY[];
120 /** Sender vouches confirmation method */
121 static const XMLCh SENDER_VOUCHES[];
124 BEGIN_XMLOBJECT(SAML_API,Subject,xmltooling::XMLObject,SAML 1.x Subject element);
125 DECL_TYPED_CHILD(NameIdentifier);
126 DECL_TYPED_CHILD(SubjectConfirmation);
127 /** SubjectType local name */
128 static const XMLCh TYPE_NAME[];
131 BEGIN_XMLOBJECT(SAML_API,Statement,xmltooling::XMLObject,SAML 1.x Statement element);
134 BEGIN_XMLOBJECT(SAML_API,SubjectStatement,Statement,SAML 1.x SubjectStatement element);
135 DECL_TYPED_CHILD(Subject);
138 BEGIN_XMLOBJECT(SAML_API,SubjectLocality,xmltooling::XMLObject,SAML 1.x SubjectLocality element);
139 DECL_STRING_ATTRIB(IPAddress,IPADDRESS);
140 DECL_STRING_ATTRIB(DNSAddress,DNSADDRESS);
141 /** SubjectLocalityType local name */
142 static const XMLCh TYPE_NAME[];
145 BEGIN_XMLOBJECT(SAML_API,AuthorityBinding,xmltooling::XMLObject,SAML 1.x AuthorityBinding element);
146 DECL_XMLOBJECT_ATTRIB(AuthorityKind,AUTHORITYKIND,xmltooling::QName);
147 DECL_STRING_ATTRIB(Location,LOCATION);
148 DECL_STRING_ATTRIB(Binding,BINDING);
149 /** AuthorityBindingType local name */
150 static const XMLCh TYPE_NAME[];
153 BEGIN_XMLOBJECT(SAML_API,AuthenticationStatement,SubjectStatement,SAML 1.x AuthenticationStatement element);
154 DECL_STRING_ATTRIB(AuthenticationMethod,AUTHENTICATIONMETHOD);
155 DECL_DATETIME_ATTRIB(AuthenticationInstant,AUTHENTICATIONINSTANT);
156 DECL_TYPED_CHILD(SubjectLocality);
157 DECL_TYPED_CHILDREN(AuthorityBinding);
158 /** AuthenticationStatementType local name */
159 static const XMLCh TYPE_NAME[];
162 BEGIN_XMLOBJECT(SAML_API,Action,xmltooling::XMLObject,SAML 1.x Action element);
163 DECL_STRING_ATTRIB(Namespace,NAMESPACE);
164 DECL_SIMPLE_CONTENT(Action);
165 /** ActionType local name */
166 static const XMLCh TYPE_NAME[];
167 /** Read/Write/Execute/Delete/Control Action Namespace */
168 static const XMLCh RWEDC_NEG_ACTION_NAMESPACE[];
169 /** Read/Write/Execute/Delete/Control with Negation Action Namespace */
170 static const XMLCh RWEDC_ACTION_NAMESPACE[];
171 /** Get/Head/Put/Post Action Namespace */
172 static const XMLCh GHPP_ACTION_NAMESPACE[];
173 /** UNIX File Permissions Action Namespace */
174 static const XMLCh UNIX_ACTION_NAMESPACE[];
177 BEGIN_XMLOBJECT(SAML_API,Evidence,xmltooling::XMLObject,SAML 1.x Evidence element);
178 DECL_TYPED_CHILDREN(AssertionIDReference);
179 DECL_TYPED_CHILDREN(Assertion);
180 /** EvidenceType local name */
181 static const XMLCh TYPE_NAME[];
184 BEGIN_XMLOBJECT(SAML_API,AuthorizationDecisionStatement,SubjectStatement,SAML 1.x AuthorizationDecisionStatement element);
185 DECL_STRING_ATTRIB(Resource,RESOURCE);
186 DECL_STRING_ATTRIB(Decision,DECISION);
187 DECL_TYPED_CHILDREN(Action);
188 DECL_TYPED_CHILD(Evidence);
189 /** AuthorizationDecisionStatementType local name */
190 static const XMLCh TYPE_NAME[];
191 /** Permit Decision */
192 static const XMLCh DECISION_PERMIT[];
194 static const XMLCh DECISION_DENY[];
195 /** Indeterminate Decision */
196 static const XMLCh DECISION_INDETERMINATE[];
199 BEGIN_XMLOBJECT(SAML_API,AttributeDesignator,xmltooling::XMLObject,SAML 1.x AttributeDesignator element);
200 DECL_STRING_ATTRIB(AttributeName,ATTRIBUTENAME);
201 DECL_STRING_ATTRIB(AttributeNamespace,ATTRIBUTENAMESPACE);
202 /** AttributeDesignatorType local name */
203 static const XMLCh TYPE_NAME[];
206 BEGIN_XMLOBJECT(SAML_API,Attribute,AttributeDesignator,SAML 1.x Attribute element);
207 DECL_XMLOBJECT_CHILDREN(AttributeValue);
208 /** AttributeType local name */
209 static const XMLCh TYPE_NAME[];
212 BEGIN_XMLOBJECT(SAML_API,AttributeValue,xmltooling::ElementProxy,SAML 1.x AttributeValue element);
215 BEGIN_XMLOBJECT(SAML_API,AttributeStatement,SubjectStatement,SAML 1.x AttributeStatement element);
216 DECL_TYPED_CHILDREN(Attribute);
217 /** AttributeStatementType local name */
218 static const XMLCh TYPE_NAME[];
221 BEGIN_XMLOBJECT(SAML_API,Advice,xmltooling::ElementExtensibleXMLObject,SAML 1.x Advice element);
222 DECL_TYPED_CHILDREN(AssertionIDReference);
223 DECL_TYPED_CHILDREN(Assertion);
224 /** AdviceType local name */
225 static const XMLCh TYPE_NAME[];
228 BEGIN_XMLOBJECT(SAML_API,Assertion,opensaml::Assertion,SAML 1.x Assertion element);
229 DECL_INTEGER_ATTRIB(MinorVersion,MINORVERSION);
230 DECL_STRING_ATTRIB(AssertionID,ASSERTIONID);
231 DECL_STRING_ATTRIB(Issuer,ISSUER);
232 DECL_INHERITED_DATETIME_ATTRIB(IssueInstant,ISSUEINSTANT);
233 DECL_TYPED_CHILD(Conditions);
234 DECL_TYPED_CHILD(Advice);
235 DECL_TYPED_CHILDREN(Statement);
236 DECL_TYPED_CHILDREN(SubjectStatement);
237 DECL_TYPED_CHILDREN(AuthenticationStatement);
238 DECL_TYPED_CHILDREN(AttributeStatement);
239 DECL_TYPED_CHILDREN(AuthorizationDecisionStatement);
240 /** AssertionType local name */
241 static const XMLCh TYPE_NAME[];
244 DECL_SAML1OBJECTBUILDER(Action);
245 DECL_SAML1OBJECTBUILDER(Advice);
246 DECL_SAML1OBJECTBUILDER(Assertion);
247 DECL_SAML1OBJECTBUILDER(AssertionIDReference);
248 DECL_SAML1OBJECTBUILDER(Attribute);
249 DECL_SAML1OBJECTBUILDER(AttributeDesignator);
250 DECL_SAML1OBJECTBUILDER(AttributeStatement);
251 DECL_SAML1OBJECTBUILDER(AttributeValue);
252 DECL_SAML1OBJECTBUILDER(Audience);
253 DECL_SAML1OBJECTBUILDER(AudienceRestrictionCondition);
254 DECL_SAML1OBJECTBUILDER(AuthenticationStatement);
255 DECL_SAML1OBJECTBUILDER(AuthorizationDecisionStatement);
256 DECL_SAML1OBJECTBUILDER(AuthorityBinding);
257 DECL_SAML1OBJECTBUILDER(Conditions);
258 DECL_SAML1OBJECTBUILDER(ConfirmationMethod);
259 DECL_SAML1OBJECTBUILDER(DoNotCacheCondition);
260 DECL_SAML1OBJECTBUILDER(Evidence);
261 DECL_SAML1OBJECTBUILDER(NameIdentifier);
262 DECL_SAML1OBJECTBUILDER(Subject);
263 DECL_SAML1OBJECTBUILDER(SubjectConfirmation);
264 DECL_SAML1OBJECTBUILDER(SubjectConfirmationData);
265 DECL_SAML1OBJECTBUILDER(SubjectLocality);
268 * Builder for Condition extension objects.
270 * This is customized to force the schema type to be specified.
272 class SAML_API ConditionBuilder : public xmltooling::XMLObjectBuilder {
274 virtual ~ConditionBuilder() {}
275 /** Builder that allows element/type override. */
276 #ifdef HAVE_COVARIANT_RETURNS
277 virtual Condition* buildObject(
279 virtual xmltooling::XMLObject* buildObject(
281 const XMLCh* nsURI, const XMLCh* localName, const XMLCh* prefix=nullptr, const xmltooling::QName* schemaType=nullptr
284 /** Singleton builder. */
285 static Condition* buildCondition(const xmltooling::QName& schemaType) {
286 const ConditionBuilder* b = dynamic_cast<const ConditionBuilder*>(
287 XMLObjectBuilder::getBuilder(xmltooling::QName(samlconstants::SAML1_NS,Condition::LOCAL_NAME))
290 #ifdef HAVE_COVARIANT_RETURNS
291 return b->buildObject(samlconstants::SAML1_NS, Condition::LOCAL_NAME, samlconstants::SAML1_PREFIX, &schemaType);
293 return dynamic_cast<Condition*>(b->buildObject(samlconstants::SAML1_NS, Condition::LOCAL_NAME, samlconstants::SAML1_PREFIX, &schemaType));
296 throw xmltooling::XMLObjectException("Unable to obtain typed builder for Condition.");
301 * Builder for Statement extension objects.
303 * This is customized to force the schema type to be specified.
305 class SAML_API StatementBuilder : public xmltooling::XMLObjectBuilder {
307 virtual ~StatementBuilder() {}
308 /** Builder that allows element/type override. */
309 #ifdef HAVE_COVARIANT_RETURNS
310 virtual Statement* buildObject(
312 virtual xmltooling::XMLObject* buildObject(
314 const XMLCh* nsURI, const XMLCh* localName, const XMLCh* prefix=nullptr, const xmltooling::QName* schemaType=nullptr
317 /** Singleton builder. */
318 static Statement* buildStatement(const xmltooling::QName& schemaType) {
319 const StatementBuilder* b = dynamic_cast<const StatementBuilder*>(
320 XMLObjectBuilder::getBuilder(xmltooling::QName(samlconstants::SAML1_NS,Statement::LOCAL_NAME))
323 #ifdef HAVE_COVARIANT_RETURNS
324 return b->buildObject(samlconstants::SAML1_NS, Statement::LOCAL_NAME, samlconstants::SAML1_PREFIX, &schemaType);
326 return dynamic_cast<Statement*>(b->buildObject(samlconstants::SAML1_NS, Statement::LOCAL_NAME, samlconstants::SAML1_PREFIX, &schemaType));
329 throw xmltooling::XMLObjectException("Unable to obtain typed builder for Statement.");
334 * Registers builders and validators for SAML 1.x Assertion classes into the runtime.
336 void SAML_API registerAssertionClasses();
340 #endif /* __saml1_assertions_h__ */